Re: [PATCH 4/4] nvme: clamp FDP placement handle count to the buffer size
Nilay Shroff <[email protected]> Thu, 30 Jul 2026 17:38:17 +0530
| Newsgroups | org.infradead.lists.linux-nvme |
|---|---|
| Message-ID | <[email protected]> |
On 7/30/26 10:01 AM, Guixin Liu wrote:
> nvme_query_fdp_info() allocates the RUH status buffer for at most
> S8_MAX - 1 descriptors and caps the io-mgmt-receive transfer to that
> size. head->nr_plids, however, is taken verbatim from the device-supplied
> nruhsd field, which can be up to 65535. If a non-conformant or malicious
> device reports more descriptors than the buffer holds, the copy loop
> reads past the end of the ruhs buffer (heap out-of-bounds read).
>
> Clamp nr_plids to the number of descriptors the buffer can actually hold.
>
> Fixes: 30b5f20bb2dd ("nvme: register fdp parameters with the block layer")
> Signed-off-by: Guixin Liu<[email protected]>
Looks good to me.
Reviewed-by: Nilay Shroff <[email protected]>