* [Devel] [PATCH RHEL10 COMMIT] ve/hooks: fix off-by-one in chain bounds check
[not found] <20260706110002.1024515-16-khorenko@virtuozzo.com>
@ 2026-08-05 19:58 ` Konstantin Khorenko
0 siblings, 0 replies; only message in thread
From: Konstantin Khorenko @ 2026-08-05 19:58 UTC (permalink / raw)
The commit is pushed to "branch-rh10-6.12.0-211.39.1.16.x.vz10-ovz" and will appear at git at bitbucket.org:openvz/vzkernel.git
after rh10-6.12.0-211.39.1.16.2.vz10
------>
commit aa8446429da3cf04c8cf2850fe973736d1b778ae
Author: Konstantin Khorenko <khorenko@virtuozzo.com>
Date: Mon Jul 6 12:59:53 2026 +0200
ve/hooks: fix off-by-one in chain bounds check
ve_hooks[] has VE_MAX_CHAINS elements, so valid indices are
0..VE_MAX_CHAINS-1. The guard in ve_hook_register() used
"chain > VE_MAX_CHAINS", which lets chain == VE_MAX_CHAINS through
and then indexes one element past the end of the array, corrupting
whatever lies behind it via list_add_tail().
Today the only chain value passed by in-tree callers is VE_SS_CHAIN
(0), so the bug is dormant. But the whole point of this BUG_ON is to
catch a caller passing VE_MAX_CHAINS by mistake (e.g. after the enum
grows), and in its current form it silently allows exactly that
out-of-bounds write instead of tripping. Use ">=" so the check
rejects the first invalid index.
Fixes: 82652f8a07493 ("ve: Add ve cgroup and ve_hook subsys")
Feature: ve: ve generic structures
https://virtuozzo.atlassian.net/browse/VSTOR-137234
Signed-off-by: Konstantin Khorenko <khorenko@virtuozzo.com>
Reviewed-by: Pavel Tikhomirov <ptikhomirov@virtuozzo.com>
---
kernel/ve/hooks.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/kernel/ve/hooks.c b/kernel/ve/hooks.c
index df93174301143..273961069a23a 100644
--- a/kernel/ve/hooks.c
+++ b/kernel/ve/hooks.c
@@ -20,7 +20,7 @@ void ve_hook_register(int chain, struct ve_hook *vh)
struct list_head *lh;
struct ve_hook *tmp;
- BUG_ON(chain > VE_MAX_CHAINS);
+ BUG_ON(chain >= VE_MAX_CHAINS);
down_write(&ve_hook_sem);
list_for_each(lh, &ve_hooks[chain]) {
^ permalink raw reply [flat|nested] only message in thread
only message in thread, other threads:[~2026-08-05 19:58 UTC | newest]
Thread overview: (only message) (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
[not found] <20260706110002.1024515-16-khorenko@virtuozzo.com>
2026-08-05 19:58 ` [Devel] [PATCH RHEL10 COMMIT] ve/hooks: fix off-by-one in chain bounds check Konstantin Khorenko
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.