> move_to_indirect() validates an indirect descriptor table only with
> "len % sizeof(struct vring_desc)". A descriptor flagged
> VRING_DESC_F_INDIRECT with len == 0 passes that test, so *desc_max is
> set to 0 while *descs points at the empty table. __vringh_iov() then
> copies one struct vring_desc from descs[0] -- 16 bytes past the end of
> the table -- before the "indirect_count > desc_max" loop detection
> aborts the walk. The over-read value is discarded when the walk aborts
> and is never used to map anything, but the access itself is out of
> bounds.
>
> Reject any len smaller than one descriptor, alongside the existing
> stride check, so an empty table is refused with -EINVAL and no
> descriptor is ever fetched from it.
>
> Fixes: f87d0fbb5798 ("vringh: host-side implementation of virtio rings.")
> Cc: [email protected]
> Assisted-by: Hawkeye:GLM-5.3-flash
> Assisted-by: Qoder:Qwen3.8-Max
> Signed-off-by: Fang Xieyan <[email protected]>
Sashiko has reviewed this patch and found no issues. It looks great!
--
Sashiko AI review ยท
https://sashiko.dev/#/patchset/[email protected]?part=1