vfio/pci: Fix integer overflows, bitmask check
authorVlad Tsyrklevich <vlad@tsyrklevich.net>
Wed, 12 Oct 2016 16:51:24 +0000 (18:51 +0200)
committerSalvatore Bonaccorso <carnil@debian.org>
Fri, 2 Dec 2016 05:35:22 +0000 (05:35 +0000)
commit4b117fdcf6c9bc3d40420e5eea0d6dbe14858a3e
treeb0d01b6db4d711f4b6b6e53ebbaa05862d3773c1
parentc763fc449756a1989bf2804bfb4c71508d5aeb14
vfio/pci: Fix integer overflows, bitmask check

The VFIO_DEVICE_SET_IRQS ioctl did not sufficiently sanitize
user-supplied integers, potentially allowing memory corruption. This
patch adds appropriate integer overflow checks, checks the range bounds
for VFIO_IRQ_SET_DATA_NONE, and also verifies that only single element
in the VFIO_IRQ_SET_DATA_TYPE_MASK bitmask is set.
VFIO_IRQ_SET_ACTION_TYPE_MASK is already correctly checked later in
vfio_pci_set_irqs_ioctl().

Furthermore, a kzalloc is changed to a kcalloc because the use of a
kzalloc with an integer multiplication allowed an integer overflow
condition to be reached without this patch. kcalloc checks for overflow
and should prevent a similar occurrence.

Signed-off-by: Vlad Tsyrklevich <vlad@tsyrklevich.net>
Signed-off-by: Alex Williamson <alex.williamson@redhat.com>
Gbp-Pq: Topic bugfix/all
Gbp-Pq: Name vfio-pci-Fix-integer-overflows-bitmask-check.patch
drivers/vfio/pci/vfio_pci.c
drivers/vfio/pci/vfio_pci_intrs.c