mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: Justin Tee <justintee8345@gmail.com>
To: Maoyi Xie <maoyixie.tju@gmail.com>,
	Justin Tee <justin.tee@broadcom.com>,
	Paul Ely <paul.ely@broadcom.com>
Cc: "Martin K. Petersen" <martin.petersen@oracle.com>,
	linux-scsi@vger.kernel.org, linux-kernel@vger.kernel.org
Subject: Re: lpfc: unbounded QFPA response length in lpfc_cmpl_els_qfpa()
Date: Mon, 22 Jun 2026 10:40:23 -0700	[thread overview]
Message-ID: <82be2f83-5454-47cb-8719-b259209a5e2b@gmail.com> (raw)
In-Reply-To: <178214622623.2376914.7843191393281628987@maoyixie.com>

Hi Maoyi,

 > This runs when the VMID feature is negotiated. The attacker is a 
malicious
 > or compromised fabric switch or target answering the QFPA request.
 >
 > I reproduced the overflow on 7.1-rc7. I ran the same copy with a 1020 
byte
 > qfpa_res buffer and a len that makes len + 8 larger than it. The copy 
runs
 > past the buffer and faults.

Is it possible to provide the fabric switch and target hardware details, 
i.e. model and version numbers, used to reproduce this issue?

 > Does this look like a real bug to you, and is bounding len the right
 > approach? If so I am happy to send a proper patch with a Fixes tag and Cc
 > stable.

No, this does not look like a real bug because the payload comes from an 
implicitly trusted source within the fabric.  Hence, it would be helpful 
to share switch and target details that this issue was found.  That 
said, we are already aware of this through AI security scan warnings and 
it will be addressed in a near lpfc version update.

Regards,
Justin

  reply	other threads:[~2026-06-22 17:42 UTC|newest]

Thread overview: 3+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-06-22 16:37 Maoyi Xie
2026-06-22 17:40 ` Justin Tee [this message]
2026-06-23  6:32   ` Maoyi Xie

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=82be2f83-5454-47cb-8719-b259209a5e2b@gmail.com \
    --to=justintee8345@gmail.com \
    --cc=justin.tee@broadcom.com \
    --cc=linux-kernel@vger.kernel.org \
    --cc=linux-scsi@vger.kernel.org \
    --cc=maoyixie.tju@gmail.com \
    --cc=martin.petersen@oracle.com \
    --cc=paul.ely@broadcom.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®