[PATCH 5.10.y 5/5] scsi: scsi_debug: Fix REPORT ZONES alloc_len underflow OOB write
Sasha Levin <[email protected]>
| Newsgroups | org.kernel.vger.stable |
|---|---|
| Message-ID | <[email protected]> |
From: Ibrahim Hashimov <[email protected]> resp_report_zones() sizes the reply buffer from the CDB allocation length. The v3 fix rounds alloc_len up with ALIGN() before deriving the descriptor count: rep_max_zones = (ALIGN((u64)alloc_len, RZONES_DESC_HD) - RZONES_DESC_HD) >> ilog2(RZONES_DESC_HD); arr_len = (u64)RZONES_DESC_HD * (rep_max_zones + 1); For alloc_len in 0xFFFFFFC1..0xFFFFFFFF, ALIGN() rounds up to 0x100000000, so arr_len is 4 GB. On 32-bit, kzalloc()'s size_t is 32-bit and truncates 0x100000000 to 0; kzalloc(0) returns ZERO_SIZE_PTR, which passes the !arr check, and desc = arr + 64 is then dereferenced in the loop -> out-of-bounds write / panic. Clamp rep_max_zones to devip->nr_zones. The loop already stops at sdebug_capacity (after nr_zones zones), so a report can never hold more than nr_zones descriptors; the clamp does not change the report, it only bounds arr_len to (nr_zones + 1) * RZONES_DESC_HD, a real device property that can never reach 0x100000000. Fixes: 7db0e0c8190a ("scsi: scsi_debug: Fix buffer size of REPORT ZONES command") Suggested-by: Damien Le Moal <[email protected]> Cc: [email protected] Signed-off-by: Ibrahim Hashimov <[email protected]> Assisted-by: AuditCode-AI:2026.07 Reviewed-by: Damien Le Moal <[email protected]> Reviewed-by: Bart Van Assche <[email protected]> Link: https://patch.msgid.link/[email protected] Signed-off-by: Martin K. Petersen <[email protected]> [ Adjusted for 5.10: resp_report_zones() here predates commit 4a5fc1c6d752 ("scsi: scsi_debug: Add gap zone support"), so it still computes max_zones = devip->nr_zones - (zs_lba >> devip->zsize_shift); and bounds the descriptor loop with it. Keep that existing, tighter clamp instead of introducing a second one against devip->nr_zones: max_zones is by construction <= devip->nr_zones and is the actual number of descriptors the loop can emit, so it satisfies the upstream requirement that arr_len be bounded by a real device property while leaving the reported zone list unchanged. Without the fix 5.10 has the same class of bug from the other end of the range: for alloc_len in 1..63 the unsigned (alloc_len - 64) underflows, kzalloc(alloc_len) returns a sub-64-byte buffer, and both the report header at arr + 0 and desc = arr + 64 are written out of bounds. Sizing the allocation from rep_max_zones rather than from alloc_len fixes that too. ] (cherry picked from commit 93dde0bf2f39a0f9f57fd610aa3201ce5b753433) --- drivers/scsi/scsi_debug.c | 9 ++++++--- 1 file changed, 6 insertions(+), 3 deletions(-) diff --git a/drivers/scsi/scsi_debug.c b/drivers/scsi/scsi_debug.c index ad4cea4e14848..02d624dd35964 100644 --- a/drivers/scsi/scsi_debug.c +++ b/drivers/scsi/scsi_debug.c @@ -4320,6 +4320,7 @@ static int resp_report_zones(struct scsi_cmnd *scp, u32 alloc_len, rep_opts, rep_len; bool partial; u64 lba, zs_lba; + u64 arr_len; u8 *arr = NULL, *desc; u8 *cmd = scp->cmnd; struct sdeb_zone_state *zsp; @@ -4343,10 +4344,12 @@ static int resp_report_zones(struct scsi_cmnd *scp, } max_zones = devip->nr_zones - (zs_lba >> devip->zsize_shift); - rep_max_zones = min((alloc_len - 64) >> ilog2(RZONES_DESC_HD), - max_zones); + rep_max_zones = (ALIGN((u64)alloc_len, RZONES_DESC_HD) - RZONES_DESC_HD) >> + ilog2(RZONES_DESC_HD); + rep_max_zones = min_t(unsigned int, rep_max_zones, max_zones); + arr_len = (u64)RZONES_DESC_HD * (rep_max_zones + 1); - arr = kzalloc(alloc_len, GFP_ATOMIC | __GFP_NOWARN); + arr = kzalloc(arr_len, GFP_ATOMIC | __GFP_NOWARN); if (!arr) { mk_sense_buffer(scp, ILLEGAL_REQUEST, INSUFF_RES_ASC, INSUFF_RES_ASCQ); -- 2.53.0