CVE-2026-74470: scsi: scsi_debug: Fix REPORT ZONES alloc_len underflow OOB write

Greg Kroah-Hartman <[email protected]>
Newsgroups org.kernel.vger.linux-cve-announce
Message-ID <2026081534-CVE-2026-74470-6792@gregkh>
From: Greg Kroah-Hartman <[email protected]>

Description
===========

In the Linux kernel, the following vulnerability has been resolved:

scsi: scsi_debug: Fix REPORT ZONES alloc_len underflow OOB write

resp_report_zones() sizes the reply buffer from the CDB allocation
length. The v3 fix rounds alloc_len up with ALIGN() before deriving the
descriptor count:

	rep_max_zones = (ALIGN((u64)alloc_len, RZONES_DESC_HD) -
			 RZONES_DESC_HD) >> ilog2(RZONES_DESC_HD);
	arr_len = (u64)RZONES_DESC_HD * (rep_max_zones + 1);

For alloc_len in 0xFFFFFFC1..0xFFFFFFFF, ALIGN() rounds up to
0x100000000, so arr_len is 4 GB. On 32-bit, kzalloc()'s size_t is 32-bit
and truncates 0x100000000 to 0; kzalloc(0) returns ZERO_SIZE_PTR, which
passes the !arr check, and desc = arr + 64 is then dereferenced in the
loop -> out-of-bounds write / panic.

Clamp rep_max_zones to devip->nr_zones. The loop already stops at
sdebug_capacity (after nr_zones zones), so a report can never hold more
than nr_zones descriptors; the clamp does not change the report, it only
bounds arr_len to (nr_zones + 1) * RZONES_DESC_HD, a real device
property that can never reach 0x100000000.

The Linux kernel CVE team has assigned CVE-2026-74470 to this issue.


Affected and fixed versions
===========================

	Issue introduced in 5.16 with commit 7db0e0c8190a086ef92ce5bb960836cde49540aa and fixed in 6.6.151 with commit 49e5b25a0b74dbac595f122e5608fdce2918cc4e
	Issue introduced in 5.16 with commit 7db0e0c8190a086ef92ce5bb960836cde49540aa and fixed in 6.12.103 with commit 495058429ca55ab7fcc21977b63b92907ad68066
	Issue introduced in 5.16 with commit 7db0e0c8190a086ef92ce5bb960836cde49540aa and fixed in 6.18.44 with commit 2047ed09bf13453b7d6f9431b112ec07984dd69b
	Issue introduced in 5.16 with commit 7db0e0c8190a086ef92ce5bb960836cde49540aa and fixed in 7.1.8 with commit d6e6da6bc3b53231fac77ffab428da8173ee729c
	Issue introduced in 5.16 with commit 7db0e0c8190a086ef92ce5bb960836cde49540aa and fixed in 7.2-rc6 with commit 93dde0bf2f39a0f9f57fd610aa3201ce5b753433
	Issue introduced in 5.10.85 with commit c4d2d7c935a4ad20e8e726ca10499cefe4537103
	Issue introduced in 5.15.8 with commit ebacb44cb2042b90951140eda806bedad23ef554

Please see https://www.kernel.org for a full list of currently supported
kernel versions by the kernel community.

Unaffected versions might change over time as fixes are backported to
older supported kernel versions.  The official CVE entry at
	https://cve.org/CVERecord/?id=CVE-2026-74470
will be updated if fixes are backported, please check that for the most
up to date information about this issue.


Affected files
==============

The file(s) affected by this issue are:
	drivers/scsi/scsi_debug.c


Mitigation
==========

The Linux kernel CVE team recommends that you update to the latest
stable kernel version for this, and many other bugfixes.  Individual
changes are never tested alone, but rather are part of a larger kernel
release.  Cherry-picking individual commits is not recommended or
supported by the Linux kernel community at all.  If however, updating to
the latest release is impossible, the individual changes to resolve this
issue can be found at these commits:
	https://git.kernel.org/stable/c/49e5b25a0b74dbac595f122e5608fdce2918cc4e
	https://git.kernel.org/stable/c/495058429ca55ab7fcc21977b63b92907ad68066
	https://git.kernel.org/stable/c/2047ed09bf13453b7d6f9431b112ec07984dd69b
	https://git.kernel.org/stable/c/d6e6da6bc3b53231fac77ffab428da8173ee729c
	https://git.kernel.org/stable/c/93dde0bf2f39a0f9f57fd610aa3201ce5b753433
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.