> move_to_indirect() validates an indirect descriptor table only with
> "len % sizeof(struct vring_desc)".  A descriptor flagged
> VRING_DESC_F_INDIRECT with len == 0 passes that test, so *desc_max is
> set to 0 while *descs points at the empty table.  __vringh_iov() then
> copies one struct vring_desc from descs[0] -- 16 bytes past the end of
> the table -- before the "indirect_count > desc_max" loop detection
> aborts the walk.  The over-read value is discarded when the walk aborts
> and is never used to map anything, but the access itself is out of
> bounds.
> 
> Reject any len smaller than one descriptor, alongside the existing
> stride check, so an empty table is refused with -EINVAL and no
> descriptor is ever fetched from it.
> 
> Fixes: f87d0fbb5798 ("vringh: host-side implementation of virtio rings.")
> Cc: [email protected]
> Assisted-by: Hawkeye:GLM-5.3-flash
> Assisted-by: Qoder:Qwen3.8-Max
> Signed-off-by: Fang Xieyan <[email protected]>

Sashiko has reviewed this patch and found no issues. It looks great!

-- 
Sashiko AI review ยท 
https://sashiko.dev/#/patchset/[email protected]?part=1


Reply via email to