diff options
| author | Hari Mishal <harimishal1@gmail.com> | 2026-07-09 14:30:32 +0200 |
|---|---|---|
| committer | Keith Busch <kbusch@kernel.org> | 2026-07-14 15:11:59 -0700 |
| commit | 3c568b35a0d309acb40746552bec2af24cd550ef (patch) | |
| tree | 0833a6ec480c28c23d14602762cfcd317d704829 | |
| parent | cdf9a65e80ec874b630502946d269fac38dc5de8 (diff) | |
nvme: bound ns descriptor header and body to identify buffer
nvme_identify_ns_descs() allocates a buffer and gives it to the
controller, which populates it and then iterates the buffer with
variable byte increments that vary by type and body size. But, there is
no bounds check inside the iteration itself except the loop bound
itself. Fix this by checking and stopping iteration if the next header
or its declared body would go past the buffer itself.
Assisted-by: gkh_clanker_t1000
Reviewed-by: Christoph Hellwig <hch@lst.de>
Signed-off-by: Hari Mishal <harimishal1@gmail.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Keith Busch <kbusch@kernel.org>
| -rw-r--r-- | drivers/nvme/host/core.c | 4 |
1 files changed, 4 insertions, 0 deletions
diff --git a/drivers/nvme/host/core.c b/drivers/nvme/host/core.c index db0c8ad4628a..0b8330c79b1a 100644 --- a/drivers/nvme/host/core.c +++ b/drivers/nvme/host/core.c @@ -1583,8 +1583,12 @@ static int nvme_identify_ns_descs(struct nvme_ctrl *ctrl, for (pos = 0; pos < NVME_IDENTIFY_DATA_SIZE; pos += len) { struct nvme_ns_id_desc *cur = data + pos; + if (pos + sizeof(*cur) > NVME_IDENTIFY_DATA_SIZE) + break; if (cur->nidl == 0) break; + if (pos + sizeof(*cur) + cur->nidl > NVME_IDENTIFY_DATA_SIZE) + break; len = nvme_process_ns_desc(ctrl, &info->ids, cur, &csi_seen); if (len < 0) |
