From nobody Sat Oct 03 12:41:59 2026 X-Original-To: dev-commits-src-main@mlmmj.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mlmmj.nyi.freebsd.org (Postfix) with ESMTP id 4hxlf04Vbzz6vM1V for ; Sat, 03 Oct 2026 12:42:00 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from mxrelay.nyi.freebsd.org (mxrelay.nyi.freebsd.org [IPv6:2610:1c1:1:606c::19:3]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature RSA-PSS (4096 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "mxrelay.nyi.freebsd.org", Issuer "YR2" (not verified)) by mx1.freebsd.org (Postfix) with ESMTPS id 4hxlf03ZVDz3LvX for ; Sat, 03 Oct 2026 12:42:00 +0000 (UTC) (envelope-from git@FreeBSD.org) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1791031320; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=xdI7PT/6seTaTGD/G/Rp+jUT7DbuKF0liTGhfg6cLjI=; b=r/0XKFfN+8n0ExBQ+jCkigzwMlZIScaig/q6ngP9MDUF6rQQQ6S0Enda7dO2GhULPHjNd+ kt1s6Mqo1W186sioM+kHKwhc865iUG4meoKqyzxMXs1N+hMQL4IJltk0k9akfIfMFrOyQB PmIT42dCHKjSPTTxqta+rut9eyM4kALmK/4fAoG1lRO1IfU+C6wj9Ippvu4TJtzVplSHth 0YW0ik+BAKY4Ia2gN4bGHirEbGsyQ/rk0uRY1fpU8lMJktdoJ+LHSoUsxizhBel3jEB0sM XC5rJ8pa+Xec3aBGiQY4Prcrw8rzQZdbzepPZOzHeu8zVlygbS43fT+1q4EG2w== ARC-Seal: i=1; a=rsa-sha256; d=freebsd.org; s=dkim; cv=none; t=1791031320; b=SOJsOGYlB3J/lZhnk2xx1zmBdkA9XpcEbjZMbcJ/xj5Jo9ZKSJcTxniq4zP2puXlvy99UO 84vdv+XqQtwX2x5jDxx6Yc08Ms/PZ1LXL24Tfc+VdtvkRdPoU5PpjIsmv/kEQTtEFyi432 nI6MsSjYM/eClldkka56vANEqSDToZhhgz0a78actAM3xMtXPj65gbC+D8Q0jlGyU5LhHT Cvk4cEs2ZrJyApCwBvPqFqgpE+S3ncYf9KATiUxqHLzj61FRXhkPyy4Fe2Nyn9+jERBWyL aaD3Kh3TXB5Lzccc4sZnwaTX5yT+v7nP4l4iURJk/3QeA9M6RIZoGzWOFjfDpQ== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1791031320; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=xdI7PT/6seTaTGD/G/Rp+jUT7DbuKF0liTGhfg6cLjI=; b=BAKizGirvnXfWG1tHFjj4SJKYV+QSTpKpVvvqPRQ3Vs+JIDNka10PWVAK3QKpcDJ2YbjpH 6yfs9Gz66dLe0HEQ69co8uXbF1Zo0+39Jtofq0LE5Gvc1KbcpL+2q85Zs/4Vxye+72gZX6 qpQQndweVvdwphohVZlaHwa1jRu97/kQI+sC6epz2mlH61S+WcAK36UbTAqz1K8TsPqH67 vf0WJ58eFVGxPCEzEB+J6FeLMXYlW7PR8NxM9bvOU2TAzobSbwUMQa/KdYe4LfkdFUCYtL k3/1bfjz9DDxDJ9EYfnq1JB9+ychHJTpi90h2RINuAUAv8v5Fjg2Kg/EiJJ7/g== ARC-Authentication-Results: i=1; mx1.freebsd.org; none Received: from gitrepo.freebsd.org (gitrepo.freebsd.org [IPv6:2610:1c1:1:6068::e6a:5]) by mxrelay.nyi.freebsd.org (Postfix) with ESMTP id 4hxldz179wz13t3 for ; Sat, 03 Oct 2026 12:41:59 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from git (uid 1279) (envelope-from git@FreeBSD.org) id 30314 by gitrepo.freebsd.org (DragonFly Mail Agent v0.13+ on gitrepo.freebsd.org); Sat, 03 Oct 2026 12:41:59 +0000 To: src-committers@FreeBSD.org, dev-commits-src-all@FreeBSD.org, dev-commits-src-main@FreeBSD.org From: Faraz Vahedi Subject: git: 15198bfd7437 - main - virtio: Validate host-supplied used lengths List-Id: Commit messages for the main branch of the src repository List-Archive: https://lists.freebsd.org/archives/dev-commits-src-main List-Help: List-Post: List-Subscribe: List-Unsubscribe: X-BeenThere: dev-commits-src-main@freebsd.org Sender: owner-dev-commits-src-main@FreeBSD.org List-Id: List-Post: List-Help: List-Subscribe: List-Unsubscribe: List-Owner: Precedence: list MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: 8bit X-Git-Committer: kfv X-Git-Repository: src X-Git-Refname: refs/heads/main X-Git-Reftype: branch X-Git-Commit: 15198bfd7437a616e66342be3c672da0b523e710 Auto-Submitted: auto-generated Date: Sat, 03 Oct 2026 12:41:59 +0000 Message-Id: <6ac0f817.30314.3c38c618@gitrepo.freebsd.org> The branch main has been updated by kfv: URL: https://cgit.FreeBSD.org/src/commit/?id=15198bfd7437a616e66342be3c672da0b523e710 commit 15198bfd7437a616e66342be3c672da0b523e710 Author: Faraz Vahedi AuthorDate: 2026-10-03 12:39:36 +0000 Commit: Faraz Vahedi CommitDate: 2026-10-03 12:39:36 +0000 virtio: Validate host-supplied used lengths virtio_console used the host-supplied used lengths without validation, so a host could report a length larger than the buffer, causing the receive and control paths to read past the end of it. Clamp to the buffer size. vtnet already rejected used lengths larger than the buffer, but performed the check after converting the length to an int, so a length larger than INT_MAX would become negative and bypass the check. Reject such frames early before the conversion, and count them in ierrors and rx_frame_too_large. Reviewed by: markj Approved by: fuz (mentor) Differential Revision: https://reviews.freebsd.org/D60092 --- sys/dev/virtio/console/virtio_console.c | 2 ++ sys/dev/virtio/network/if_vtnet.c | 5 ++++- 2 files changed, 6 insertions(+), 1 deletion(-) diff --git a/sys/dev/virtio/console/virtio_console.c b/sys/dev/virtio/console/virtio_console.c index 81ffd7058f06..7dc6b531ea0e 100644 --- a/sys/dev/virtio/console/virtio_console.c +++ b/sys/dev/virtio/console/virtio_console.c @@ -922,6 +922,7 @@ vtcon_ctrl_task_cb(void *xsc, int pending) if (control == NULL) break; + len = min(len, VTCON_CTRL_BUFSZ); if (len > sizeof(struct virtio_console_control)) { data = (void *) &control[1]; data_len = len - sizeof(struct virtio_console_control); @@ -1320,6 +1321,7 @@ again: deq = 0; while ((buf = virtqueue_dequeue(vq, &len)) != NULL) { + len = min(len, VTCON_BULK_BUFSZ); for (i = 0; i < len; i++) { #if defined(KDB) if (port->vtcport_flags & VTCON_PORT_FLAG_CONSOLE) diff --git a/sys/dev/virtio/network/if_vtnet.c b/sys/dev/virtio/network/if_vtnet.c index 15dd50e7df77..f85b02fe18aa 100644 --- a/sys/dev/virtio/network/if_vtnet.c +++ b/sys/dev/virtio/network/if_vtnet.c @@ -2190,7 +2190,10 @@ vtnet_rxq_eof(struct vtnet_rxq *rxq) mp = mp->m_next; } - if (len < sc->vtnet_hdr_size + ETHER_HDR_LEN) { + if (synced < len || + len < sc->vtnet_hdr_size + ETHER_HDR_LEN) { + if (synced < len) + sc->vtnet_stats.rx_frame_too_large++; rxq->vtnrx_stats.vrxs_ierrors++; vtnet_rxq_discard_buf(rxq, m); continue;