From: Christoph Hellwig <hch@lst.de>
To: Guixin Liu <kanie@linux.alibaba.com>
Cc: Hannes Reinecke <hare@suse.de>, Christoph Hellwig <hch@lst.de>,
Sagi Grimberg <sagi@grimberg.me>,
Chaitanya Kulkarni <kch@nvidia.com>, Jens Axboe <axboe@kernel.dk>,
linux-nvme@lists.infradead.org
Subject: Re: [PATCH] nvmet: fix heap out-of-bounds read in nvmet_auth_negotiate()
Date: Tue, 4 Aug 2026 18:19:26 +0200 [thread overview]
Message-ID: <20260804161926.GC11977@lst.de> (raw)
In-Reply-To: <20260804033800.3975537-1-kanie@linux.alibaba.com>
On Tue, Aug 04, 2026 at 11:38:00AM +0800, Guixin Liu wrote:
> nvmet_execute_auth_send() allocates the DH-HMAC-CHAP message buffer with
> the host-supplied transfer length (tl) and hands it to
> nvmet_auth_negotiate() without passing tl along. nvmet_auth_negotiate()
> then reads the negotiate header and, for each of the halen hash
> identifiers and dhlen DH group identifiers, indexes into the fixed
> idlist[60] array (hashes at idlist[0..halen), groups at idlist[30..]).
>
> Neither the transfer length nor halen/dhlen is validated. A malicious or
> non-conformant host can report a tl smaller than the negotiate structure,
> or a halen/dhlen larger than the array (both are u8, up to 255), making
> the loops read past the end of the allocated buffer (heap out-of-bounds
> read). The sibling nvmet_auth_reply() already validates tl against the
> structure size; the negotiate path did not.
>
> Pass tl into nvmet_auth_negotiate(), reject a tl that does not cover the
> negotiate data plus one full protocol descriptor, and reject halen/dhlen
> larger than NVME_AUTH_DHCHAP_MAX_DH_IDS.
>
> Fixes: db1312dd9548 ("nvmet: implement basic In-Band Authentication")
> Signed-off-by: Guixin Liu <kanie@linux.alibaba.com>
> ---
> drivers/nvme/target/fabrics-cmd-auth.c | 12 ++++++++++--
> 1 file changed, 10 insertions(+), 2 deletions(-)
>
> diff --git a/drivers/nvme/target/fabrics-cmd-auth.c b/drivers/nvme/target/fabrics-cmd-auth.c
> index d1b39e64d877..d015968bae2d 100644
> --- a/drivers/nvme/target/fabrics-cmd-auth.c
> +++ b/drivers/nvme/target/fabrics-cmd-auth.c
> @@ -31,12 +31,16 @@ void nvmet_auth_sq_init(struct nvmet_sq *sq)
> sq->dhchap_step = NVME_AUTH_DHCHAP_MESSAGE_NEGOTIATE;
> }
>
> -static u8 nvmet_auth_negotiate(struct nvmet_req *req, void *d)
> +static u8 nvmet_auth_negotiate(struct nvmet_req *req, void *d, u32 tl)
> {
> struct nvmet_ctrl *ctrl = req->sq->ctrl;
> struct nvmf_auth_dhchap_negotiate_data *data = d;
> int i, hash_id = 0, fallback_hash_id = 0, dhgid, fallback_dhgid;
>
> + if (tl < sizeof(*data) +
> + sizeof(struct nvmf_auth_dhchap_protocol_descriptor))
Odd formatting here. Condition continuations either get two-tab indents
or after the brace:
if (tl < sizeof(*data) +
sizeof(struct nvmf_auth_dhchap_protocol_descriptor))
if (tl <
sizeof(*data) + sizeof(struct nvmf_auth_dhchap_protocol_descriptor))
Otherwise looks good:
Reviewed-by: Christoph Hellwig <hch@lst.de>
next prev parent reply other threads:[~2026-08-04 16:19 UTC|newest]
Thread overview: 5+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-04 3:38 [PATCH] nvmet: fix heap out-of-bounds read in nvmet_auth_negotiate() Guixin Liu
2026-08-04 7:24 ` Hannes Reinecke
2026-08-04 16:19 ` Christoph Hellwig [this message]
2026-08-05 1:48 ` Guixin Liu
2026-08-10 19:37 ` Keith Busch
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260804161926.GC11977@lst.de \
--to=hch@lst.de \
--cc=axboe@kernel.dk \
--cc=hare@suse.de \
--cc=kanie@linux.alibaba.com \
--cc=kch@nvidia.com \
--cc=linux-nvme@lists.infradead.org \
--cc=sagi@grimberg.me \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.