From: Artem Dinaburg <artem@trailofbits.com>
To: stable@vger.kernel.org
Cc: Artem Dinaburg <artem@trailofbits.com>,
Sasha Levin <sashal@kernel.org>,
Greg Kroah-Hartman <gregkh@linuxfoundation.org>,
Justin Tee <justin.tee@broadcom.com>,
Paul Ely <paul.ely@broadcom.com>,
James Smart <james.smart@broadcom.com>,
Dick Kennedy <dick.kennedy@broadcom.com>,
"James E . J . Bottomley" <James.Bottomley@HansenPartnership.com>,
James Bottomley <jejb@linux.ibm.com>,
"Martin K . Petersen" <mkp@kernel.org>,
Martin Petersen <martin.petersen@oracle.com>,
linux-scsi@vger.kernel.org, linux-kernel@vger.kernel.org
Subject: [PATCH 6.6.y v2 0/2] scsi: lpfc: Backport SFP mailbox timeout handling
Date: Fri, 2 Oct 2026 14:22:01 -0400 [thread overview]
Message-ID: <20261002182205.11550-1-artem@trailofbits.com> (raw)
Hi Sasha and lpfc maintainers,
Thanks for catching the SLI3 overflow in v1.
This v2 takes the ext_buf portion of upstream commit 115d137aa918 first.
That leaves the SLI3 response in the existing 1,024-byte DMA buffer while
ctx_buf continues to point to the descriptor used by cleanup. Patch 2 then
backports the original CVE-2024-46842 fix from ede596b1434b.
Could you please queue these two patches for 6.6.y?
Changes in v2:
- replace the unsafe ctx_buf restoration with the ext_buf prerequisite;
- send the prerequisite and CVE fix as a two-patch series;
- keep the generic upstream ownership race out of this backport; and
- rebase and rebuild after the current 6.6 stable queue.
v1: https://lore.kernel.org/r/20260930024505.96440-1-artem@trailofbits.com
Review: https://lore.kernel.org/r/2026-09-30-1-daily-reply-0014-lpfc-sfp-info-mbox-timeout-6-6@kernel.org
Thanks,
Artem Dinaburg
Justin Tee (2):
scsi: lpfc: Define lpfc_dmabuf type for ctx_buf ptr
scsi: lpfc: Handle mailbox timeouts in lpfc_get_sfp_info
drivers/scsi/lpfc/lpfc_bsg.c | 2 +-
drivers/scsi/lpfc/lpfc_els.c | 21 +++++++++++++--------
drivers/scsi/lpfc/lpfc_sli.c | 20 ++++++++++----------
drivers/scsi/lpfc/lpfc_sli.h | 1 +
4 files changed, 25 insertions(+), 19 deletions(-)
base-commit: 79643295eba17affbd16ca97f3ef04c90266b28c
--
2.39.5
next reply other threads:[~2026-10-02 18:22 UTC|newest]
Thread overview: 3+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-10-02 18:22 Artem Dinaburg [this message]
2026-10-02 18:22 ` [PATCH 6.6.y v2 1/2] scsi: lpfc: Define lpfc_dmabuf type for ctx_buf ptr Artem Dinaburg
2026-10-02 18:22 ` [PATCH 6.6.y v2 2/2] scsi: lpfc: Handle mailbox timeouts in lpfc_get_sfp_info Artem Dinaburg
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20261002182205.11550-1-artem@trailofbits.com \
--to=artem@trailofbits.com \
--cc=James.Bottomley@HansenPartnership.com \
--cc=dick.kennedy@broadcom.com \
--cc=gregkh@linuxfoundation.org \
--cc=james.smart@broadcom.com \
--cc=jejb@linux.ibm.com \
--cc=justin.tee@broadcom.com \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-scsi@vger.kernel.org \
--cc=martin.petersen@oracle.com \
--cc=mkp@kernel.org \
--cc=paul.ely@broadcom.com \
--cc=sashal@kernel.org \
--cc=stable@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®