[PATCH v2 0/3] scsi: libiscsi: validate task lookups driven by target-supplied ITTs

Yehyeong Lee <[email protected]> Tue, 4 Aug 2026 13:05:43 +0900
Newsgroups gmane.linux.scsi,gmane.linux.iscsi.open-iscsi,gmane.linux.kernel
Message-ID <[email protected]>
v1 was a single patch for the Reject path. The Sashiko review of it
pointed at two more places where a target-supplied ITT reaches a task
without being checked, and both are now in the series.

1/3 bounds the index from below. A transport that implements
parse_pdu_itt can produce a negative one; be2iscsi does, and forwards an
unsolicited NOP-In from the hardware with the target's ITT intact. I
have no be2iscsi hardware, so this one is argued from source.

2/3 is v1 unchanged: the ITT reflected in a Reject PDU.

3/3 is the same defect at the lookup that five management responses
share. An unsolicited NOP-In naming an unused index dereferences a NULL
task->conn; a Text Response with the same ITT crashes a little later in
iscsi_complete_task().

Measured on 7.2-rc5 with KASAN over a proxy that injects one PDU. Five
attack shapes oops or warn unpatched and none of them do with the
series. Normal I/O, an abort TMF, a rejected NOP-Out ping, a userspace
nop sent over netlink and an iscsid-driven session are unchanged.

v1: [email protected]

Yehyeong Lee (3):
  scsi: libiscsi: reject a negative task index from parse_pdu_itt
  scsi: libiscsi: validate the ITT reflected in a Reject PDU
  scsi: libiscsi: validate the task named by a management response

 drivers/scsi/libiscsi.c | 13 ++++++++-----
 1 file changed, 8 insertions(+), 5 deletions(-)

-- 
2.43.0