OpenVZ / Virtuozzo kernel development (devel@openvz.org)
 help / color / mirror / Atom feed
* [Devel] [PATCH RHEL10 COMMIT] ve/hooks: fix off-by-one in chain bounds check
       [not found] <20260706110002.1024515-16-khorenko@virtuozzo.com>
@ 2026-08-05 19:58 ` Konstantin Khorenko
  0 siblings, 0 replies; only message in thread
From: Konstantin Khorenko @ 2026-08-05 19:58 UTC (permalink / raw)


The commit is pushed to "branch-rh10-6.12.0-211.39.1.16.x.vz10-ovz" and will appear at git at bitbucket.org:openvz/vzkernel.git
after rh10-6.12.0-211.39.1.16.2.vz10
------>
commit aa8446429da3cf04c8cf2850fe973736d1b778ae
Author: Konstantin Khorenko <khorenko@virtuozzo.com>
Date:   Mon Jul 6 12:59:53 2026 +0200

    ve/hooks: fix off-by-one in chain bounds check
    
    ve_hooks[] has VE_MAX_CHAINS elements, so valid indices are
    0..VE_MAX_CHAINS-1. The guard in ve_hook_register() used
    "chain > VE_MAX_CHAINS", which lets chain == VE_MAX_CHAINS through
    and then indexes one element past the end of the array, corrupting
    whatever lies behind it via list_add_tail().
    
    Today the only chain value passed by in-tree callers is VE_SS_CHAIN
    (0), so the bug is dormant. But the whole point of this BUG_ON is to
    catch a caller passing VE_MAX_CHAINS by mistake (e.g. after the enum
    grows), and in its current form it silently allows exactly that
    out-of-bounds write instead of tripping. Use ">=" so the check
    rejects the first invalid index.
    
    Fixes: 82652f8a07493 ("ve: Add ve cgroup and ve_hook subsys")
    Feature: ve: ve generic structures
    https://virtuozzo.atlassian.net/browse/VSTOR-137234
    Signed-off-by: Konstantin Khorenko <khorenko@virtuozzo.com>
    Reviewed-by: Pavel Tikhomirov <ptikhomirov@virtuozzo.com>
---
 kernel/ve/hooks.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/kernel/ve/hooks.c b/kernel/ve/hooks.c
index df93174301143..273961069a23a 100644
--- a/kernel/ve/hooks.c
+++ b/kernel/ve/hooks.c
@@ -20,7 +20,7 @@ void ve_hook_register(int chain, struct ve_hook *vh)
 	struct list_head *lh;
 	struct ve_hook *tmp;
 
-	BUG_ON(chain > VE_MAX_CHAINS);
+	BUG_ON(chain >= VE_MAX_CHAINS);
 
 	down_write(&ve_hook_sem);
 	list_for_each(lh, &ve_hooks[chain]) {

^ permalink raw reply	[flat|nested] only message in thread

only message in thread, other threads:[~2026-08-05 19:58 UTC | newest]

Thread overview: (only message) (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
     [not found] <20260706110002.1024515-16-khorenko@virtuozzo.com>
2026-08-05 19:58 ` [Devel] [PATCH RHEL10 COMMIT] ve/hooks: fix off-by-one in chain bounds check Konstantin Khorenko

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox