yeahuh / rpms / qemu-kvm

Forked from rpms/qemu-kvm 2 years ago
Clone

Blame SOURCES/kvm-block-iscsi-fix-heap-buffer-overflow-in-iscsi_aio_io.patch

8fced6
From b9b77159567283628645943b5367d39b558e8faa Mon Sep 17 00:00:00 2001
8fced6
From: Jon Maloy <jmaloy@redhat.com>
8fced6
Date: Tue, 26 Jan 2021 20:07:59 -0500
8fced6
Subject: [PATCH 9/9] block/iscsi:fix heap-buffer-overflow in
8fced6
 iscsi_aio_ioctl_cb
8fced6
MIME-Version: 1.0
8fced6
Content-Type: text/plain; charset=UTF-8
8fced6
Content-Transfer-Encoding: 8bit
8fced6
8fced6
RH-Author: Jon Maloy <jmaloy@redhat.com>
8fced6
Message-id: <20210126200759.245891-2-jmaloy@redhat.com>
8fced6
Patchwork-id: 100787
8fced6
O-Subject: [RHEL-8.4.0 qemu-kvm PATCH 1/1] block/iscsi:fix heap-buffer-overflow in iscsi_aio_ioctl_cb
8fced6
Bugzilla: 1912974
8fced6
RH-Acked-by: Stefan Hajnoczi <stefanha@redhat.com>
8fced6
RH-Acked-by: Kevin Wolf <kwolf@redhat.com>
8fced6
RH-Acked-by: Laszlo Ersek <lersek@redhat.com>
8fced6
8fced6
From: Chen Qun <kuhn.chenqun@huawei.com>
8fced6
8fced6
There is an overflow, the source 'datain.data[2]' is 100 bytes,
8fced6
 but the 'ss' is 252 bytes.This may cause a security issue because
8fced6
 we can access a lot of unrelated memory data.
8fced6
8fced6
The len for sbp copy data should take the minimum of mx_sb_len and
8fced6
 sb_len_wr, not the maximum.
8fced6
8fced6
If we use iscsi device for VM backend storage, ASAN show stack:
8fced6
8fced6
READ of size 252 at 0xfffd149dcfc4 thread T0
8fced6
    #0 0xaaad433d0d34 in __asan_memcpy (aarch64-softmmu/qemu-system-aarch64+0x2cb0d34)
8fced6
    #1 0xaaad45f9d6d0 in iscsi_aio_ioctl_cb /qemu/block/iscsi.c:996:9
8fced6
    #2 0xfffd1af0e2dc  (/usr/lib64/iscsi/libiscsi.so.8+0xe2dc)
8fced6
    #3 0xfffd1af0d174  (/usr/lib64/iscsi/libiscsi.so.8+0xd174)
8fced6
    #4 0xfffd1af19fac  (/usr/lib64/iscsi/libiscsi.so.8+0x19fac)
8fced6
    #5 0xaaad45f9acc8 in iscsi_process_read /qemu/block/iscsi.c:403:5
8fced6
    #6 0xaaad4623733c in aio_dispatch_handler /qemu/util/aio-posix.c:467:9
8fced6
    #7 0xaaad4622f350 in aio_dispatch_handlers /qemu/util/aio-posix.c:510:20
8fced6
    #8 0xaaad4622f350 in aio_dispatch /qemu/util/aio-posix.c:520
8fced6
    #9 0xaaad46215944 in aio_ctx_dispatch /qemu/util/async.c:298:5
8fced6
    #10 0xfffd1bed12f4 in g_main_context_dispatch (/lib64/libglib-2.0.so.0+0x512f4)
8fced6
    #11 0xaaad46227de0 in glib_pollfds_poll /qemu/util/main-loop.c:219:9
8fced6
    #12 0xaaad46227de0 in os_host_main_loop_wait /qemu/util/main-loop.c:242
8fced6
    #13 0xaaad46227de0 in main_loop_wait /qemu/util/main-loop.c:518
8fced6
    #14 0xaaad43d9d60c in qemu_main_loop /qemu/softmmu/vl.c:1662:9
8fced6
    #15 0xaaad4607a5b0 in main /qemu/softmmu/main.c:49:5
8fced6
    #16 0xfffd1a460b9c in __libc_start_main (/lib64/libc.so.6+0x20b9c)
8fced6
    #17 0xaaad43320740 in _start (aarch64-softmmu/qemu-system-aarch64+0x2c00740)
8fced6
8fced6
0xfffd149dcfc4 is located 0 bytes to the right of 100-byte region [0xfffd149dcf60,0xfffd149dcfc4)
8fced6
allocated by thread T0 here:
8fced6
    #0 0xaaad433d1e70 in __interceptor_malloc (aarch64-softmmu/qemu-system-aarch64+0x2cb1e70)
8fced6
    #1 0xfffd1af0e254  (/usr/lib64/iscsi/libiscsi.so.8+0xe254)
8fced6
    #2 0xfffd1af0d174  (/usr/lib64/iscsi/libiscsi.so.8+0xd174)
8fced6
    #3 0xfffd1af19fac  (/usr/lib64/iscsi/libiscsi.so.8+0x19fac)
8fced6
    #4 0xaaad45f9acc8 in iscsi_process_read /qemu/block/iscsi.c:403:5
8fced6
    #5 0xaaad4623733c in aio_dispatch_handler /qemu/util/aio-posix.c:467:9
8fced6
    #6 0xaaad4622f350 in aio_dispatch_handlers /qemu/util/aio-posix.c:510:20
8fced6
    #7 0xaaad4622f350 in aio_dispatch /qemu/util/aio-posix.c:520
8fced6
    #8 0xaaad46215944 in aio_ctx_dispatch /qemu/util/async.c:298:5
8fced6
    #9 0xfffd1bed12f4 in g_main_context_dispatch (/lib64/libglib-2.0.so.0+0x512f4)
8fced6
    #10 0xaaad46227de0 in glib_pollfds_poll /qemu/util/main-loop.c:219:9
8fced6
    #11 0xaaad46227de0 in os_host_main_loop_wait /qemu/util/main-loop.c:242
8fced6
    #12 0xaaad46227de0 in main_loop_wait /qemu/util/main-loop.c:518
8fced6
    #13 0xaaad43d9d60c in qemu_main_loop /qemu/softmmu/vl.c:1662:9
8fced6
    #14 0xaaad4607a5b0 in main /qemu/softmmu/main.c:49:5
8fced6
    #15 0xfffd1a460b9c in __libc_start_main (/lib64/libc.so.6+0x20b9c)
8fced6
    #16 0xaaad43320740 in _start (aarch64-softmmu/qemu-system-aarch64+0x2c00740)
8fced6
8fced6
Reported-by: Euler Robot <euler.robot@huawei.com>
8fced6
Signed-off-by: Chen Qun <kuhn.chenqun@huawei.com>
8fced6
Reviewed-by: Stefan Hajnoczi <stefanha@redhat.com>
8fced6
Message-id: 20200418062602.10776-1-kuhn.chenqun@huawei.com
8fced6
Reviewed-by: Daniel P. Berrangé <berrange@redhat.com>
8fced6
Signed-off-by: Peter Maydell <peter.maydell@linaro.org>
8fced6
8fced6
(cherry picked from ff0507c239a246fd7215b31c5658fc6a3ee1e4c5)
8fced6
Signed-off-by: Jon Maloy <jmaloy@redhat.com>
8fced6
Signed-off-by: Jon Maloy <jmaloy.redhat.com>
8fced6
---
8fced6
 block/iscsi.c | 3 +--
8fced6
 1 file changed, 1 insertion(+), 2 deletions(-)
8fced6
8fced6
diff --git a/block/iscsi.c b/block/iscsi.c
8fced6
index 0bea2d3a93..06915655b3 100644
8fced6
--- a/block/iscsi.c
8fced6
+++ b/block/iscsi.c
8fced6
@@ -991,8 +991,7 @@ iscsi_aio_ioctl_cb(struct iscsi_context *iscsi, int status,
8fced6
         acb->ioh->driver_status |= SG_ERR_DRIVER_SENSE;
8fced6
 
8fced6
         acb->ioh->sb_len_wr = acb->task->datain.size - 2;
8fced6
-        ss = (acb->ioh->mx_sb_len >= acb->ioh->sb_len_wr) ?
8fced6
-             acb->ioh->mx_sb_len : acb->ioh->sb_len_wr;
8fced6
+        ss = MIN(acb->ioh->mx_sb_len, acb->ioh->sb_len_wr);
8fced6
         memcpy(acb->ioh->sbp, &acb->task->datain.data[2], ss);
8fced6
     }
8fced6
 
8fced6
-- 
8fced6
2.18.2
8fced6