All of lore.kernel.org
 help / color / mirror / Atom feed
From: Christoph Hellwig <hch@lst.de>
To: Hari Mishal <harimishal1@gmail.com>
Cc: Christoph Hellwig <hch@lst.de>, Sagi Grimberg <sagi@grimberg.me>,
	Chaitanya Kulkarni <kch@nvidia.com>,
	linux-nvme@lists.infradead.org, linux-kernel@vger.kernel.org
Subject: Re: [PATCH] nvmet: passthru: fix OOB reads when parsing ns id descriptor list
Date: Mon, 20 Jul 2026 10:23:55 +0200	[thread overview]
Message-ID: <20260720082355.GA20499@lst.de> (raw)
In-Reply-To: <20260717144353.19436-1-harimishal1@gmail.com>

On Fri, Jul 17, 2026 at 04:43:53PM +0200, Hari Mishal wrote:
> nvmet_passthru_override_id_descs() walks a namespace identification
> descriptor list populated from the underlying passthru controller's
> Identify response, which is device reported. The loop advanced pos by
> device controlled amounts (sizeof(*cur) + nidl) without checking that
> the next descriptor header actually fits inside the buffer, so a
> malicious device could push pos to within a few bytes of the buffer end
> and cause cur->nidl, cur->nidt or the reserved field to be read past the
> allocation.
> 
> Additionally, when a CSI descriptor lands exactly at the last valid
> header offset, cur + 1 points one byte past the end of the buffer.
> The unconditional memcpy(&csi, cur + 1, NVME_NIDT_CSI_LEN) could read
> that out-of-bounds byte and copy it back to the initiator via
> nvmet_copy_to_sgl(), leaking adjacent heap memory.
> 
> Bounds check both the descriptor header and the CSI value before
> dereferencing them.
> 
> Signed-off-by: Hari Mishal <harimishal1@gmail.com>
> ---
>  drivers/nvme/target/passthru.c | 8 ++++++++
>  1 file changed, 8 insertions(+)
> 
> diff --git a/drivers/nvme/target/passthru.c b/drivers/nvme/target/passthru.c
> index e27f84e3cf2b..7ef02958078b 100644
> --- a/drivers/nvme/target/passthru.c
> +++ b/drivers/nvme/target/passthru.c
> @@ -53,13 +53,21 @@ static u16 nvmet_passthru_override_id_descs(struct nvmet_req *req)
>  	for (pos = 0; pos < NVME_IDENTIFY_DATA_SIZE; pos += len) {
>  		struct nvme_ns_id_desc *cur = data + pos;
>  
> +		if (pos + sizeof(*cur) > NVME_IDENTIFY_DATA_SIZE)
> +			break;
> +
>  		if (cur->nidl == 0)
>  			break;
> +
>  		if (cur->nidt == NVME_NIDT_CSI) {
> +			if (pos + sizeof(*cur) + NVME_NIDT_CSI_LEN > NVME_IDENTIFY_DATA_SIZE)

Overly long line here.  Otherwise this looks sane.


      reply	other threads:[~2026-07-20  8:24 UTC|newest]

Thread overview: 2+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-07-17 14:43 [PATCH] nvmet: passthru: fix OOB reads when parsing ns id descriptor list Hari Mishal
2026-07-20  8:23 ` Christoph Hellwig [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260720082355.GA20499@lst.de \
    --to=hch@lst.de \
    --cc=harimishal1@gmail.com \
    --cc=kch@nvidia.com \
    --cc=linux-kernel@vger.kernel.org \
    --cc=linux-nvme@lists.infradead.org \
    --cc=sagi@grimberg.me \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.