Re: [syzbot] [nvme?] KASAN: slab-out-of-bounds Read in nvmet_install_queue

"Maurizio Lombardi" <[email protected]>
Newsgroups gmane.linux.kernel
Message-ID <[email protected]>
On Fri Aug 7, 2026 at 2:01 AM CEST, syzbot wrote:
> Hello,
>
> syzbot found the following issue on:
>
>
> ==================================================================
> BUG: KASAN: slab-out-of-bounds in nvmet_install_queue+0x522/0x590 drivers/nvme/target/fabrics-cmd.c:189
> Read of size 8 at addr ffff888058219a70 by task kworker/u33:8/1166
>
> CPU: 1 UID: 0 PID: 1166 Comm: kworker/u33:8 Not tainted syzkaller #0 PREEMPT(full) 
> Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2 04/01/2014
> Workqueue: nvmet-wq nvme_loop_execute_work
> Call Trace:
>  <TASK>
>  __dump_stack lib/dump_stack.c:94 [inline]
>  dump_stack_lvl+0x100/0x190 lib/dump_stack.c:120
>  print_address_description mm/kasan/report.c:378 [inline]
>  print_report+0x13d/0x4b0 mm/kasan/report.c:482
>  kasan_report+0xdf/0x1c0 mm/kasan/report.c:595
>  nvmet_install_queue+0x522/0x590 drivers/nvme/target/fabrics-cmd.c:189
>  nvmet_execute_io_connect+0x294/0x490 drivers/nvme/target/fabrics-cmd.c:380

I am able to reproduce it, the problem is that
nvmet_subsys_attr_qid_max_store() can race against
nvmet_alloc_control().

Suppose max_qid is 64.
nvmet_alloc_ctrl() executed ctrl->sqs = kzalloc_objs(struct nvmet_sq *, subsys->max_qid + 1);

at this point a userspace process changes max_qid to 128.
nvmet_subsys_attr_qid_max_store() sets the new max_qid value but
the new controller won't be deleted because it hasn't been added to the
subsys->ctrls list yet.


nvmet_alloc_ctrl() proceeds and adds the new controller to the
subsys->ctrls list.

Now nvmet_install_queue() will be called with max_qid set to 128, but
the memory allocated for sqs is just for 64 entries, hence the KASAN
warning.

I will try to prepare a patch.

Maurizio
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.