From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-1.web.codeaurora.org [10.30.226.201]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 1971813C9A2 for ; Sat, 17 Aug 2024 09:22:38 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=10.30.226.201 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1723886559; cv=none; b=MWZQ7/0TLvg3fjuSIOQZiJJTy27qEQinOQHxatpg+PodShP5IxF9uM0NiN5UsVvbYds4nVg1DBNvuJNbAAdhzKtJy5eql66FIHKeWquYh0GGFAAUjoc4pMBh4RpxmFWQ5FXccqDseAsENGBirlnVgq7vkk/sFFJ7NbU4cwW5naY= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1723886559; c=relaxed/simple; bh=Y1OErX8BVGnmWegpbLo8nR6VwusjVWD0zHxkEuhcp9o=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=Ckot+kBT83AprlsgTj53PZI0Rom2DNoJ03Y3DclZPYvXdI3p5r4SwnxjU7uPEa1mUuLJ53bNgm0THjBF56IG1RCZFY3je4RoGXsd1b0utQvDBnHQt7WmC853cDGPIs+bhi5qccmM05vfXpA3bCBXTxA7ZdXO5HectoipbPUHCFk= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=fWLsfAzf; arc=none smtp.client-ip=10.30.226.201 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="fWLsfAzf" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 3D512C116B1; Sat, 17 Aug 2024 09:22:38 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=linuxfoundation.org; s=korg; t=1723886558; bh=Y1OErX8BVGnmWegpbLo8nR6VwusjVWD0zHxkEuhcp9o=; h=From:To:Cc:Subject:Date:Reply-to:From; b=fWLsfAzfwhwayzT5mALDZ/DebJH6T20q9Tt9grfWsD0YdUeZnKiA7FSMVSChTWW8m swx0AzjoUvAAe/3IospweKVwzM0Yjt6/GFlCgpyYwf+QGLrd8mXQNA3mF0Q9YrCflQ F5y5OGWLGBoZ5gaXMUCJdJMY7ZBn1fogEMn2OQ0c= From: Greg Kroah-Hartman To: linux-cve-announce@vger.kernel.org Cc: Greg Kroah-Hartman Subject: CVE-2024-43816: scsi: lpfc: Revise lpfc_prep_embed_io routine with proper endian macro usages Date: Sat, 17 Aug 2024 11:22:20 +0200 Message-ID: <2024081723-CVE-2024-43816-293f@gregkh> X-Mailer: git-send-email 2.46.0 Precedence: bulk X-Mailing-List: linux-cve-announce@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Reply-to: , X-Developer-Signature: v=1; a=openpgp-sha256; l=2190; i=gregkh@linuxfoundation.org; h=from:subject:message-id; bh=Y1OErX8BVGnmWegpbLo8nR6VwusjVWD0zHxkEuhcp9o=; b=owGbwMvMwCRo6H6F97bub03G02pJDGkHss8b7j3eIeanfElxZnp6ya+OA+Z5G9N0UmY+2Ddd9 H3l1KqTHbEsDIJMDLJiiixftvEc3V9xSNHL0PY0zBxWJpAhDFycAjARBUOGBefzRZ21ErQXLlzw J0f0ul7KrR/P1zEsOCbmfWrV8QarVVO6dj+xuz1h+cfL2wE= X-Developer-Key: i=gregkh@linuxfoundation.org; a=openpgp; fpr=F4B60CC5BF78C2214A313DCB3147D40DDB2DFB29 Content-Transfer-Encoding: 8bit Description =========== In the Linux kernel, the following vulnerability has been resolved: scsi: lpfc: Revise lpfc_prep_embed_io routine with proper endian macro usages On big endian architectures, it is possible to run into a memory out of bounds pointer dereference when FCP targets are zoned. In lpfc_prep_embed_io, the memcpy(ptr, fcp_cmnd, sgl->sge_len) is referencing a little endian formatted sgl->sge_len value. So, the memcpy can cause big endian systems to crash. Redefine the *sgl ptr as a struct sli4_sge_le to make it clear that we are referring to a little endian formatted data structure. And, update the routine with proper le32_to_cpu macro usages. The Linux kernel CVE team has assigned CVE-2024-43816 to this issue. Affected and fixed versions =========================== Issue introduced in 6.10 with commit af20bb73ac25 and fixed in 6.10.3 with commit 9fd003f344d5 Issue introduced in 6.10 with commit af20bb73ac25 and fixed in 6.11-rc1 with commit 8bc7c617642d Please see https://www.kernel.org for a full list of currently supported kernel versions by the kernel community. Unaffected versions might change over time as fixes are backported to older supported kernel versions. The official CVE entry at https://cve.org/CVERecord/?id=CVE-2024-43816 will be updated if fixes are backported, please check that for the most up to date information about this issue. Affected files ============== The file(s) affected by this issue are: drivers/scsi/lpfc/lpfc_sli.c Mitigation ========== The Linux kernel CVE team recommends that you update to the latest stable kernel version for this, and many other bugfixes. Individual changes are never tested alone, but rather are part of a larger kernel release. Cherry-picking individual commits is not recommended or supported by the Linux kernel community at all. If however, updating to the latest release is impossible, the individual changes to resolve this issue can be found at these commits: https://git.kernel.org/stable/c/9fd003f344d502f65252963169df3dd237054e49 https://git.kernel.org/stable/c/8bc7c617642db6d8d20ee671fb6c4513017e7a7e