Commit 9283b739 authored by Giovanni Cabiddu's avatar Giovanni Cabiddu Committed by Alex Williamson
Browse files

vfio/qat: fix overflow check in qat_vf_resume_write()

The unsigned variable `size_t len` is cast to the signed type `loff_t`
when passed to the function check_add_overflow(). This function considers
the type of the destination, which is of type loff_t (signed),
potentially leading to an overflow. This issue is similar to the one
described in the link below.

Remove the cast.

Note that even if check_add_overflow() is bypassed, by setting `len` to
a value that is greater than LONG_MAX (which is considered as a negative
value after the cast), the function copy_from_user(), invoked a few lines
later, will not perform any copy and return `len` as (len > INT_MAX)
causing qat_vf_resume_write() to fail with -EFAULT.

Fixes: bb208810 ("vfio/qat: Add vfio_pci driver for Intel QAT SR-IOV VF devices")
CC: stable@vger.kernel.org # 6.10+
Link: https://lore.kernel.org/all/138bd2e2-ede8-4bcc-aa7b-f3d9de167a37@moroto.mountain


Reported-by: default avatarZijie Zhao <zzjas98@gmail.com>
Signed-off-by: default avatarGiovanni Cabiddu <giovanni.cabiddu@intel.com>
Reviewed-by: default avatarXin Zeng <xin.zeng@intel.com>
Link: https://lore.kernel.org/r/20241021123843.42979-1-giovanni.cabiddu@intel.com


Signed-off-by: default avatarAlex Williamson <alex.williamson@redhat.com>
parent 12cd88a9
Loading
Loading
Loading
Loading
+1 −1
Original line number Diff line number Diff line
@@ -304,7 +304,7 @@ static ssize_t qat_vf_resume_write(struct file *filp, const char __user *buf,
	offs = &filp->f_pos;

	if (*offs < 0 ||
	    check_add_overflow((loff_t)len, *offs, &end))
	    check_add_overflow(len, *offs, &end))
		return -EOVERFLOW;

	if (end > mig_dev->state_size)