From: Chandrakanth Patil <chandrakanth.patil@broadcom.com>
To: linux-scsi@vger.kernel.org, martin.petersen@oracle.com
Cc: sathya.prakash@broadcom.com, ranjan.kumar@broadcom.com,
sumit.saxena@broadcom.com, sweeti.vandure@broadcom.com,
vishakhavc@google.com, ipylypiv@google.com,
Chandrakanth Patil <chandrakanth.patil@broadcom.com>
Subject: [PATCH v2 00/17] scsi: mpi3mr: Fix out-of-bounds accesses and reference leaks
Date: Wed, 26 Aug 2026 02:33:54 +0530 [thread overview]
Message-ID: <20260825210411.301535-1-chandrakanth.patil@broadcom.com> (raw)
This series contains a set of fixes for the mpi3mr driver:
- out-of-bounds accesses where values reported by the controller
(device handles, phy numbers, topology event entry counts, reply and
sense buffer addresses, event data lengths) are used to index arrays,
derive pointers or size copies without being checked first
- out-of-bounds accesses in the BSG passthrough paths, from a request
size held in too narrow a variable and from a copy made without
checking the payload holds that much data
- target device reference leaks and an I/O block counter leak on error
and teardown paths, the latter leaving a device blocked for I/O
- a response buffer copied back to user space without being zeroed
first, so its unwritten fields carry whatever the allocation held
- a use-after-free and a NULL dereference around the firmware event
workqueue during driver removal and PCI error recovery
Changes in v2:
- Patch 6: Switched to do_div() for alignment check to fix 32-bit
build issue.
- Patch 7: Switched to do_div() for alignment check to fix 32-bit
build issue.
- Patch 8: Relocated handle bounds check to the entry of
mpi3mr_dev_rmhs_send_tm() so out-of-bounds handles are rejected
immediately without polluting delayed_rmhs_list.
- Patch 10: Cached num_entries in a local variable before bounds
checking to eliminate the TOCTOU re-fetch race from DMA memory.
- Patch 14: Cached num_entries in a local variable before bounds
checking to eliminate the TOCTOU re-fetch race from DMA memory.
- Patch 17: Removed stop_drv_processing and workqueue cleanup from
pci_channel_io_frozen to prevent I/O breakage (DID_NO_CONNECT) and
workqueue deadlocks. Added pci_err_recovery check in
mpi3mr_fwevt_bh() to safely skip event processing.
- Patches 1-5, 9, 11-13, 15-16: Unchanged from v1.
Chandrakanth Patil (17):
mpi3mr: Fix buffer overflow in BSG passthrough request copy
mpi3mr: Fix out-of-bounds read when copying BSG MPI requests
mpi3mr: Fix I/O block counter leak on admin request post failure
mpi3mr: Fix target device reference leak in BSG task management
mpi3mr: Fix buffer overflow when caching log data
mpi3mr: Fix out-of-bounds reply frame access
mpi3mr: Fix out-of-bounds sense buffer access
mpi3mr: Fix out-of-bounds bitmap access during device removal
mpi3mr: Fix target device reference leak in device removal handshake
mpi3mr: Fix out-of-bounds read in SAS topology change events
mpi3mr: Fix out-of-bounds read of event data
mpi3mr: Fix out-of-bounds phy array access on link change
mpi3mr: Fix buffer overflow in the BSG target device map
mpi3mr: Fix out-of-bounds read in PCIe topology change events
mpi3mr: zero out diagnostic buffer status memory
mpi3mr: Fix use-after-free of the firmware event workqueue
mpi3mr: Fix NULL pointer dereference on PCI error recovery
drivers/scsi/mpi3mr/mpi3mr_app.c | 43 ++++++++----
drivers/scsi/mpi3mr/mpi3mr_fw.c | 17 ++++-
drivers/scsi/mpi3mr/mpi3mr_os.c | 95 +++++++++++++++++++++-----
drivers/scsi/mpi3mr/mpi3mr_transport.c | 7 ++
4 files changed, 133 insertions(+), 29 deletions(-)
--
2.52.0
next reply other threads:[~2026-08-25 15:43 UTC|newest]
Thread overview: 33+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-25 21:03 Chandrakanth Patil [this message]
2026-08-25 21:03 ` [PATCH v2 01/17] mpi3mr: Fix buffer overflow in BSG passthrough request copy Chandrakanth Patil
2026-08-25 16:09 ` sashiko-bot
2026-08-25 21:03 ` [PATCH v2 02/17] mpi3mr: Fix out-of-bounds read when copying BSG MPI requests Chandrakanth Patil
2026-08-25 16:06 ` sashiko-bot
2026-08-25 21:03 ` [PATCH v2 03/17] mpi3mr: Fix I/O block counter leak on admin request post failure Chandrakanth Patil
2026-08-25 16:06 ` sashiko-bot
2026-08-25 21:03 ` [PATCH v2 04/17] mpi3mr: Fix target device reference leak in BSG task management Chandrakanth Patil
2026-08-25 16:05 ` sashiko-bot
2026-08-25 21:03 ` [PATCH v2 05/17] mpi3mr: Fix buffer overflow when caching log data Chandrakanth Patil
2026-08-25 16:12 ` sashiko-bot
2026-08-25 21:04 ` [PATCH v2 06/17] mpi3mr: Fix out-of-bounds reply frame access Chandrakanth Patil
2026-08-25 21:04 ` [PATCH v2 07/17] mpi3mr: Fix out-of-bounds sense buffer access Chandrakanth Patil
2026-08-25 16:08 ` sashiko-bot
2026-08-25 21:04 ` [PATCH v2 08/17] mpi3mr: Fix out-of-bounds bitmap access during device removal Chandrakanth Patil
2026-08-25 16:11 ` sashiko-bot
2026-08-25 21:04 ` [PATCH v2 09/17] mpi3mr: Fix target device reference leak in device removal handshake Chandrakanth Patil
2026-08-25 16:20 ` sashiko-bot
2026-08-25 21:04 ` [PATCH v2 10/17] mpi3mr: Fix out-of-bounds read in SAS topology change events Chandrakanth Patil
2026-08-25 17:15 ` sashiko-bot
2026-08-25 21:04 ` [PATCH v2 11/17] mpi3mr: Fix out-of-bounds read of event data Chandrakanth Patil
2026-08-25 16:06 ` sashiko-bot
2026-08-25 21:04 ` [PATCH v2 12/17] mpi3mr: Fix out-of-bounds phy array access on link change Chandrakanth Patil
2026-08-25 16:18 ` sashiko-bot
2026-08-25 21:04 ` [PATCH v2 13/17] mpi3mr: Fix buffer overflow in the BSG target device map Chandrakanth Patil
2026-08-25 16:07 ` sashiko-bot
2026-08-25 21:04 ` [PATCH v2 14/17] mpi3mr: Fix out-of-bounds read in PCIe topology change events Chandrakanth Patil
2026-08-25 16:10 ` sashiko-bot
2026-08-25 21:04 ` [PATCH v2 15/17] mpi3mr: zero out diagnostic buffer status memory Chandrakanth Patil
2026-08-25 21:04 ` [PATCH v2 16/17] mpi3mr: Fix use-after-free of the firmware event workqueue Chandrakanth Patil
2026-08-25 16:19 ` sashiko-bot
2026-08-25 21:04 ` [PATCH v2 17/17] mpi3mr: Fix NULL pointer dereference on PCI error recovery Chandrakanth Patil
2026-08-25 16:20 ` sashiko-bot
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260825210411.301535-1-chandrakanth.patil@broadcom.com \
--to=chandrakanth.patil@broadcom.com \
--cc=ipylypiv@google.com \
--cc=linux-scsi@vger.kernel.org \
--cc=martin.petersen@oracle.com \
--cc=ranjan.kumar@broadcom.com \
--cc=sathya.prakash@broadcom.com \
--cc=sumit.saxena@broadcom.com \
--cc=sweeti.vandure@broadcom.com \
--cc=vishakhavc@google.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.