From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id E8779298CAB for ; Sat, 15 Aug 2026 12:30:45 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786797047; cv=none; b=s9dDgMZS9xfhvmNkydgeOQFhe7qHuDXuH8ou2HAFNUJaVsBB0aUazMbEqdnVSg8oIWnkbwy8mkxAssr19OKdP+Z2teeZlYAcUkFAfAR9jFeZlrZo6KvWukxwf5qasW/n1PELbWpJWcFwPyasCnlUnxkbL493SpaSx3PsU+hMB9I= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786797047; c=relaxed/simple; bh=L+ub0Sf8OyNGcPw9bFgUF9RA+K8V9MKDTCErhidft84=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=JzxL8cH621WDRPBVri8I32XMomMUCnhdb9sqsxYWqjQQJj9WCiJ+/V4uYd2EDF/zdozb8nY9ZWn63uMt9wNvyJbJW1+xGEKNHM+Ycb5pwADOh3LDPTQgXG+HaCqM9Uw90eP19B/jc3l4mcJ/IDthe81N9kCsAnYKo4ZP8GZqcKw= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=C8OJJyKh; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="C8OJJyKh" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 06FAA1F000E9; Sat, 15 Aug 2026 12:30:44 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxfoundation.org; s=korg; t=1786797045; bh=wmliXxk4P+Qj5cmRp670W0kWW1PnBjpSp7wDSNE/oNg=; h=From:To:Cc:Subject:Date:Reply-To; b=C8OJJyKh5Pk+ygXh9tVUeIVloW3vkKWhKHCLeI0fxNceezTIpL7s1ZlzDriSgDpZG vmC5syWy4hXDezQf6K+vRewSqL57VOhreAdjdIvUW44eY3N/m53mN6otJa3CSmqDgm 2Ovpbox3UEWrT8Xqjkky8cRDnwncVEhMcUHsw+CE= From: Greg Kroah-Hartman To: linux-cve-announce@vger.kernel.org Cc: Greg Kroah-Hartman Subject: CVE-2026-74470: scsi: scsi_debug: Fix REPORT ZONES alloc_len underflow OOB write Date: Sat, 15 Aug 2026 21:25:51 +0900 Message-ID: <2026081534-CVE-2026-74470-6792@gregkh> X-Mailer: git-send-email 2.55.0 Reply-To: , Precedence: bulk X-Mailing-List: linux-cve-announce@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 X-Developer-Signature: v=1; a=openpgp-sha256; l=3597; i=gregkh@linuxfoundation.org; h=from:subject:message-id; bh=UTpKrGK5omcNNS9PFGf3uc7VpHCsT9yXjmLbfaxMGyc=; b=owGbwMvMwCRo6H6F97bub03G02pJDFkNUfuOC5wzUmjQfWHy8+8HEXODLVMfeBQpfAkO/XzDh e/n2zseHbEsDIJMDLJiiixftvEc3V9xSNHL0PY0zBxWJpAhDFycAjARBTeGBRvUJ7dMva/31aDa bu6/vG3VH6yPbGFYsC633rDz2OMDiXvit2l5+nutXpW9FwA= X-Developer-Key: i=gregkh@linuxfoundation.org; a=openpgp; fpr=F4B60CC5BF78C2214A313DCB3147D40DDB2DFB29 Content-Transfer-Encoding: 8bit From: Greg Kroah-Hartman Description =========== In the Linux kernel, the following vulnerability has been resolved: scsi: scsi_debug: Fix REPORT ZONES alloc_len underflow OOB write resp_report_zones() sizes the reply buffer from the CDB allocation length. The v3 fix rounds alloc_len up with ALIGN() before deriving the descriptor count: rep_max_zones = (ALIGN((u64)alloc_len, RZONES_DESC_HD) - RZONES_DESC_HD) >> ilog2(RZONES_DESC_HD); arr_len = (u64)RZONES_DESC_HD * (rep_max_zones + 1); For alloc_len in 0xFFFFFFC1..0xFFFFFFFF, ALIGN() rounds up to 0x100000000, so arr_len is 4 GB. On 32-bit, kzalloc()'s size_t is 32-bit and truncates 0x100000000 to 0; kzalloc(0) returns ZERO_SIZE_PTR, which passes the !arr check, and desc = arr + 64 is then dereferenced in the loop -> out-of-bounds write / panic. Clamp rep_max_zones to devip->nr_zones. The loop already stops at sdebug_capacity (after nr_zones zones), so a report can never hold more than nr_zones descriptors; the clamp does not change the report, it only bounds arr_len to (nr_zones + 1) * RZONES_DESC_HD, a real device property that can never reach 0x100000000. The Linux kernel CVE team has assigned CVE-2026-74470 to this issue. Affected and fixed versions =========================== Issue introduced in 5.16 with commit 7db0e0c8190a086ef92ce5bb960836cde49540aa and fixed in 6.6.151 with commit 49e5b25a0b74dbac595f122e5608fdce2918cc4e Issue introduced in 5.16 with commit 7db0e0c8190a086ef92ce5bb960836cde49540aa and fixed in 6.12.103 with commit 495058429ca55ab7fcc21977b63b92907ad68066 Issue introduced in 5.16 with commit 7db0e0c8190a086ef92ce5bb960836cde49540aa and fixed in 6.18.44 with commit 2047ed09bf13453b7d6f9431b112ec07984dd69b Issue introduced in 5.16 with commit 7db0e0c8190a086ef92ce5bb960836cde49540aa and fixed in 7.1.8 with commit d6e6da6bc3b53231fac77ffab428da8173ee729c Issue introduced in 5.16 with commit 7db0e0c8190a086ef92ce5bb960836cde49540aa and fixed in 7.2-rc6 with commit 93dde0bf2f39a0f9f57fd610aa3201ce5b753433 Issue introduced in 5.10.85 with commit c4d2d7c935a4ad20e8e726ca10499cefe4537103 Issue introduced in 5.15.8 with commit ebacb44cb2042b90951140eda806bedad23ef554 Please see https://www.kernel.org for a full list of currently supported kernel versions by the kernel community. Unaffected versions might change over time as fixes are backported to older supported kernel versions. The official CVE entry at https://cve.org/CVERecord/?id=CVE-2026-74470 will be updated if fixes are backported, please check that for the most up to date information about this issue. Affected files ============== The file(s) affected by this issue are: drivers/scsi/scsi_debug.c Mitigation ========== The Linux kernel CVE team recommends that you update to the latest stable kernel version for this, and many other bugfixes. Individual changes are never tested alone, but rather are part of a larger kernel release. Cherry-picking individual commits is not recommended or supported by the Linux kernel community at all. If however, updating to the latest release is impossible, the individual changes to resolve this issue can be found at these commits: https://git.kernel.org/stable/c/49e5b25a0b74dbac595f122e5608fdce2918cc4e https://git.kernel.org/stable/c/495058429ca55ab7fcc21977b63b92907ad68066 https://git.kernel.org/stable/c/2047ed09bf13453b7d6f9431b112ec07984dd69b https://git.kernel.org/stable/c/d6e6da6bc3b53231fac77ffab428da8173ee729c https://git.kernel.org/stable/c/93dde0bf2f39a0f9f57fd610aa3201ce5b753433