Re: [PATCH v2] crypto: qat - zero the VF migration state buffer on save
From: Herbert Xu
Date: Wed Sep 23 2026 - 05:22:26 EST
On Sat, Sep 19, 2026 at 07:49:34AM +0200, Karl Mehltretter wrote:
> The QAT VF migration state buffer is allocated with kmalloc(), while
> qat_vf_save_state() exposes all state_size bytes to userspace. The state
> manager writes only the serialized sections, leaving the unused tail
> unchanged. The first save can therefore disclose stale heap contents,
> and subsequent saves can disclose data left by an earlier migration.
>
> Zero the whole buffer before writing the setup data. Once the setup data
> is present, preserve it and zero the remaining state area before each
> state save.
>
> Fixes: f0bbfc391aa7 ("crypto: qat - implement interface for live migration")
> Cc: stable@xxxxxxxxxxxxxxx
> Assisted-by: Claude:claude-fable-5
> Signed-off-by: Karl Mehltretter <kmehltretter@xxxxxxxxx>
> ---
> Found by review. Compile-tested only; I do not have QAT hardware available.
>
> Changes since RFC:
> - Drop the RFC tag and mark the patch ready for application.
> - Describe the concrete userspace exposure path and add Cc: stable.
> - No code changes.
>
> RFC: https://lore.kernel.org/r/20260817042613.19855-1-kmehltretter@xxxxxxxxx/
>
> drivers/crypto/intel/qat/qat_common/adf_gen4_vf_mig.c | 5 +++++
> 1 file changed, 5 insertions(+)
Patch applied. Thanks.
--
Email: Herbert Xu <herbert@xxxxxxxxxxxxxxxxxxx>
Home Page: http://gondor.apana.org.au/~herbert/
PGP Key: http://gondor.apana.org.au/~herbert/pubkey.txt