CVE-2026-74470: scsi: scsi_debug: Fix REPORT ZONES alloc_len underflow OOB write
Greg Kroah-Hartman <[email protected]>
| Newsgroups | org.kernel.vger.linux-cve-announce |
|---|---|
| Message-ID | <2026081534-CVE-2026-74470-6792@gregkh> |
From: Greg Kroah-Hartman <[email protected]> Description =========== In the Linux kernel, the following vulnerability has been resolved: scsi: scsi_debug: Fix REPORT ZONES alloc_len underflow OOB write resp_report_zones() sizes the reply buffer from the CDB allocation length. The v3 fix rounds alloc_len up with ALIGN() before deriving the descriptor count: rep_max_zones = (ALIGN((u64)alloc_len, RZONES_DESC_HD) - RZONES_DESC_HD) >> ilog2(RZONES_DESC_HD); arr_len = (u64)RZONES_DESC_HD * (rep_max_zones + 1); For alloc_len in 0xFFFFFFC1..0xFFFFFFFF, ALIGN() rounds up to 0x100000000, so arr_len is 4 GB. On 32-bit, kzalloc()'s size_t is 32-bit and truncates 0x100000000 to 0; kzalloc(0) returns ZERO_SIZE_PTR, which passes the !arr check, and desc = arr + 64 is then dereferenced in the loop -> out-of-bounds write / panic. Clamp rep_max_zones to devip->nr_zones. The loop already stops at sdebug_capacity (after nr_zones zones), so a report can never hold more than nr_zones descriptors; the clamp does not change the report, it only bounds arr_len to (nr_zones + 1) * RZONES_DESC_HD, a real device property that can never reach 0x100000000. The Linux kernel CVE team has assigned CVE-2026-74470 to this issue. Affected and fixed versions =========================== Issue introduced in 5.16 with commit 7db0e0c8190a086ef92ce5bb960836cde49540aa and fixed in 6.6.151 with commit 49e5b25a0b74dbac595f122e5608fdce2918cc4e Issue introduced in 5.16 with commit 7db0e0c8190a086ef92ce5bb960836cde49540aa and fixed in 6.12.103 with commit 495058429ca55ab7fcc21977b63b92907ad68066 Issue introduced in 5.16 with commit 7db0e0c8190a086ef92ce5bb960836cde49540aa and fixed in 6.18.44 with commit 2047ed09bf13453b7d6f9431b112ec07984dd69b Issue introduced in 5.16 with commit 7db0e0c8190a086ef92ce5bb960836cde49540aa and fixed in 7.1.8 with commit d6e6da6bc3b53231fac77ffab428da8173ee729c Issue introduced in 5.16 with commit 7db0e0c8190a086ef92ce5bb960836cde49540aa and fixed in 7.2-rc6 with commit 93dde0bf2f39a0f9f57fd610aa3201ce5b753433 Issue introduced in 5.10.85 with commit c4d2d7c935a4ad20e8e726ca10499cefe4537103 Issue introduced in 5.15.8 with commit ebacb44cb2042b90951140eda806bedad23ef554 Please see https://www.kernel.org for a full list of currently supported kernel versions by the kernel community. Unaffected versions might change over time as fixes are backported to older supported kernel versions. The official CVE entry at https://cve.org/CVERecord/?id=CVE-2026-74470 will be updated if fixes are backported, please check that for the most up to date information about this issue. Affected files ============== The file(s) affected by this issue are: drivers/scsi/scsi_debug.c Mitigation ========== The Linux kernel CVE team recommends that you update to the latest stable kernel version for this, and many other bugfixes. Individual changes are never tested alone, but rather are part of a larger kernel release. Cherry-picking individual commits is not recommended or supported by the Linux kernel community at all. If however, updating to the latest release is impossible, the individual changes to resolve this issue can be found at these commits: https://git.kernel.org/stable/c/49e5b25a0b74dbac595f122e5608fdce2918cc4e https://git.kernel.org/stable/c/495058429ca55ab7fcc21977b63b92907ad68066 https://git.kernel.org/stable/c/2047ed09bf13453b7d6f9431b112ec07984dd69b https://git.kernel.org/stable/c/d6e6da6bc3b53231fac77ffab428da8173ee729c https://git.kernel.org/stable/c/93dde0bf2f39a0f9f57fd610aa3201ce5b753433