[PATCH 0/4] Drivers: hv: vmbus: Harden the ring buffer against a malicious host
From: Kameron Carr
Date: Thu Oct 01 2026 - 18:11:41 EST
In a CoCo VM the host is untrusted. Since the VMBus ring buffer read and
write indices live in shared memory, the guest has to treat both as
potentially malicious and as changing at any time. This patch series
adds bounds checking and reuses the validated indices instead of
re-accessing them.
Patch 1 contains the minimum security fix, and is the only patch in the
series intended to be backported. hv_ringbuffer_write() copies into the
ring at the write index, so a malicious host can make the guest write to
memory outside the ring buffer. This is reachable on any channel a CoCo
VM accepts.
Patches 2 and 3 add READ/WRITE_ONCE annotations and refactor the helper
functions to allow the caller to work with a consistent snapshot of the
ring buffer indices.
Patch 4 adds the rest of the bounds checking. The memcopy() in
hv_pkt_iter_avail() can only result in an out-of-bounds read if
rbi->pkt_buffer_size exceeds the ring's data size. KVP is the only
in-tree channel whose max_pkt_size exceeds its ring's data size (16K vs
12K on a 4K page guest). CoCo VMs reject the KVP channel, so this bug is
currently unreachable on CoCo VMs. The other paths patch 4 checks can't
cause a bad access, only a nonsense byte count or a wrong signaling
decision.
Patch 1 applies cleanly to v5.15 and later. The unchecked write goes
back to the original driver, but the host is only untrusted in CoCo VMs,
which Linux has supported since v5.12, so patch 1's Fixes tag points at
the original driver while its stable tag starts at 5.15.x.
---
Kameron Carr (4):
Drivers: hv: vmbus: Bounds check the shared ring buffer indices
Drivers: hv: vmbus: Annotate accesses to the shared ring buffer indices
Drivers: hv: vmbus: Compute ring byte counts from a caller-held snapshot
Drivers: hv: vmbus: Keep the ring byte counts sane for a bad index
drivers/hv/ring_buffer.c | 112 +++++++++++++++++++++--------------------------
include/linux/hyperv.h | 58 ++++++++++++++++++------
2 files changed, 94 insertions(+), 76 deletions(-)
---
base-commit: 72d3fcf802c45d00b300f25b848a93c3a2bd7c7e