From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from arkamax.eu (128-116-240-228.dyn.eolo.it [128.116.240.228]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 883BE39EF2E for ; Mon, 20 Apr 2026 12:28:58 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=128.116.240.228 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1776688142; cv=none; b=LYZ/VjYwgWVR2g+hb6TKABjSY6ojDzHVQot628lMaL5fiGqseN7gLL9au/vO6IguWsf8iDFDDYmT5e1G6rFDVrv8diPdSXW+v8lW2VuXHjA1tVSXmKXiwQBnpoZFeuFcRQIHq3oRalg7EOt5G3KJ1CYFPIws/GHIOKHJK9+sKSQ= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1776688142; c=relaxed/simple; bh=1WiYKlDIVB8xXkfPBJvsoZlYJ3zTd4xroGPXUZq/EO0=; h=Mime-Version:Content-Type:Date:Message-Id:From:To:Cc:Subject: References:In-Reply-To; b=XnEPKOqoSPpnApRCJeOntyolI71r+tYqRcroxxZDEZK41wAjvYKpnmLxgTKwQqpkV4xmaQkmjGeFS9ZOg+MUl2BhgMiaEQ9gEYcFixQgzb1iXkqr3BGu6GmHFb1K6pAjijEGeM1cRRD68nx45cXS+JE8tgdwHyGp+nnRDCbkUfE= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=arkamax.eu; spf=pass smtp.mailfrom=arkamax.eu; arc=none smtp.client-ip=128.116.240.228 Authentication-Results: smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=arkamax.eu Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=arkamax.eu Received: from localhost (128-116-240-228.dyn.eolo.it [128.116.240.228]) by arkamax.eu (OpenSMTPD) with ESMTPSA id 217576e9 (TLSv1.3:TLS_AES_256_GCM_SHA384:256:NO); Mon, 20 Apr 2026 14:22:17 +0200 (CEST) Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset=UTF-8 Date: Mon, 20 Apr 2026 14:22:16 +0200 Message-Id: From: "Maurizio Lombardi" To: "Chao Shi" , "Keith Busch" , "Jens Axboe" , "Christoph Hellwig" , "Sagi Grimberg" , "Daniel Wagner" , "Hannes Reinecke" , , Cc: "Sungwoo Kim" , "Dave Tian" , "Weidong Zhu" Subject: Re: [PATCH] nvme: core: reject invalid LBA data size from Identify Namespace X-Mailer: aerc 0.21.0 References: <20260418042835.420281-1-coshi036@gmail.com> In-Reply-To: <20260418042835.420281-1-coshi036@gmail.com> On Sat Apr 18, 2026 at 6:28 AM CEST, Chao Shi wrote: > nvme_update_ns_info_block() trusts id->lbaf[lbaf].ds from the > controller and assigns it directly to ns->head->lba_shift without > bounds checking. nvme_lba_to_sect() then does: > > return lba << (head->lba_shift - SECTOR_SHIFT); > > When called with lba =3D le64_to_cpu(id->nsze) to compute the device > capacity, an attacker-controlled controller can choose ds < 9 or a > combination of (ds, nsze) that makes the left shift overflow > sector_t. The former is a C undefined behaviour that UBSAN reports > as a BUG; the latter silently yields a bogus capacity that the > block layer then trusts for bounds checking. > > Validate ds against SECTOR_SHIFT and use check_shl_overflow() to > compute capacity so that any (ds, nsze) combination that would > overflow sector_t is rejected. The namespace is skipped with -EIO > instead of crashing the kernel. This is reachable by a malicious > NVMe device, a buggy firmware, or an attacker-controlled NVMe-oF > target. > > Stack trace (UBSAN, ds < 9 variant): > > RIP: nvme_lba_to_sect drivers/nvme/host/nvme.h:699 [inline] > RIP: nvme_update_ns_info_block.cold+0x5/0x7 > Call Trace: > nvme_update_ns_info+0x175/0xd90 drivers/nvme/host/core.c:2467 > nvme_validate_ns drivers/nvme/host/core.c:4299 [inline] > nvme_scan_ns drivers/nvme/host/core.c:4350 > nvme_scan_ns_async+0xa5/0xe0 drivers/nvme/host/core.c:4383 > async_run_entry_fn > process_one_work > worker_thread > kthread > > Found by Syzkaller. > > Fixes: 9419e71b8d67 ("nvme: move ns id info to struct nvme_ns_head") > Acked-by: Sungwoo Kim > Acked-by: Dave Tian > Acked-by: Weidong Zhu > Signed-off-by: Chao Shi > --- > drivers/nvme/host/core.c | 12 +++++++++++- > 1 file changed, 11 insertions(+), 1 deletion(-) > > diff --git a/drivers/nvme/host/core.c b/drivers/nvme/host/core.c > index 1e33af94c24..9b3bf3e4075 100644 > --- a/drivers/nvme/host/core.c > +++ b/drivers/nvme/host/core.c > @@ -2407,9 +2407,19 @@ static int nvme_update_ns_info_block(struct nvme_n= s *ns, > lim =3D queue_limits_start_update(ns->disk->queue); > =20 > memflags =3D blk_mq_freeze_queue(ns->disk->queue); > + if (id->lbaf[lbaf].ds < SECTOR_SHIFT || > + check_shl_overflow(le64_to_cpu(id->nsze), > + id->lbaf[lbaf].ds - SECTOR_SHIFT, > + &capacity)) { > + dev_warn_once(ns->ctrl->device, > + "invalid LBA data size %u, skipping namespace\n", > + id->lbaf[lbaf].ds); Just a nit: If I'm reading the NVMe spec correctly, ds =3D=3D 0 has a special meaning: 'LBA format is not currently available.' maybe we should use a different dev_warn() for ds =3D=3D 0 ? Maurizio