Re: [PATCH 1/4] nvmet: fix NULL pointer dereference in nvmet_execute_identify_nslist()

Nilay Shroff <[email protected]> Thu, 30 Jul 2026 17:36:14 +0530
Newsgroups org.infradead.lists.linux-nvme
Message-ID <[email protected]>
On 7/30/26 10:01 AM, Guixin Liu wrote:
> When a host issues an Identify command with CNS 07h (Active Namespace ID
> List for a specific I/O Command Set), nvmet_execute_identify_nslist() is
> called with match_css set. The command-set filter dereferences req->ns,
> but this handler never calls nvmet_req_find_ns(), so req->ns is always
> NULL (nvmet_req_init() resets it to NULL). As soon as an enabled
> namespace with an NSID greater than the requested value exists,
> req->ns->csi dereferences a NULL pointer and oopses.
> 
> Besides the crash, the comparison is logically wrong: to filter the list
> by command set it must test the command set of the namespace being
> iterated, not a single fixed value. Use the loop variable ns->csi.
> 
> Fixes: 61c9967cd634 ("nvmet: implement active command set ns list")
> Signed-off-by: Guixin Liu <[email protected]>

Looks good to me.

Reviewed-by: Nilay Shroff <[email protected]>