Commit 2f383577 authored by Carlos Bilbao's avatar Carlos Bilbao Committed by Martin K. Petersen
Browse files

scsi: target: iscsi: reject invalid size Extended CDB AHS



If ecdb_ahdr->ahslength is zero, two bugs follow:

  kmalloc(be16_to_cpu(ecdb_ahdr->ahslength) + 15, ...)

allocates 15 bytes, but the immediately following memcpy writes
ISCSI_CDB_SIZE (16) bytes into it, a one-byte heap overflow. Also:

  memcpy(cdb + ISCSI_CDB_SIZE, ecdb_ahdr->ecdb,
           be16_to_cpu(ecdb_ahdr->ahslength) - 1);

(u16)0 - 1 promotes to (int)-1 which converts to SIZE_MAX as size_t,
causing a massive out-of-bounds write.

Reject ahslength == 0 with ISCSI_REASON_PROTOCOL_ERROR before the kmalloc.
Also reject ahslength values that exceed the actual AHS buffer advertised.

Fixes: 8f1f7d29 ("scsi: target: iscsi: Add support for extended CDB AHS")
Signed-off-by: default avatarCarlos Bilbao <carlos.bilbao@kernel.org>
Reviewed-by: default avatarDmitry Bogdanov <d.bogdanov@yadro.com>
Link: https://patch.msgid.link/20260415040728.187680-1-carlos.bilbao@kernel.org


Signed-off-by: default avatarMartin K. Petersen <martin.petersen@oracle.com>
parent b06cf63d
Loading
Loading
Loading
Loading
+18 −4
Original line number Diff line number Diff line
@@ -995,6 +995,7 @@ int iscsit_setup_scsi_cmd(struct iscsit_conn *conn, struct iscsit_cmd *cmd,
	int data_direction, payload_length;
	struct iscsi_ecdb_ahdr *ecdb_ahdr;
	struct iscsi_scsi_req *hdr;
	u16 ahslength, cdb_length;
	int iscsi_task_attr;
	unsigned char *cdb;
	int sam_task_attr;
@@ -1108,14 +1109,27 @@ int iscsit_setup_scsi_cmd(struct iscsit_conn *conn, struct iscsit_cmd *cmd,
				ISCSI_REASON_CMD_NOT_SUPPORTED, buf);
		}

		cdb = kmalloc(be16_to_cpu(ecdb_ahdr->ahslength) + 15,
			      GFP_KERNEL);
		ahslength = be16_to_cpu(ecdb_ahdr->ahslength);
		if (!ahslength) {
			pr_err("Extended CDB AHS with zero length, protocol error.\n");
			return iscsit_add_reject_cmd(cmd,
				ISCSI_REASON_PROTOCOL_ERROR, buf);
		}
		if (ahslength > (hdr->hlength * 4) - 3) {
			pr_err("Extended CDB AHS length %u exceeds available PDU buffer.\n",
			       ahslength);
			return iscsit_add_reject_cmd(cmd,
				ISCSI_REASON_PROTOCOL_ERROR, buf);
		}

		cdb_length = ahslength - 1 + ISCSI_CDB_SIZE;

		cdb = kmalloc(cdb_length, GFP_KERNEL);
		if (cdb == NULL)
			return iscsit_add_reject_cmd(cmd,
				ISCSI_REASON_BOOKMARK_NO_RESOURCES, buf);
		memcpy(cdb, hdr->cdb, ISCSI_CDB_SIZE);
		memcpy(cdb + ISCSI_CDB_SIZE, ecdb_ahdr->ecdb,
		       be16_to_cpu(ecdb_ahdr->ahslength) - 1);
		memcpy(cdb + ISCSI_CDB_SIZE, ecdb_ahdr->ecdb, cdb_length - ISCSI_CDB_SIZE);
	}

	data_direction = (hdr->flags & ISCSI_FLAG_CMD_WRITE) ? DMA_TO_DEVICE :