mirror of
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git
synced 2026-05-16 02:01:18 -04:00
scsi: target: iscsi: reject invalid size Extended CDB AHS
If ecdb_ahdr->ahslength is zero, two bugs follow:
kmalloc(be16_to_cpu(ecdb_ahdr->ahslength) + 15, ...)
allocates 15 bytes, but the immediately following memcpy writes
ISCSI_CDB_SIZE (16) bytes into it, a one-byte heap overflow. Also:
memcpy(cdb + ISCSI_CDB_SIZE, ecdb_ahdr->ecdb,
be16_to_cpu(ecdb_ahdr->ahslength) - 1);
(u16)0 - 1 promotes to (int)-1 which converts to SIZE_MAX as size_t,
causing a massive out-of-bounds write.
Reject ahslength == 0 with ISCSI_REASON_PROTOCOL_ERROR before the kmalloc.
Also reject ahslength values that exceed the actual AHS buffer advertised.
Fixes: 8f1f7d297b ("scsi: target: iscsi: Add support for extended CDB AHS")
Signed-off-by: Carlos Bilbao <carlos.bilbao@kernel.org>
Reviewed-by: Dmitry Bogdanov <d.bogdanov@yadro.com>
Link: https://patch.msgid.link/20260415040728.187680-1-carlos.bilbao@kernel.org
Signed-off-by: Martin K. Petersen <martin.petersen@oracle.com>
This commit is contained in:
committed by
Martin K. Petersen
parent
b06cf63d83
commit
2f3835771d
@@ -995,6 +995,7 @@ int iscsit_setup_scsi_cmd(struct iscsit_conn *conn, struct iscsit_cmd *cmd,
|
||||
int data_direction, payload_length;
|
||||
struct iscsi_ecdb_ahdr *ecdb_ahdr;
|
||||
struct iscsi_scsi_req *hdr;
|
||||
u16 ahslength, cdb_length;
|
||||
int iscsi_task_attr;
|
||||
unsigned char *cdb;
|
||||
int sam_task_attr;
|
||||
@@ -1108,14 +1109,27 @@ int iscsit_setup_scsi_cmd(struct iscsit_conn *conn, struct iscsit_cmd *cmd,
|
||||
ISCSI_REASON_CMD_NOT_SUPPORTED, buf);
|
||||
}
|
||||
|
||||
cdb = kmalloc(be16_to_cpu(ecdb_ahdr->ahslength) + 15,
|
||||
GFP_KERNEL);
|
||||
ahslength = be16_to_cpu(ecdb_ahdr->ahslength);
|
||||
if (!ahslength) {
|
||||
pr_err("Extended CDB AHS with zero length, protocol error.\n");
|
||||
return iscsit_add_reject_cmd(cmd,
|
||||
ISCSI_REASON_PROTOCOL_ERROR, buf);
|
||||
}
|
||||
if (ahslength > (hdr->hlength * 4) - 3) {
|
||||
pr_err("Extended CDB AHS length %u exceeds available PDU buffer.\n",
|
||||
ahslength);
|
||||
return iscsit_add_reject_cmd(cmd,
|
||||
ISCSI_REASON_PROTOCOL_ERROR, buf);
|
||||
}
|
||||
|
||||
cdb_length = ahslength - 1 + ISCSI_CDB_SIZE;
|
||||
|
||||
cdb = kmalloc(cdb_length, GFP_KERNEL);
|
||||
if (cdb == NULL)
|
||||
return iscsit_add_reject_cmd(cmd,
|
||||
ISCSI_REASON_BOOKMARK_NO_RESOURCES, buf);
|
||||
memcpy(cdb, hdr->cdb, ISCSI_CDB_SIZE);
|
||||
memcpy(cdb + ISCSI_CDB_SIZE, ecdb_ahdr->ecdb,
|
||||
be16_to_cpu(ecdb_ahdr->ahslength) - 1);
|
||||
memcpy(cdb + ISCSI_CDB_SIZE, ecdb_ahdr->ecdb, cdb_length - ISCSI_CDB_SIZE);
|
||||
}
|
||||
|
||||
data_direction = (hdr->flags & ISCSI_FLAG_CMD_WRITE) ? DMA_TO_DEVICE :
|
||||
|
||||
Reference in New Issue
Block a user