]> git.ipfire.org Git - thirdparty/linux.git/commitdiff
scsi: scsi_debug: Fix REPORT ZONES alloc_len underflow OOB write
authorIbrahim Hashimov <security@auditcode.ai>
Sun, 12 Jul 2026 18:37:39 +0000 (20:37 +0200)
committerMartin K. Petersen <martin.petersen@oracle.com>
Wed, 29 Jul 2026 01:52:08 +0000 (21:52 -0400)
resp_report_zones() sizes the reply buffer from the CDB allocation
length. The v3 fix rounds alloc_len up with ALIGN() before deriving the
descriptor count:

rep_max_zones = (ALIGN((u64)alloc_len, RZONES_DESC_HD) -
 RZONES_DESC_HD) >> ilog2(RZONES_DESC_HD);
arr_len = (u64)RZONES_DESC_HD * (rep_max_zones + 1);

For alloc_len in 0xFFFFFFC1..0xFFFFFFFF, ALIGN() rounds up to
0x100000000, so arr_len is 4 GB. On 32-bit, kzalloc()'s size_t is 32-bit
and truncates 0x100000000 to 0; kzalloc(0) returns ZERO_SIZE_PTR, which
passes the !arr check, and desc = arr + 64 is then dereferenced in the
loop -> out-of-bounds write / panic.

Clamp rep_max_zones to devip->nr_zones. The loop already stops at
sdebug_capacity (after nr_zones zones), so a report can never hold more
than nr_zones descriptors; the clamp does not change the report, it only
bounds arr_len to (nr_zones + 1) * RZONES_DESC_HD, a real device
property that can never reach 0x100000000.

Fixes: 7db0e0c8190a ("scsi: scsi_debug: Fix buffer size of REPORT ZONES command")
Suggested-by: Damien Le Moal <dlemoal@kernel.org>
Cc: stable@vger.kernel.org
Signed-off-by: Ibrahim Hashimov <security@auditcode.ai>
Assisted-by: AuditCode-AI:2026.07
Reviewed-by: Damien Le Moal <dlemoal@kernel.org>
Reviewed-by: Bart Van Assche <bvanassche@acm.org>
Link: https://patch.msgid.link/20260712183739.83915-1-security@auditcode.ai
Signed-off-by: Martin K. Petersen <martin.petersen@oracle.com>
drivers/scsi/scsi_debug.c

index 9d1c9c41d0f9905b6a83c0c6ef5f223bc2fd1001..64305133213259471e540a71daf688bb0e3a9df9 100644 (file)
@@ -5890,6 +5890,7 @@ static int resp_report_zones(struct scsi_cmnd *scp,
        u32 alloc_len, rep_opts, rep_len;
        bool partial;
        u64 lba, zs_lba;
+       u64 arr_len;
        u8 *arr = NULL, *desc;
        u8 *cmd = scp->cmnd;
        struct sdeb_zone_state *zsp = NULL;
@@ -5911,9 +5912,12 @@ static int resp_report_zones(struct scsi_cmnd *scp,
                return check_condition_result;
        }
 
-       rep_max_zones = (alloc_len - 64) >> ilog2(RZONES_DESC_HD);
+       rep_max_zones = (ALIGN((u64)alloc_len, RZONES_DESC_HD) - RZONES_DESC_HD) >>
+                       ilog2(RZONES_DESC_HD);
+       rep_max_zones = min_t(unsigned int, rep_max_zones, devip->nr_zones);
+       arr_len = (u64)RZONES_DESC_HD * (rep_max_zones + 1);
 
-       arr = kzalloc(alloc_len, GFP_ATOMIC | __GFP_NOWARN);
+       arr = kzalloc(arr_len, GFP_ATOMIC | __GFP_NOWARN);
        if (!arr) {
                mk_sense_buffer(scp, ILLEGAL_REQUEST, INSUFF_RES_ASC,
                                INSUFF_RES_ASCQ);