From: Sasha Levin <sashal@kernel.org>
To: linux-kernel@vger.kernel.org, stable@vger.kernel.org
Cc: Ye Bin <yebin10@huawei.com>,
Douglas Gilbert <dgilbert@interlog.com>,
"Martin K . Petersen" <martin.petersen@oracle.com>,
Sasha Levin <sashal@kernel.org>,
JBottomley@odin.com, linux-scsi@vger.kernel.org
Subject: [PATCH AUTOSEL 5.14 58/75] scsi: scsi_debug: Fix out-of-bound read in resp_readcap16()
Date: Tue, 9 Nov 2021 17:18:48 -0500 [thread overview]
Message-ID: <20211109221905.1234094-58-sashal@kernel.org> (raw)
In-Reply-To: <20211109221905.1234094-1-sashal@kernel.org>
From: Ye Bin <yebin10@huawei.com>
[ Upstream commit 4e3ace0051e7e504b55d239daab8789dd89b863c ]
The following warning was observed running syzkaller:
[ 3813.830724] sg_write: data in/out 65466/242 bytes for SCSI command 0x9e-- guessing data in;
[ 3813.830724] program syz-executor not setting count and/or reply_len properly
[ 3813.836956] ==================================================================
[ 3813.839465] BUG: KASAN: stack-out-of-bounds in sg_copy_buffer+0x157/0x1e0
[ 3813.841773] Read of size 4096 at addr ffff8883cf80f540 by task syz-executor/1549
[ 3813.846612] Call Trace:
[ 3813.846995] dump_stack+0x108/0x15f
[ 3813.847524] print_address_description+0xa5/0x372
[ 3813.848243] kasan_report.cold+0x236/0x2a8
[ 3813.849439] check_memory_region+0x240/0x270
[ 3813.850094] memcpy+0x30/0x80
[ 3813.850553] sg_copy_buffer+0x157/0x1e0
[ 3813.853032] sg_copy_from_buffer+0x13/0x20
[ 3813.853660] fill_from_dev_buffer+0x135/0x370
[ 3813.854329] resp_readcap16+0x1ac/0x280
[ 3813.856917] schedule_resp+0x41f/0x1630
[ 3813.858203] scsi_debug_queuecommand+0xb32/0x17e0
[ 3813.862699] scsi_dispatch_cmd+0x330/0x950
[ 3813.863329] scsi_request_fn+0xd8e/0x1710
[ 3813.863946] __blk_run_queue+0x10b/0x230
[ 3813.864544] blk_execute_rq_nowait+0x1d8/0x400
[ 3813.865220] sg_common_write.isra.0+0xe61/0x2420
[ 3813.871637] sg_write+0x6c8/0xef0
[ 3813.878853] __vfs_write+0xe4/0x800
[ 3813.883487] vfs_write+0x17b/0x530
[ 3813.884008] ksys_write+0x103/0x270
[ 3813.886268] __x64_sys_write+0x77/0xc0
[ 3813.886841] do_syscall_64+0x106/0x360
[ 3813.887415] entry_SYSCALL_64_after_hwframe+0x44/0xa9
This issue can be reproduced with the following syzkaller log:
r0 = openat(0xffffffffffffff9c, &(0x7f0000000040)='./file0\x00', 0x26e1, 0x0)
r1 = syz_open_procfs(0xffffffffffffffff, &(0x7f0000000000)='fd/3\x00')
open_by_handle_at(r1, &(0x7f00000003c0)=ANY=[@ANYRESHEX], 0x602000)
r2 = syz_open_dev$sg(&(0x7f0000000000), 0x0, 0x40782)
write$binfmt_aout(r2, &(0x7f0000000340)=ANY=[@ANYBLOB="00000000deff000000000000000000000000000000000000000000000000000047f007af9e107a41ec395f1bded7be24277a1501ff6196a83366f4e6362bc0ff2b247f68a972989b094b2da4fb3607fcf611a22dd04310d28c75039d"], 0x126)
In resp_readcap16() we get "int alloc_len" value -1104926854, and then pass
the huge arr_len to fill_from_dev_buffer(), but arr is only 32 bytes. This
leads to OOB in sg_copy_buffer().
To solve this issue, define alloc_len as u32.
Link: https://lore.kernel.org/r/20211013033913.2551004-2-yebin10@huawei.com
Acked-by: Douglas Gilbert <dgilbert@interlog.com>
Signed-off-by: Ye Bin <yebin10@huawei.com>
Signed-off-by: Martin K. Petersen <martin.petersen@oracle.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
---
drivers/scsi/scsi_debug.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/drivers/scsi/scsi_debug.c b/drivers/scsi/scsi_debug.c
index 5b3a20a140f9e..a5125df0b7842 100644
--- a/drivers/scsi/scsi_debug.c
+++ b/drivers/scsi/scsi_debug.c
@@ -1856,7 +1856,7 @@ static int resp_readcap16(struct scsi_cmnd *scp,
{
unsigned char *cmd = scp->cmnd;
unsigned char arr[SDEBUG_READCAP16_ARR_SZ];
- int alloc_len;
+ u32 alloc_len;
alloc_len = get_unaligned_be32(cmd + 10);
/* following just in case virtual_gb changed */
@@ -1885,7 +1885,7 @@ static int resp_readcap16(struct scsi_cmnd *scp,
}
return fill_from_dev_buffer(scp, arr,
- min_t(int, alloc_len, SDEBUG_READCAP16_ARR_SZ));
+ min_t(u32, alloc_len, SDEBUG_READCAP16_ARR_SZ));
}
#define SDEBUG_MAX_TGTPGS_ARR_SZ 1412
--
2.33.0
next prev parent reply other threads:[~2021-11-09 22:28 UTC|newest]
Thread overview: 75+ messages / expand[flat|nested] mbox.gz Atom feed top
2021-11-09 22:17 [PATCH AUTOSEL 5.14 01/75] arm64: zynqmp: Do not duplicate flash partition label property Sasha Levin
2021-11-09 22:17 ` [PATCH AUTOSEL 5.14 02/75] arm64: zynqmp: Fix serial compatible string Sasha Levin
2021-11-09 22:17 ` [PATCH AUTOSEL 5.14 03/75] clk: sunxi-ng: Unregister clocks/resets when unbinding Sasha Levin
2021-11-09 22:17 ` [PATCH AUTOSEL 5.14 04/75] ARM: dts: sunxi: Fix OPPs node name Sasha Levin
2021-11-09 22:17 ` [PATCH AUTOSEL 5.14 05/75] arm64: dts: allwinner: h5: Fix GPU thermal zone " Sasha Levin
2021-11-09 22:17 ` [PATCH AUTOSEL 5.14 06/75] arm64: dts: allwinner: a100: Fix " Sasha Levin
2021-11-09 22:17 ` [PATCH AUTOSEL 5.14 07/75] staging: wfx: ensure IRQ is ready before enabling it Sasha Levin
2021-11-09 22:17 ` [PATCH AUTOSEL 5.14 08/75] ARM: dts: BCM5301X: Fix nodes names Sasha Levin
2021-11-09 22:17 ` [PATCH AUTOSEL 5.14 09/75] ARM: dts: BCM5301X: Fix MDIO mux binding Sasha Levin
2021-11-09 22:18 ` [PATCH AUTOSEL 5.14 10/75] ARM: dts: NSP: Fix mpcore, mmc node names Sasha Levin
2021-11-09 22:18 ` [PATCH AUTOSEL 5.14 11/75] arm64: dts: broadcom: bcm4908: Move reboot syscon out of bus Sasha Levin
2021-11-09 22:18 ` [PATCH AUTOSEL 5.14 12/75] scsi: pm80xx: Fix memory leak during rmmod Sasha Levin
2021-11-09 22:18 ` [PATCH AUTOSEL 5.14 13/75] scsi: lpfc: Fix list_add() corruption in lpfc_drain_txq() Sasha Levin
2021-11-09 22:18 ` [PATCH AUTOSEL 5.14 14/75] arm64: dts: rockchip: Disable CDN DP on Pinebook Pro Sasha Levin
2021-11-09 22:18 ` [PATCH AUTOSEL 5.14 15/75] arm64: dts: hisilicon: fix arm,sp805 compatible string Sasha Levin
2021-11-09 22:18 ` [PATCH AUTOSEL 5.14 16/75] arm64: dts: rockchip: add Coresight debug range for RK3399 Sasha Levin
2021-11-09 22:18 ` [PATCH AUTOSEL 5.14 17/75] RDMA/bnxt_re: Check if the vlan is valid before reporting Sasha Levin
2021-11-09 22:18 ` [PATCH AUTOSEL 5.14 18/75] bus: ti-sysc: Add quirk handling for reinit on context lost Sasha Levin
2021-11-09 22:18 ` [PATCH AUTOSEL 5.14 19/75] bus: ti-sysc: Use context lost quirk for otg Sasha Levin
2021-11-09 22:18 ` [PATCH AUTOSEL 5.14 20/75] usb: musb: tusb6010: check return value after calling platform_get_resource() Sasha Levin
2021-11-09 22:18 ` [PATCH AUTOSEL 5.14 21/75] usb: typec: tipd: Remove WARN_ON in tps6598x_block_read Sasha Levin
2021-11-09 22:18 ` [PATCH AUTOSEL 5.14 22/75] ARM: dts: ux500: Skomer regulator fixes Sasha Levin
2021-11-09 22:18 ` [PATCH AUTOSEL 5.14 23/75] staging: rtl8723bs: remove possible deadlock when disconnect (v2) Sasha Levin
2021-11-09 22:18 ` [PATCH AUTOSEL 5.14 24/75] staging: rtl8723bs: remove a third possible deadlock Sasha Levin
2021-11-09 22:18 ` [PATCH AUTOSEL 5.14 25/75] ARM: BCM53016: Specify switch ports for Meraki MR32 Sasha Levin
2021-11-09 22:18 ` [PATCH AUTOSEL 5.14 26/75] arm64: dts: qcom: msm8998: Fix CPU/L2 idle state latency and residency Sasha Levin
2021-11-09 22:18 ` [PATCH AUTOSEL 5.14 27/75] arm64: dts: qcom: ipq6018: Fix qcom,controlled-remotely property Sasha Levin
2021-11-09 22:18 ` [PATCH AUTOSEL 5.14 28/75] arm64: dts: qcom: sdm845: " Sasha Levin
2021-11-09 22:18 ` [PATCH AUTOSEL 5.14 29/75] arm64: dts: qcom: msm8916: Add unit name for /soc node Sasha Levin
2021-11-09 22:18 ` [PATCH AUTOSEL 5.14 30/75] arm64: dts: freescale: fix arm,sp805 compatible string Sasha Levin
2021-11-09 22:18 ` [PATCH AUTOSEL 5.14 31/75] arm64: dts: ls1012a: Add serial alias for ls1012a-rdb Sasha Levin
2021-11-09 22:18 ` [PATCH AUTOSEL 5.14 32/75] RDMA/rxe: Separate HW and SW l/rkeys Sasha Levin
2021-11-09 22:18 ` [PATCH AUTOSEL 5.14 33/75] ASoC: SOF: Intel: hda-dai: fix potential locking issue Sasha Levin
2021-11-09 22:18 ` [PATCH AUTOSEL 5.14 34/75] scsi: core: Fix scsi_mode_sense() buffer length handling Sasha Levin
2021-11-09 22:18 ` [PATCH AUTOSEL 5.14 35/75] ALSA: usb-audio: disable implicit feedback sync for Behringer UFX1204 and UFX1604 Sasha Levin
2021-11-09 22:18 ` [PATCH AUTOSEL 5.14 36/75] clk: imx: imx6ul: Move csi_sel mux to correct base register Sasha Levin
2021-11-09 22:18 ` [PATCH AUTOSEL 5.14 37/75] ASoC: es8316: Use IRQF_NO_AUTOEN when requesting the IRQ Sasha Levin
2021-11-09 22:18 ` [PATCH AUTOSEL 5.14 38/75] ASoC: rt5651: " Sasha Levin
2021-11-09 22:18 ` [PATCH AUTOSEL 5.14 39/75] ASoC: nau8824: Add DMI quirk mechanism for active-high jack-detect Sasha Levin
2021-11-09 22:18 ` [PATCH AUTOSEL 5.14 40/75] scsi: advansys: Fix kernel pointer leak Sasha Levin
2021-11-09 22:18 ` [PATCH AUTOSEL 5.14 41/75] scsi: smartpqi: Add controller handshake during kdump Sasha Levin
2021-11-09 22:18 ` [PATCH AUTOSEL 5.14 42/75] arm64: dts: imx8mm-kontron: Fix reset delays for ethernet PHY Sasha Levin
2021-11-09 22:18 ` [PATCH AUTOSEL 5.14 43/75] ALSA: intel-dsp-config: add quirk for APL/GLK/TGL devices based on ES8336 codec Sasha Levin
2021-11-09 22:18 ` [PATCH AUTOSEL 5.14 44/75] ASoC: Intel: soc-acpi: add missing quirk for TGL SDCA single amp Sasha Levin
2021-11-09 22:18 ` [PATCH AUTOSEL 5.14 45/75] ASoC: Intel: sof_sdw: add missing quirk for Dell SKU 0A45 Sasha Levin
2021-11-09 22:18 ` [PATCH AUTOSEL 5.14 46/75] firmware_loader: fix pre-allocated buf built-in firmware use Sasha Levin
2021-11-09 22:18 ` [PATCH AUTOSEL 5.14 47/75] cpuidle: tegra: Check whether PMC is ready Sasha Levin
2021-11-09 22:18 ` [PATCH AUTOSEL 5.14 48/75] HID: multitouch: disable sticky fingers for UPERFECT Y Sasha Levin
2021-11-09 22:18 ` [PATCH AUTOSEL 5.14 49/75] ALSA: usb-audio: Add support for the Pioneer DJM 750MK2 Mixer/Soundcard Sasha Levin
2021-11-09 22:18 ` [PATCH AUTOSEL 5.14 50/75] ARM: dts: omap: fix gpmc,mux-add-data type Sasha Levin
2021-11-09 22:18 ` [PATCH AUTOSEL 5.14 51/75] usb: host: ohci-tmio: check return value after calling platform_get_resource() Sasha Levin
2021-11-09 22:18 ` [PATCH AUTOSEL 5.14 52/75] ARM: dts: ls1021a: move thermal-zones node out of soc/ Sasha Levin
2021-11-09 22:18 ` [PATCH AUTOSEL 5.14 53/75] ARM: dts: ls1021a-tsn: use generic "jedec,spi-nor" compatible for flash Sasha Levin
2021-11-09 22:18 ` [PATCH AUTOSEL 5.14 54/75] ALSA: ISA: not for M68K Sasha Levin
2021-11-09 22:18 ` [PATCH AUTOSEL 5.14 55/75] iommu/vt-d: Do not falsely log intel_iommu is unsupported kernel option Sasha Levin
2021-11-09 22:18 ` [PATCH AUTOSEL 5.14 56/75] tty: tty_buffer: Fix the softlockup issue in flush_to_ldisc Sasha Levin
2021-11-09 22:18 ` [PATCH AUTOSEL 5.14 57/75] MIPS: sni: Fix the build Sasha Levin
2021-11-09 22:18 ` Sasha Levin [this message]
2021-11-09 22:18 ` [PATCH AUTOSEL 5.14 59/75] scsi: scsi_debug: Fix out-of-bound read in resp_report_tgtpgs() Sasha Levin
2021-11-09 22:18 ` [PATCH AUTOSEL 5.14 60/75] scsi: target: Fix ordered tag handling Sasha Levin
2021-11-09 22:18 ` [PATCH AUTOSEL 5.14 61/75] scsi: target: Fix alua_tg_pt_gps_count tracking Sasha Levin
2021-11-09 22:18 ` [PATCH AUTOSEL 5.14 62/75] iio: imu: st_lsm6dsx: Avoid potential array overflow in st_lsm6dsx_set_odr() Sasha Levin
2021-11-09 22:18 ` [PATCH AUTOSEL 5.14 63/75] RDMA/core: Use kvzalloc when allocating the struct ib_port Sasha Levin
2021-11-09 22:18 ` [PATCH AUTOSEL 5.14 64/75] scsi: lpfc: Fix use-after-free in lpfc_unreg_rpi() routine Sasha Levin
2021-11-09 22:18 ` [PATCH AUTOSEL 5.14 65/75] scsi: lpfc: Fix link down processing to address NULL pointer dereference Sasha Levin
2021-11-09 22:18 ` [PATCH AUTOSEL 5.14 66/75] memory: tegra20-emc: Add runtime dependency on devfreq governor module Sasha Levin
2021-11-09 22:18 ` [PATCH AUTOSEL 5.14 67/75] powerpc/5200: dts: fix memory node unit name Sasha Levin
2021-11-09 22:18 ` [PATCH AUTOSEL 5.14 68/75] arm64: dts: qcom: msm8916: Add CPU ACC and SAW/SPM Sasha Levin
2021-11-09 22:18 ` [PATCH AUTOSEL 5.14 69/75] ARM: dts: qcom: fix memory and mdio nodes naming for RB3011 Sasha Levin
2021-11-09 22:19 ` [PATCH AUTOSEL 5.14 70/75] ALSA: gus: fix null pointer dereference on pointer block Sasha Levin
2021-11-09 22:19 ` [PATCH AUTOSEL 5.14 71/75] ALSA: usb-audio: fix null pointer dereference on pointer cs_desc Sasha Levin
2021-11-09 22:19 ` [PATCH AUTOSEL 5.14 72/75] clk: at91: sama7g5: remove prescaler part of master clock Sasha Levin
2021-11-09 22:19 ` [PATCH AUTOSEL 5.14 73/75] powerpc/dcr: Use cmplwi instead of 3-argument cmpli Sasha Levin
2021-11-09 22:19 ` [PATCH AUTOSEL 5.14 74/75] powerpc/8xx: Fix Oops with STRICT_KERNEL_RWX without DEBUG_RODATA_TEST Sasha Levin
2021-11-09 22:19 ` [PATCH AUTOSEL 5.14 75/75] HID: playstation: require multicolor LED functionality Sasha Levin
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20211109221905.1234094-58-sashal@kernel.org \
--to=sashal@kernel.org \
--cc=JBottomley@odin.com \
--cc=dgilbert@interlog.com \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-scsi@vger.kernel.org \
--cc=martin.petersen@oracle.com \
--cc=stable@vger.kernel.org \
--cc=yebin10@huawei.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox