From: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
To: linux-cve-announce@vger.kernel.org
Cc: Greg Kroah-Hartman <gregkh@kernel.org>
Subject: CVE-2026-74470: scsi: scsi_debug: Fix REPORT ZONES alloc_len underflow OOB write
Date: Sat, 15 Aug 2026 21:25:51 +0900 [thread overview]
Message-ID: <2026081534-CVE-2026-74470-6792@gregkh> (raw)
From: Greg Kroah-Hartman <gregkh@kernel.org>
Description
===========
In the Linux kernel, the following vulnerability has been resolved:
scsi: scsi_debug: Fix REPORT ZONES alloc_len underflow OOB write
resp_report_zones() sizes the reply buffer from the CDB allocation
length. The v3 fix rounds alloc_len up with ALIGN() before deriving the
descriptor count:
rep_max_zones = (ALIGN((u64)alloc_len, RZONES_DESC_HD) -
RZONES_DESC_HD) >> ilog2(RZONES_DESC_HD);
arr_len = (u64)RZONES_DESC_HD * (rep_max_zones + 1);
For alloc_len in 0xFFFFFFC1..0xFFFFFFFF, ALIGN() rounds up to
0x100000000, so arr_len is 4 GB. On 32-bit, kzalloc()'s size_t is 32-bit
and truncates 0x100000000 to 0; kzalloc(0) returns ZERO_SIZE_PTR, which
passes the !arr check, and desc = arr + 64 is then dereferenced in the
loop -> out-of-bounds write / panic.
Clamp rep_max_zones to devip->nr_zones. The loop already stops at
sdebug_capacity (after nr_zones zones), so a report can never hold more
than nr_zones descriptors; the clamp does not change the report, it only
bounds arr_len to (nr_zones + 1) * RZONES_DESC_HD, a real device
property that can never reach 0x100000000.
The Linux kernel CVE team has assigned CVE-2026-74470 to this issue.
Affected and fixed versions
===========================
Issue introduced in 5.16 with commit 7db0e0c8190a086ef92ce5bb960836cde49540aa and fixed in 6.6.151 with commit 49e5b25a0b74dbac595f122e5608fdce2918cc4e
Issue introduced in 5.16 with commit 7db0e0c8190a086ef92ce5bb960836cde49540aa and fixed in 6.12.103 with commit 495058429ca55ab7fcc21977b63b92907ad68066
Issue introduced in 5.16 with commit 7db0e0c8190a086ef92ce5bb960836cde49540aa and fixed in 6.18.44 with commit 2047ed09bf13453b7d6f9431b112ec07984dd69b
Issue introduced in 5.16 with commit 7db0e0c8190a086ef92ce5bb960836cde49540aa and fixed in 7.1.8 with commit d6e6da6bc3b53231fac77ffab428da8173ee729c
Issue introduced in 5.16 with commit 7db0e0c8190a086ef92ce5bb960836cde49540aa and fixed in 7.2-rc6 with commit 93dde0bf2f39a0f9f57fd610aa3201ce5b753433
Issue introduced in 5.10.85 with commit c4d2d7c935a4ad20e8e726ca10499cefe4537103
Issue introduced in 5.15.8 with commit ebacb44cb2042b90951140eda806bedad23ef554
Please see https://www.kernel.org for a full list of currently supported
kernel versions by the kernel community.
Unaffected versions might change over time as fixes are backported to
older supported kernel versions. The official CVE entry at
https://cve.org/CVERecord/?id=CVE-2026-74470
will be updated if fixes are backported, please check that for the most
up to date information about this issue.
Affected files
==============
The file(s) affected by this issue are:
drivers/scsi/scsi_debug.c
Mitigation
==========
The Linux kernel CVE team recommends that you update to the latest
stable kernel version for this, and many other bugfixes. Individual
changes are never tested alone, but rather are part of a larger kernel
release. Cherry-picking individual commits is not recommended or
supported by the Linux kernel community at all. If however, updating to
the latest release is impossible, the individual changes to resolve this
issue can be found at these commits:
https://git.kernel.org/stable/c/49e5b25a0b74dbac595f122e5608fdce2918cc4e
https://git.kernel.org/stable/c/495058429ca55ab7fcc21977b63b92907ad68066
https://git.kernel.org/stable/c/2047ed09bf13453b7d6f9431b112ec07984dd69b
https://git.kernel.org/stable/c/d6e6da6bc3b53231fac77ffab428da8173ee729c
https://git.kernel.org/stable/c/93dde0bf2f39a0f9f57fd610aa3201ce5b753433
reply other threads:[~2026-08-15 12:30 UTC|newest]
Thread overview: [no followups] expand[flat|nested] mbox.gz Atom feed
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=2026081534-CVE-2026-74470-6792@gregkh \
--to=gregkh@linuxfoundation.org \
--cc=cve@kernel.org \
--cc=gregkh@kernel.org \
--cc=linux-cve-announce@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.