Re: [PATCH v4 0/1] Fix buffer over-read in cca_cipher2protkey

Vasily Gorbik <[email protected]>
Newsgroups org.kernel.vger.linux-s390
Message-ID <[email protected]>
On Wed, Jul 29, 2026 at 01:40:08PM +0200, Harald Freudenberger wrote:
> Add validation of both the actual key buffer size and token length
> fields in all the cca_check_sec*token() functions. Additionally check
> in cca_gencipherkey() for possible underflow with returned key size.
> 
> The CCA token structures contain user-controlled len fields that
> were used in operations without proper validation against both the
> actual buffer size and minimum token structure size. An attacker
> could set this field larger than the actual buffer size, leading to
> reading beyond buffer boundaries. This may result in a kernel crash or
> exposure of memory via sending this as part of a request down to the
> crypto card. Also an attacker could have used a very small len value
> and thus enforce a buffer under-run which may produce similar effects
> as a over-read.
> 
> So now a key must
> - key buf length must be at least sizeof the token struct
> - the key len field inside the token must fit into the range of
>   sizeof key token struct ... key buf length
> 
> Changelog:
> v1 - initial version
> v2 - extend the length check to all cca_check_sec*token() functions,
>      also check for min given buffer length and token length field.
> v3 - there was still a possibility to under-run the length checks in
>      function  cca_gencipherkey(). Fixed as suggested by Ingo.
> v4 - Reviewd-by from Ingo added.
> 
> Harald Freudenberger (1):
>   s390/zcrypt: Fix buffer over-read in cca_cipher2protkey
> 
>  drivers/s390/crypto/pkey_cca.c       | 15 +++----
>  drivers/s390/crypto/zcrypt_ccamisc.c | 64 +++++++++++++++++++++++-----
>  drivers/s390/crypto/zcrypt_ccamisc.h |  6 +--
>  3 files changed, 62 insertions(+), 23 deletions(-)

Applied, thank you!
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.