[Devel] [PATCH RHEL10 COMMIT] ve/hooks: fix off-by-one in chain bounds check

Konstantin Khorenko khorenko at virtuozzo.com
Wed Aug 5 22:58:23 MSK 2026


The commit is pushed to "branch-rh10-6.12.0-211.39.1.16.x.vz10-ovz" and will appear at git at bitbucket.org:openvz/vzkernel.git
after rh10-6.12.0-211.39.1.16.2.vz10
------>
commit aa8446429da3cf04c8cf2850fe973736d1b778ae
Author: Konstantin Khorenko <khorenko at virtuozzo.com>
Date:   Mon Jul 6 12:59:53 2026 +0200

    ve/hooks: fix off-by-one in chain bounds check
    
    ve_hooks[] has VE_MAX_CHAINS elements, so valid indices are
    0..VE_MAX_CHAINS-1. The guard in ve_hook_register() used
    "chain > VE_MAX_CHAINS", which lets chain == VE_MAX_CHAINS through
    and then indexes one element past the end of the array, corrupting
    whatever lies behind it via list_add_tail().
    
    Today the only chain value passed by in-tree callers is VE_SS_CHAIN
    (0), so the bug is dormant. But the whole point of this BUG_ON is to
    catch a caller passing VE_MAX_CHAINS by mistake (e.g. after the enum
    grows), and in its current form it silently allows exactly that
    out-of-bounds write instead of tripping. Use ">=" so the check
    rejects the first invalid index.
    
    Fixes: 82652f8a07493 ("ve: Add ve cgroup and ve_hook subsys")
    Feature: ve: ve generic structures
    https://virtuozzo.atlassian.net/browse/VSTOR-137234
    Signed-off-by: Konstantin Khorenko <khorenko at virtuozzo.com>
    Reviewed-by: Pavel Tikhomirov <ptikhomirov at virtuozzo.com>
---
 kernel/ve/hooks.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/kernel/ve/hooks.c b/kernel/ve/hooks.c
index df93174301143..273961069a23a 100644
--- a/kernel/ve/hooks.c
+++ b/kernel/ve/hooks.c
@@ -20,7 +20,7 @@ void ve_hook_register(int chain, struct ve_hook *vh)
 	struct list_head *lh;
 	struct ve_hook *tmp;
 
-	BUG_ON(chain > VE_MAX_CHAINS);
+	BUG_ON(chain >= VE_MAX_CHAINS);
 
 	down_write(&ve_hook_sem);
 	list_for_each(lh, &ve_hooks[chain]) {


More information about the Devel mailing list