]> git.ipfire.org Git - thirdparty/kernel/linux.git/commitdiff
scsi: target: iscsi: reject invalid size Extended CDB AHS
authorCarlos Bilbao <carlos.bilbao@kernel.org>
Wed, 15 Apr 2026 04:07:28 +0000 (21:07 -0700)
committerMartin K. Petersen <martin.petersen@oracle.com>
Wed, 22 Apr 2026 01:08:25 +0000 (21:08 -0400)
If ecdb_ahdr->ahslength is zero, two bugs follow:

  kmalloc(be16_to_cpu(ecdb_ahdr->ahslength) + 15, ...)

allocates 15 bytes, but the immediately following memcpy writes
ISCSI_CDB_SIZE (16) bytes into it, a one-byte heap overflow. Also:

  memcpy(cdb + ISCSI_CDB_SIZE, ecdb_ahdr->ecdb,
           be16_to_cpu(ecdb_ahdr->ahslength) - 1);

(u16)0 - 1 promotes to (int)-1 which converts to SIZE_MAX as size_t,
causing a massive out-of-bounds write.

Reject ahslength == 0 with ISCSI_REASON_PROTOCOL_ERROR before the kmalloc.
Also reject ahslength values that exceed the actual AHS buffer advertised.

Fixes: 8f1f7d297bce ("scsi: target: iscsi: Add support for extended CDB AHS")
Signed-off-by: Carlos Bilbao <carlos.bilbao@kernel.org>
Reviewed-by: Dmitry Bogdanov <d.bogdanov@yadro.com>
Link: https://patch.msgid.link/20260415040728.187680-1-carlos.bilbao@kernel.org
Signed-off-by: Martin K. Petersen <martin.petersen@oracle.com>
drivers/target/iscsi/iscsi_target.c

index e80449f6ce159c357b6851d1f1f4166b06140474..cb832fd523af18bdc943cae73b08cb36f56c10ba 100644 (file)
@@ -995,6 +995,7 @@ int iscsit_setup_scsi_cmd(struct iscsit_conn *conn, struct iscsit_cmd *cmd,
        int data_direction, payload_length;
        struct iscsi_ecdb_ahdr *ecdb_ahdr;
        struct iscsi_scsi_req *hdr;
+       u16 ahslength, cdb_length;
        int iscsi_task_attr;
        unsigned char *cdb;
        int sam_task_attr;
@@ -1108,14 +1109,27 @@ int iscsit_setup_scsi_cmd(struct iscsit_conn *conn, struct iscsit_cmd *cmd,
                                ISCSI_REASON_CMD_NOT_SUPPORTED, buf);
                }
 
-               cdb = kmalloc(be16_to_cpu(ecdb_ahdr->ahslength) + 15,
-                             GFP_KERNEL);
+               ahslength = be16_to_cpu(ecdb_ahdr->ahslength);
+               if (!ahslength) {
+                       pr_err("Extended CDB AHS with zero length, protocol error.\n");
+                       return iscsit_add_reject_cmd(cmd,
+                               ISCSI_REASON_PROTOCOL_ERROR, buf);
+               }
+               if (ahslength > (hdr->hlength * 4) - 3) {
+                       pr_err("Extended CDB AHS length %u exceeds available PDU buffer.\n",
+                              ahslength);
+                       return iscsit_add_reject_cmd(cmd,
+                               ISCSI_REASON_PROTOCOL_ERROR, buf);
+               }
+
+               cdb_length = ahslength - 1 + ISCSI_CDB_SIZE;
+
+               cdb = kmalloc(cdb_length, GFP_KERNEL);
                if (cdb == NULL)
                        return iscsit_add_reject_cmd(cmd,
                                ISCSI_REASON_BOOKMARK_NO_RESOURCES, buf);
                memcpy(cdb, hdr->cdb, ISCSI_CDB_SIZE);
-               memcpy(cdb + ISCSI_CDB_SIZE, ecdb_ahdr->ecdb,
-                      be16_to_cpu(ecdb_ahdr->ahslength) - 1);
+               memcpy(cdb + ISCSI_CDB_SIZE, ecdb_ahdr->ecdb, cdb_length - ISCSI_CDB_SIZE);
        }
 
        data_direction = (hdr->flags & ISCSI_FLAG_CMD_WRITE) ? DMA_TO_DEVICE :