[PATCH 1/4] ublk: Validate SQE128 flag before accessing the cmd

Caleb Sander Mateos posted 4 patches 1 week, 2 days ago
There is a newer version of this series
[PATCH 1/4] ublk: Validate SQE128 flag before accessing the cmd
Posted by Caleb Sander Mateos 1 week, 2 days ago
From: Govindarajulu Varadarajan <govind.varadar@gmail.com>

ublk_ctrl_cmd_dump() accesses (header *)sqe->cmd before
IO_URING_F_SQE128 flag check. This could cause out of boundary memory
access.

Move the SQE128 flag check earlier in ublk_ctrl_uring_cmd() to return
-EINVAL immediately if the flag is not set.

Fixes: 71f28f3136af ("ublk_drv: add io_uring based userspace block driver")
Signed-off-by: Govindarajulu Varadarajan <govind.varadar@gmail.com>
Reviewed-by: Caleb Sander Mateos <csander@purestorage.com>
---
 drivers/block/ublk_drv.c | 6 +++---
 1 file changed, 3 insertions(+), 3 deletions(-)

diff --git a/drivers/block/ublk_drv.c b/drivers/block/ublk_drv.c
index 7981decd1cee..72ee83ae303d 100644
--- a/drivers/block/ublk_drv.c
+++ b/drivers/block/ublk_drv.c
@@ -5130,14 +5130,14 @@ static int ublk_ctrl_uring_cmd(struct io_uring_cmd *cmd,
 
 	if (ublk_ctrl_uring_cmd_may_sleep(cmd_op) &&
 	    issue_flags & IO_URING_F_NONBLOCK)
 		return -EAGAIN;
 
-	ublk_ctrl_cmd_dump(cmd);
-
 	if (!(issue_flags & IO_URING_F_SQE128))
-		goto out;
+		return -EINVAL;
+
+	ublk_ctrl_cmd_dump(cmd);
 
 	ret = ublk_check_cmd_op(cmd_op);
 	if (ret)
 		goto out;
 
-- 
2.45.2
Re: [PATCH 1/4] ublk: Validate SQE128 flag before accessing the cmd
Posted by Ming Lei 1 week, 1 day ago
On Thu, Jan 29, 2026 at 03:46:14PM -0700, Caleb Sander Mateos wrote:
> From: Govindarajulu Varadarajan <govind.varadar@gmail.com>
> 
> ublk_ctrl_cmd_dump() accesses (header *)sqe->cmd before
> IO_URING_F_SQE128 flag check. This could cause out of boundary memory
> access.
> 
> Move the SQE128 flag check earlier in ublk_ctrl_uring_cmd() to return
> -EINVAL immediately if the flag is not set.
> 
> Fixes: 71f28f3136af ("ublk_drv: add io_uring based userspace block driver")
> Signed-off-by: Govindarajulu Varadarajan <govind.varadar@gmail.com>
> Reviewed-by: Caleb Sander Mateos <csander@purestorage.com>

Reviewed-by: Ming Lei <ming.lei@redhat.com>


Thanks,
Ming