Re: [PATCH v2] nvme/070: add a test for Identify CNS 07h NULL pointer dereference

Shin'ichiro Kawasaki <[email protected]>
Newsgroups org.infradead.lists.linux-nvme
Message-ID <ansFVrVVtnxfhi0Y@shinmob>
On Aug 04, 2026 / 10:46, Guixin Liu wrote:
> nvmet_execute_identify_nslist() handles both the Active Namespace ID list
> (CNS 02h) and the per-command-set variant (CNS 07h). For CNS 07h it
> filtered the list on req->ns->csi, but this handler never resolves
> req->ns, so it is always NULL. As soon as an enabled namespace with an
> NSID above the requested value exists, the target dereferenced a NULL
> pointer and oopsed.
> 
> This test connects a target with a single namespace and issues an
> Identify with CNS 07h starting from NSID 0, which is exactly the
> condition that triggered the crash. Without the kernel fix [0] the target
> oopses; with it the command completes normally.
> 
> [0] https://lore.kernel.org/linux-nvme/[email protected]/
> 
> Suggested-by: Christoph Hellwig <[email protected]>
> Signed-off-by: Guixin Liu <[email protected]>
> ---
> v1 -> v2:
>   - Use "nvme list-ns --csi=0" instead of a raw admin-passthru to issue
>     Identify CNS 07h, as suggested by Nilay and Shinichiro; it drives the
>     same target code path via the existing nvme-cli subcommand.

Thanks for this v2 patch. It looks good to me. I will wait for the kernel side
fix get settled on Linus master branch before I apply this patch.
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.