[PATCH v2 0/3] scsi: libiscsi: validate task lookups driven by target-supplied ITTs
Yehyeong Lee <[email protected]> Tue, 4 Aug 2026 13:05:43 +0900
| Newsgroups | gmane.linux.scsi,gmane.linux.iscsi.open-iscsi,gmane.linux.kernel |
|---|---|
| Message-ID | <[email protected]> |
v1 was a single patch for the Reject path. The Sashiko review of it pointed at two more places where a target-supplied ITT reaches a task without being checked, and both are now in the series. 1/3 bounds the index from below. A transport that implements parse_pdu_itt can produce a negative one; be2iscsi does, and forwards an unsolicited NOP-In from the hardware with the target's ITT intact. I have no be2iscsi hardware, so this one is argued from source. 2/3 is v1 unchanged: the ITT reflected in a Reject PDU. 3/3 is the same defect at the lookup that five management responses share. An unsolicited NOP-In naming an unused index dereferences a NULL task->conn; a Text Response with the same ITT crashes a little later in iscsi_complete_task(). Measured on 7.2-rc5 with KASAN over a proxy that injects one PDU. Five attack shapes oops or warn unpatched and none of them do with the series. Normal I/O, an abort TMF, a rejected NOP-Out ping, a userspace nop sent over netlink and an iscsid-driven session are unchanged. v1: [email protected] Yehyeong Lee (3): scsi: libiscsi: reject a negative task index from parse_pdu_itt scsi: libiscsi: validate the ITT reflected in a Reject PDU scsi: libiscsi: validate the task named by a management response drivers/scsi/libiscsi.c | 13 ++++++++----- 1 file changed, 8 insertions(+), 5 deletions(-) -- 2.43.0