Re: [PATCH 1/4] nvmet: fix NULL pointer dereference in nvmet_execute_identify_nslist()
Nilay Shroff <[email protected]> Thu, 30 Jul 2026 17:36:14 +0530
| Newsgroups | org.infradead.lists.linux-nvme |
|---|---|
| Message-ID | <[email protected]> |
On 7/30/26 10:01 AM, Guixin Liu wrote:
> When a host issues an Identify command with CNS 07h (Active Namespace ID
> List for a specific I/O Command Set), nvmet_execute_identify_nslist() is
> called with match_css set. The command-set filter dereferences req->ns,
> but this handler never calls nvmet_req_find_ns(), so req->ns is always
> NULL (nvmet_req_init() resets it to NULL). As soon as an enabled
> namespace with an NSID greater than the requested value exists,
> req->ns->csi dereferences a NULL pointer and oopses.
>
> Besides the crash, the comparison is logically wrong: to filter the list
> by command set it must test the command set of the namespace being
> iterated, not a single fixed value. Use the loop variable ns->csi.
>
> Fixes: 61c9967cd634 ("nvmet: implement active command set ns list")
> Signed-off-by: Guixin Liu <[email protected]>
Looks good to me.
Reviewed-by: Nilay Shroff <[email protected]>