From: Dan Carpenter Date: Fri, 28 Feb 2025 09:37:28 +0000 (+0300) Subject: scsi: mpt3sas: Fix buffer overflow in mpt3sas_send_mctp_passthru_req() X-Git-Tag: v6.15-rc1~164^2~22 X-Git-Url: http://git.ipfire.org/?a=commitdiff_plain;h=0711f1966a523d77d4c5f00776a7bd073d56251a;p=thirdparty%2Fkernel%2Flinux.git scsi: mpt3sas: Fix buffer overflow in mpt3sas_send_mctp_passthru_req() The "sz" argument in mpt3sas_check_cmd_timeout() is the number of u32, not the number of bytes. We dump that many u32 values to dmesg. Passing the number of bytes will lead to a read overflow. Divide by 4 to get the correct value. Fixes: c72be4b5bb7c ("scsi: mpt3sas: Add support for MCTP Passthrough commands") Signed-off-by: Dan Carpenter Link: https://lore.kernel.org/r/02b0d4ff-961c-49ae-921a-5cc469edf93c@stanley.mountain Signed-off-by: Martin K. Petersen --- diff --git a/drivers/scsi/mpt3sas/mpt3sas_ctl.c b/drivers/scsi/mpt3sas/mpt3sas_ctl.c index ff8fedf5f20eb..063b10dd82514 100644 --- a/drivers/scsi/mpt3sas/mpt3sas_ctl.c +++ b/drivers/scsi/mpt3sas/mpt3sas_ctl.c @@ -3017,7 +3017,7 @@ int mpt3sas_send_mctp_passthru_req(struct mpt3_passthru_command *command) if (!(ioc->ctl_cmds.status & MPT3_CMD_COMPLETE)) { mpt3sas_check_cmd_timeout(ioc, ioc->ctl_cmds.status, mpi_request, - sizeof(Mpi26MctpPassthroughRequest_t), issue_reset); + sizeof(Mpi26MctpPassthroughRequest_t) / 4, issue_reset); goto issue_host_reset; }