From: Christian Borntraeger <[email protected]>
We verify the sccb length and then allocate based on that length. The
following access re-reads the sccb again. This can race against other
vCPUs overwriting the length field.
sclp_service_call_protected does not need a change as the ultravisor
provides a consistent snapshot.
Fixes: c1db53a5910f ("s390/sclp: read sccb from mem based on provided length")
Cc: [email protected]
Signed-off-by: Christian Borntraeger <[email protected]>
Reviewed-by: Matthew Rosato <[email protected]>
Reviewed-by: Eric Farman <[email protected]>
Reviewed-by: Collin Walling <[email protected]>
Message-ID: <[email protected]>
Signed-off-by: Cornelia Huck <[email protected]>
(cherry picked from commit 20701190e023216d0213a107a491402ce2cc501e)
Signed-off-by: Michael Tokarev <[email protected]>
diff --git a/hw/s390x/sclp.c b/hw/s390x/sclp.c
index 3a7302f760c..ea5362771cf 100644
--- a/hw/s390x/sclp.c
+++ b/hw/s390x/sclp.c
@@ -333,7 +333,8 @@ int sclp_service_call(S390CPU *cpu, uint64_t sccb, uint32_t
code)
/*
* we want to work on a private copy of the sccb, to prevent guests
* from playing dirty tricks by modifying the memory content after
- * the host has checked the values
+ * the host has checked the values.
+ * Reuse the previously fetched header
*/
work_sccb = g_malloc0(be16_to_cpu(header.length));
ret = address_space_read(as, sccb, attrs,
@@ -341,6 +342,7 @@ int sclp_service_call(S390CPU *cpu, uint64_t sccb, uint32_t
code)
if (ret != MEMTX_OK) {
return -PGM_ADDRESSING;
}
+ work_sccb->h = header;
if (!sclp_command_code_valid(code)) {
work_sccb->h.response_code = cpu_to_be16(SCLP_RC_INVALID_SCLP_COMMAND);
--
2.47.3