From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 30821355F42; Wed, 30 Sep 2026 16:48:55 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790786937; cv=none; b=UGMsp4uZGnj2wMfhuQ2U1H5AkqpUk+PudfeF3PD4q0S7G5Dw4ZsznZfsA4K3gdfS9dF3tMa1j5q0z5Ex6b5kstSZIRTuVDLSrCiG6MNJ3YwTunS8WpHteHdLpFmVoYiE/qDbSAcKerf2G3sSYwNz9GnlpbPdHm2oP9LVTyckiaQ= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790786937; c=relaxed/simple; bh=wmS9381vBRUIdueZ8Ir4pzHp4cfEeoZjSuUAjZ8Dxr4=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=gAADW/FG0hHOSILcGI/3Jtt1142pCJsMVDHHk2GDRs8e83Yi1nxt4IWVE3DmMHxrXNeM4bltbdFRVA4Y4wFXPcs8J1a3fHPT8Yib7bxsYBkHGoDLlYU30L08P7PXzliFcijv7YRRT3o5iiMZTy4P4xKtwxBqSWYeESpC+2PRH1E= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=1Muj9bRb; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="1Muj9bRb" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 4B61D1F00893; Wed, 30 Sep 2026 16:48:55 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxfoundation.org; s=korg; t=1790786935; bh=sJ6WSd7Ll14RbBbhtzmtWCnk7JWAGLRfvnhQh1vVEHo=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=1Muj9bRb047jkM6WXbGCOTZCqPALOucbD2vy0w7nix0YMdD52KTPIf941OqI6UAm8 bd1Ow9WmSRAtF/MoLujDrDorU3pblzI85542rld/cNglPzp2JOm5mmr65+dwDK7Mm3 EPXYDcRiU6uma5f/X5LPqDoHfQrEyw7X9MJISdsA= From: Greg Kroah-Hartman To: stable@vger.kernel.org Cc: Greg Kroah-Hartman , patches@lists.linux.dev, ZHOU Jiaxiang , Damien Le Moal , "Martin K. Petersen (Oracle)" , Sasha Levin Subject: [PATCH 7.2 052/457] scsi: sd_zbc: Reject disks with too many zones Date: Wed, 30 Sep 2026 17:22:37 +0200 Message-ID: <20260930152347.158686762@linuxfoundation.org> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260930152346.024115587@linuxfoundation.org> References: <20260930152346.024115587@linuxfoundation.org> User-Agent: quilt/0.69 X-stable: review X-Patchwork-Hint: ignore Precedence: bulk X-Mailing-List: patches@lists.linux.dev List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit 7.2-stable review patch. If anyone has any objections, please let me know. ------------------ From: ZHOU Jiaxiang [ Upstream commit b6ec0f79745967c751c85df373062c8d15e45fc4 ] sd_zbc_read_zones() computes the number of zones with 64-bit arithmetic and stores the result in the unsigned int nr_zones field of struct zoned_disk_info, silently truncating counts that exceed 32 bits. The truncated count is later used to size per-zone resources, while the device may still report more zones than fit. Moreover, sd_zbc_report_zones() counts the reported zones with a signed int zone_idx, which overflows past INT_MAX. Reject devices reporting more than INT_MAX zones at scan time; such a device is not realistic for any medium that exists today, and accepting it produces inconsistent zone bookkeeping. Fixes: 89d947561077 ("sd: Implement support for ZBC devices") Signed-off-by: ZHOU Jiaxiang Reviewed-by: Damien Le Moal Link: https://patch.msgid.link/C41798AB5AA6BF2B+20260916135822.32584-3-me@fxti.xyz Signed-off-by: Martin K. Petersen (Oracle) Signed-off-by: Sasha Levin --- drivers/scsi/sd_zbc.c | 8 +++++++- 1 file changed, 7 insertions(+), 1 deletion(-) diff --git a/drivers/scsi/sd_zbc.c b/drivers/scsi/sd_zbc.c index 56e455fb5addd..456beaf2e7690 100644 --- a/drivers/scsi/sd_zbc.c +++ b/drivers/scsi/sd_zbc.c @@ -589,7 +589,7 @@ int sd_zbc_revalidate_zones(struct scsi_disk *sdkp) int sd_zbc_read_zones(struct scsi_disk *sdkp, struct queue_limits *lim, u8 buf[SD_BUF_SIZE]) { - unsigned int nr_zones; + u64 nr_zones; u32 zone_blocks = 0; int ret; @@ -621,6 +621,12 @@ int sd_zbc_read_zones(struct scsi_disk *sdkp, struct queue_limits *lim, goto err; nr_zones = round_up(sdkp->capacity, zone_blocks) >> ilog2(zone_blocks); + if (nr_zones > INT_MAX) { + sd_printk(KERN_ERR, sdkp, "Too many zones (%llu)\n", + nr_zones); + ret = -EINVAL; + goto err; + } sdkp->early_zone_info.nr_zones = nr_zones; sdkp->early_zone_info.zone_blocks = zone_blocks; -- 2.53.0