vhost: Fix Spectre V1 vulnerability
authorJason Wang <jasowang@redhat.com>
Tue, 30 Oct 2018 06:10:49 +0000 (14:10 +0800)
committerDavid S. Miller <davem@davemloft.net>
Wed, 31 Oct 2018 19:39:15 +0000 (12:39 -0700)
commitff002269a4ee9c769dbf9365acef633ebcbd6cbe
tree4857add07b45c82cc591f888f6571d94a86dafb8
parentb1c234441e07da748ccded3aaa37177622d469d3
vhost: Fix Spectre V1 vulnerability

The idx in vhost_vring_ioctl() was controlled by userspace, hence a
potential exploitation of the Spectre variant 1 vulnerability.

Fixing this by sanitizing idx before using it to index d->vqs.

Cc: Michael S. Tsirkin <mst@redhat.com>
Cc: Josh Poimboeuf <jpoimboe@redhat.com>
Cc: Andrea Arcangeli <aarcange@redhat.com>
Signed-off-by: Jason Wang <jasowang@redhat.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
drivers/vhost/vhost.c