Re: [PATCH 1/4] nvmet: fix NULL pointer dereference in nvmet_execute_identify_nslist()
Hannes Reinecke <[email protected]> Thu, 30 Jul 2026 10:22:07 +0200
| Newsgroups | org.infradead.lists.linux-nvme |
|---|---|
| Message-ID | <[email protected]> |
On 7/30/26 6:31 AM, Guixin Liu wrote:
> When a host issues an Identify command with CNS 07h (Active Namespace ID
> List for a specific I/O Command Set), nvmet_execute_identify_nslist() is
> called with match_css set. The command-set filter dereferences req->ns,
> but this handler never calls nvmet_req_find_ns(), so req->ns is always
> NULL (nvmet_req_init() resets it to NULL). As soon as an enabled
> namespace with an NSID greater than the requested value exists,
> req->ns->csi dereferences a NULL pointer and oopses.
>
> Besides the crash, the comparison is logically wrong: to filter the list
> by command set it must test the command set of the namespace being
> iterated, not a single fixed value. Use the loop variable ns->csi.
>
> Fixes: 61c9967cd634 ("nvmet: implement active command set ns list")
> Signed-off-by: Guixin Liu <[email protected]>
> ---
> drivers/nvme/target/admin-cmd.c | 2 +-
> 1 file changed, 1 insertion(+), 1 deletion(-)
>
> diff --git a/drivers/nvme/target/admin-cmd.c b/drivers/nvme/target/admin-cmd.c
> index 01b799e92ae6..ab6a0a98dd5d 100644
> --- a/drivers/nvme/target/admin-cmd.c
> +++ b/drivers/nvme/target/admin-cmd.c
> @@ -958,7 +958,7 @@ static void nvmet_execute_identify_nslist(struct nvmet_req *req, bool match_css)
> nvmet_for_each_enabled_ns(&ctrl->subsys->namespaces, idx, ns) {
> if (ns->nsid <= min_nsid)
> continue;
> - if (match_css && req->ns->csi != req->cmd->identify.csi)
> + if (match_css && ns->csi != req->cmd->identify.csi)
> continue;
> list[i++] = cpu_to_le32(ns->nsid);
> if (i == buf_size / sizeof(__le32))
Reviewed-by: Hannes Reinecke <[email protected]>
Cheers,
Hannes
--
Dr. Hannes Reinecke Kernel Storage Architect
[email protected] +49 911 74053 688
SUSE Software Solutions GmbH, Frankenstr. 146, 90461 Nürnberg
HRB 36809 (AG Nürnberg), GF: I. Totev, A. McDonald, W. Knoblich