Re: [PATCH] scsi: mpt3sas: avoid out-of-bounds cpumask_of_node() call in _base_assign_reply_queues()

Johannes Thumshirn <[email protected]>
Newsgroups gmane.linux.scsi,gmane.linux.kernel
Message-ID <[email protected]>
On Mon, Aug 17, 2026 at 04:13:00PM -0600, Ivy Lopez wrote:
> dev_to_node() can return NUMA_NO_NODE (-1) on systems without NUMA
> topology information for the PCI device, such as single-socket
> boards that don't expose device-to-node affinity. Passing -1
> directly into cpumask_of_node() indexes node_to_cpumask_map[-1],
> an out-of-bounds array read caught by UBSAN:
> 
>   UBSAN: array-index-out-of-bounds in arch/x86/include/asm/topology.h:72:28
>   index -1 is out of range for type 'cpumask *[1024]'
> 
> Fall back to cpu_online_mask when no NUMA node is available, rather
> than assuming dev_to_node() always returns a valid node index.
> 
> Link: https://bugzilla.kernel.org/show_bug.cgi?id=221294
> Signed-off-by: Ivy Lopez <[email protected]>
> ---
>  drivers/scsi/mpt3sas/mpt3sas_base.c | 4 +++-
>  1 file changed, 3 insertions(+), 1 deletion(-)
> 
> diff --git a/drivers/scsi/mpt3sas/mpt3sas_base.c b/drivers/scsi/mpt3sas/mpt3sas_base.c
> index 79052f2accbd..eaad6fb7f3cf 100644
> --- a/drivers/scsi/mpt3sas/mpt3sas_base.c
> +++ b/drivers/scsi/mpt3sas/mpt3sas_base.c
> @@ -3238,7 +3238,9 @@ _base_assign_reply_queues(struct MPT3SAS_ADAPTER *ioc)
>  		 * corresponding to high iops queues.
>  		 */
>  		if (ioc->high_iops_queues) {
> -			mask = cpumask_of_node(dev_to_node(&ioc->pdev->dev));
> +			int node = (dev_to_node(&ioc->pdev->dev));

Why the superfluous parenthesis?

> +
> +			mask = (node == NUMA_NO_NODE) ? cpu_online_mask : cpumask_of_node(node);

Overly long line here.

>  			for (index = 0; index < ioc->high_iops_queues;
>  			    index++) {
>  				irq = pci_irq_vector(ioc->pdev, index);
> -- 
> 2.55.0
> 
>
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.