git: eb01dfe6c01c - stable/11 - bhyve: Fix vq_getchain() error handling bugs in various device models
    Mark Johnston 
    markj at FreeBSD.org
       
    Tue Aug 24 18:32:33 UTC 2021
    
    
  
The branch stable/11 has been updated by markj:
URL: https://cgit.FreeBSD.org/src/commit/?id=eb01dfe6c01c700418a872ae520187a1292ea7da
commit eb01dfe6c01c700418a872ae520187a1292ea7da
Author:     Mark Johnston <markj at FreeBSD.org>
AuthorDate: 2021-08-24 18:19:49 +0000
Commit:     Mark Johnston <markj at FreeBSD.org>
CommitDate: 2021-08-24 18:30:31 +0000
    bhyve: Fix vq_getchain() error handling bugs in various device models
    
    Reviewed by:    grehan, khng
    Approved by:    so
    Security:       CVE-2021-29631
    Security:       FreeBSD-SA-21:13.bhyve
    
    (cherry picked from commit 71fbc6faed62e8eb5864f7c40839740f5e9f5558)
---
 usr.sbin/bhyve/pci_virtio_console.c | 7 ++++---
 usr.sbin/bhyve/pci_virtio_rnd.c     | 5 +++--
 2 files changed, 7 insertions(+), 5 deletions(-)
diff --git a/usr.sbin/bhyve/pci_virtio_console.c b/usr.sbin/bhyve/pci_virtio_console.c
index 13aa4ad30cca..73528a2e1476 100644
--- a/usr.sbin/bhyve/pci_virtio_console.c
+++ b/usr.sbin/bhyve/pci_virtio_console.c
@@ -404,6 +404,7 @@ pci_vtcon_sock_rx(int fd __unused, enum ev_type t __unused, void *arg)
 
 	do {
 		n = vq_getchain(vq, &idx, &iov, 1, NULL);
+		assert(n == 1);
 		len = readv(sock->vss_conn_fd, &iov, n);
 
 		if (len == 0 || (len < 0 && errno == EWOULDBLOCK)) {
@@ -544,7 +545,6 @@ pci_vtcon_control_send(struct pci_vtcon_softc *sc,
 		return;
 
 	n = vq_getchain(vq, &idx, &iov, 1, NULL);
-
 	assert(n == 1);
 
 	memcpy(iov.iov_base, ctrl, sizeof(struct pci_vtcon_control));
@@ -563,7 +563,8 @@ pci_vtcon_notify_tx(void *vsc, struct vqueue_info *vq)
 	struct pci_vtcon_softc *sc;
 	struct pci_vtcon_port *port;
 	struct iovec iov[1];
-	uint16_t idx, n;
+	int n;
+	uint16_t idx;
 	uint16_t flags[8];
 
 	sc = vsc;
@@ -571,7 +572,7 @@ pci_vtcon_notify_tx(void *vsc, struct vqueue_info *vq)
 
 	while (vq_has_descs(vq)) {
 		n = vq_getchain(vq, &idx, iov, 1, flags);
-		assert(n >= 1);
+		assert(n == 1);
 		if (port != NULL)
 			port->vsp_cb(port, port->vsp_arg, iov, 1);
 
diff --git a/usr.sbin/bhyve/pci_virtio_rnd.c b/usr.sbin/bhyve/pci_virtio_rnd.c
index 44bc55e0039e..5d2fac0c723a 100644
--- a/usr.sbin/bhyve/pci_virtio_rnd.c
+++ b/usr.sbin/bhyve/pci_virtio_rnd.c
@@ -109,7 +109,7 @@ pci_vtrnd_notify(void *vsc, struct vqueue_info *vq)
 {
 	struct iovec iov;
 	struct pci_vtrnd_softc *sc;
-	int len;
+	int len, n;
 	uint16_t idx;
 
 	sc = vsc;
@@ -120,7 +120,8 @@ pci_vtrnd_notify(void *vsc, struct vqueue_info *vq)
 	}
 
 	while (vq_has_descs(vq)) {
-		vq_getchain(vq, &idx, &iov, 1, NULL);
+		n = vq_getchain(vq, &idx, &iov, 1, NULL);
+		assert(n == 1);
 
 		len = read(sc->vrsc_fd, iov.iov_base, iov.iov_len);
 
    
    
More information about the dev-commits-src-all
mailing list