]> git.baikalelectronics.ru Git - kernel.git/commitdiff
vfio/pci: Add missing range check in vfio_pci_mmap
authorChristian A. Ehrhardt <lk@c--e.de>
Mon, 12 Apr 2021 21:41:24 +0000 (23:41 +0200)
committerAlex Williamson <alex.williamson@redhat.com>
Tue, 13 Apr 2021 14:29:16 +0000 (08:29 -0600)
When mmaping an extra device region verify that the region index
derived from the mmap offset is valid.

Fixes: d81e5fae077e ("vfio_pci: Allow mapping extra regions")
Cc: stable@vger.kernel.org
Signed-off-by: Christian A. Ehrhardt <lk@c--e.de>
Message-Id: <20210412214124.GA241759@lisa.in-ulm.de>
Reviewed-by: David Gibson <david@gibson.dropbear.id.au>
Reviewed-by: Cornelia Huck <cohuck@redhat.com>
Signed-off-by: Alex Williamson <alex.williamson@redhat.com>
drivers/vfio/pci/vfio_pci.c

index 65e7e6b44578c29b3297225096f6bca07ea1cdc9..5023e23db3bcb5824e9bdf4091dbbdbf274b7d61 100644 (file)
@@ -1656,6 +1656,8 @@ static int vfio_pci_mmap(void *device_data, struct vm_area_struct *vma)
 
        index = vma->vm_pgoff >> (VFIO_PCI_OFFSET_SHIFT - PAGE_SHIFT);
 
+       if (index >= VFIO_PCI_NUM_REGIONS + vdev->num_regions)
+               return -EINVAL;
        if (vma->vm_end < vma->vm_start)
                return -EINVAL;
        if ((vma->vm_flags & VM_SHARED) == 0)
@@ -1664,7 +1666,7 @@ static int vfio_pci_mmap(void *device_data, struct vm_area_struct *vma)
                int regnum = index - VFIO_PCI_NUM_REGIONS;
                struct vfio_pci_region *region = vdev->region + regnum;
 
-               if (region && region->ops && region->ops->mmap &&
+               if (region->ops && region->ops->mmap &&
                    (region->flags & VFIO_REGION_INFO_FLAG_MMAP))
                        return region->ops->mmap(vdev, region, vma);
                return -EINVAL;