From: Hannes Reinecke <hare@suse.de>
To: Guixin Liu <kanie@linux.alibaba.com>,
Christoph Hellwig <hch@lst.de>, Sagi Grimberg <sagi@grimberg.me>,
Chaitanya Kulkarni <kch@nvidia.com>, Jens Axboe <axboe@kernel.dk>
Cc: linux-nvme@lists.infradead.org
Subject: Re: [PATCH] nvmet: fix heap out-of-bounds read in nvmet_auth_negotiate()
Date: Tue, 4 Aug 2026 09:24:05 +0200 [thread overview]
Message-ID: <aa77d2d4-7e1f-4fef-a2d7-ca4aab1dc03c@suse.de> (raw)
In-Reply-To: <20260804033800.3975537-1-kanie@linux.alibaba.com>
On 8/4/26 5:38 AM, Guixin Liu wrote:
> nvmet_execute_auth_send() allocates the DH-HMAC-CHAP message buffer with
> the host-supplied transfer length (tl) and hands it to
> nvmet_auth_negotiate() without passing tl along. nvmet_auth_negotiate()
> then reads the negotiate header and, for each of the halen hash
> identifiers and dhlen DH group identifiers, indexes into the fixed
> idlist[60] array (hashes at idlist[0..halen), groups at idlist[30..]).
>
> Neither the transfer length nor halen/dhlen is validated. A malicious or
> non-conformant host can report a tl smaller than the negotiate structure,
> or a halen/dhlen larger than the array (both are u8, up to 255), making
> the loops read past the end of the allocated buffer (heap out-of-bounds
> read). The sibling nvmet_auth_reply() already validates tl against the
> structure size; the negotiate path did not.
>
> Pass tl into nvmet_auth_negotiate(), reject a tl that does not cover the
> negotiate data plus one full protocol descriptor, and reject halen/dhlen
> larger than NVME_AUTH_DHCHAP_MAX_DH_IDS.
>
> Fixes: db1312dd9548 ("nvmet: implement basic In-Band Authentication")
> Signed-off-by: Guixin Liu <kanie@linux.alibaba.com>
> ---
> drivers/nvme/target/fabrics-cmd-auth.c | 12 ++++++++++--
> 1 file changed, 10 insertions(+), 2 deletions(-)
>
Reviewed-by: Hannes Reinecke <hare@kernel.org>
Cheers,
Hannes
--
Dr. Hannes Reinecke Kernel Storage Architect
hare@suse.de +49 911 74053 688
SUSE Software Solutions GmbH, Frankenstr. 146, 90461 Nürnberg
HRB 36809 (AG Nürnberg), GF: I. Totev, A. McDonald, W. Knoblich
next prev parent reply other threads:[~2026-08-04 7:24 UTC|newest]
Thread overview: 5+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-04 3:38 [PATCH] nvmet: fix heap out-of-bounds read in nvmet_auth_negotiate() Guixin Liu
2026-08-04 7:24 ` Hannes Reinecke [this message]
2026-08-04 16:19 ` Christoph Hellwig
2026-08-05 1:48 ` Guixin Liu
2026-08-10 19:37 ` Keith Busch
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=aa77d2d4-7e1f-4fef-a2d7-ca4aab1dc03c@suse.de \
--to=hare@suse.de \
--cc=axboe@kernel.dk \
--cc=hch@lst.de \
--cc=kanie@linux.alibaba.com \
--cc=kch@nvidia.com \
--cc=linux-nvme@lists.infradead.org \
--cc=sagi@grimberg.me \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.