diff options
| author | Pavel Begunkov <asml.silence@gmail.com> | 2025-02-14 22:48:15 +0000 |
|---|---|---|
| committer | Greg Kroah-Hartman <gregkh@linuxfoundation.org> | 2025-02-27 04:34:19 -0800 |
| commit | fdbfd52bd8b85ed6783365ff54c82ab7067bd61b (patch) | |
| tree | 8689de00f88a605dc3fa0e963f3de46f60db041b /io_uring | |
| parent | bc218366c6aa4251348fafcacdb1d4f1475047a1 (diff) | |
| download | linux-fdbfd52bd8b85ed6783365ff54c82ab7067bd61b.tar.gz linux-fdbfd52bd8b85ed6783365ff54c82ab7067bd61b.tar.bz2 linux-fdbfd52bd8b85ed6783365ff54c82ab7067bd61b.zip | |
io_uring: prevent opcode speculation
commit 1e988c3fe1264708f4f92109203ac5b1d65de50b upstream.
sqe->opcode is used for different tables, make sure we santitise it
against speculations.
Cc: stable@vger.kernel.org
Fixes: d3656344fea03 ("io_uring: add lookup table for various opcode needs")
Signed-off-by: Pavel Begunkov <asml.silence@gmail.com>
Reviewed-by: Li Zetao <lizetao1@huawei.com>
Link: https://lore.kernel.org/r/7eddbf31c8ca0a3947f8ed98271acc2b4349c016.1739568408.git.asml.silence@gmail.com
Signed-off-by: Jens Axboe <axboe@kernel.dk>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Diffstat (limited to 'io_uring')
| -rw-r--r-- | io_uring/io_uring.c | 2 |
1 files changed, 2 insertions, 0 deletions
diff --git a/io_uring/io_uring.c b/io_uring/io_uring.c index d062c5c69211..0b0dfef93480 100644 --- a/io_uring/io_uring.c +++ b/io_uring/io_uring.c @@ -2045,6 +2045,8 @@ static int io_init_req(struct io_ring_ctx *ctx, struct io_kiocb *req, req->opcode = 0; return io_init_fail_req(req, -EINVAL); } + opcode = array_index_nospec(opcode, IORING_OP_LAST); + def = &io_issue_defs[opcode]; if (unlikely(sqe_flags & ~SQE_COMMON_FLAGS)) { /* enforce forwards compatibility on users */ |
