hv_netvsc: Use vmbus_requestor to generate transaction IDs for VMBus hardening
authorAndres Beltran <lkmlabelt@gmail.com>
Mon, 9 Nov 2020 10:04:02 +0000 (11:04 +0100)
committerWei Liu <wei.liu@kernel.org>
Tue, 17 Nov 2020 10:54:18 +0000 (10:54 +0000)
commit4d18fcc95f50950a99bd940d4e61a983f91d267a
tree1833ae5107119605a1fba4f6580e35653a1e6a82
parent453de21c2b8281228173a7b689120b92929743d6
hv_netvsc: Use vmbus_requestor to generate transaction IDs for VMBus hardening

Currently, pointers to guest memory are passed to Hyper-V as
transaction IDs in netvsc. In the face of errors or malicious
behavior in Hyper-V, netvsc should not expose or trust the transaction
IDs returned by Hyper-V to be valid guest memory addresses. Instead,
use small integers generated by vmbus_requestor as requests
(transaction) IDs.

Signed-off-by: Andres Beltran <lkmlabelt@gmail.com>
Co-developed-by: Andrea Parri (Microsoft) <parri.andrea@gmail.com>
Signed-off-by: Andrea Parri (Microsoft) <parri.andrea@gmail.com>
Reviewed-by: Michael Kelley <mikelley@microsoft.com>
Acked-by: Jakub Kicinski <kuba@kernel.org>
Reviewed-by: Wei Liu <wei.liu@kernel.org>
Cc: "David S. Miller" <davem@davemloft.net>
Cc: Jakub Kicinski <kuba@kernel.org>
Cc: netdev@vger.kernel.org
Link: https://lore.kernel.org/r/20201109100402.8946-4-parri.andrea@gmail.com
Signed-off-by: Wei Liu <wei.liu@kernel.org>
drivers/net/hyperv/hyperv_net.h
drivers/net/hyperv/netvsc.c
drivers/net/hyperv/rndis_filter.c
include/linux/hyperv.h