Thread (12 messages) 12 messages, 3 authors, 1d ago

Re: [PATCH v10 1/4] ring-buffer: Allow splice reads on static buffers

From: Steven Rostedt <rostedt@goodmis.org>
Date: 2026-09-04 17:11:09
Also in: sashiko-reviews

On Fri, 04 Sep 2026 17:01:07 +0000
sashiko-bot@kernel.org wrote:
If a malicious remote writer (such as an untrusted guest VM) modifies the
length fields in shared memory between the initial check and the memcpy(),
can event_size become arbitrarily large?

Could this bypass the bounds check and cause an out-of-bounds read from
rpage->data and a massive out-of-bounds write to dpage->data?
I don't think Sashiko knows that a remote writer isn't a guest. Well that's
not the normal case. But the trusted hypervisor that we control.

-- Steve
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help