[PATCH] scsi: libiscsi: fix stale-data leak into the SCSI sense buffer

HyeongJun An posted 1 patch 1 week, 4 days ago
drivers/scsi/libiscsi.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
[PATCH] scsi: libiscsi: fix stale-data leak into the SCSI sense buffer
Posted by HyeongJun An 1 week, 4 days ago
iscsi_scsi_cmd_rsp() copies the sense data of a SCSI Response from the
target-supplied data segment.  The segment carries a 2-byte sense length
followed by the sense bytes, so it must hold 2 + senselen bytes, but the
bounds check only requires datalen >= senselen:

	senselen = get_unaligned_be16(data);
	if (datalen < senselen)
		goto invalid_datalen;
	memcpy(sc->sense_buffer, data + 2,
	       min_t(uint16_t, senselen, SCSI_SENSE_BUFFERSIZE));

A target that returns a SCSI Response whose datalen equals senselen (with
senselen <= SCSI_SENSE_BUFFERSIZE) makes the memcpy() from data + 2 read
up to two bytes past the received data.  Those bytes are stale conn->data
contents and end up in the command's sense buffer, which is returned to
userspace.

Account for the 2-byte sense length prefix in the check.

Fixes: 7996a778ff8c ("[SCSI] iscsi: add libiscsi")
Suggested-by: Sashiko AI <sashiko-bot@kernel.org>
Assisted-by: Claude:claude-opus-4-8
Signed-off-by: HyeongJun An <sammiee5311@gmail.com>
---
 drivers/scsi/libiscsi.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/drivers/scsi/libiscsi.c b/drivers/scsi/libiscsi.c
index 160f02f2f51d..5cbc51899de0 100644
--- a/drivers/scsi/libiscsi.c
+++ b/drivers/scsi/libiscsi.c
@@ -918,7 +918,7 @@ static void iscsi_scsi_cmd_rsp(struct iscsi_conn *conn, struct iscsi_hdr *hdr,
 		}
 
 		senselen = get_unaligned_be16(data);
-		if (datalen < senselen)
+		if (datalen < senselen + 2)
 			goto invalid_datalen;
 
 		memcpy(sc->sense_buffer, data + 2,
-- 
2.43.0
Re: [PATCH] scsi: libiscsi: fix stale-data leak into the SCSI sense buffer
Posted by Chris Leech 1 week, 2 days ago
On Tue, Jul 14, 2026 at 07:49:34PM +0900, HyeongJun An wrote:
> iscsi_scsi_cmd_rsp() copies the sense data of a SCSI Response from the
> target-supplied data segment.  The segment carries a 2-byte sense length
> followed by the sense bytes, so it must hold 2 + senselen bytes, but the
> bounds check only requires datalen >= senselen:
> 
> 	senselen = get_unaligned_be16(data);
> 	if (datalen < senselen)
> 		goto invalid_datalen;
> 	memcpy(sc->sense_buffer, data + 2,
> 	       min_t(uint16_t, senselen, SCSI_SENSE_BUFFERSIZE));
> 
> A target that returns a SCSI Response whose datalen equals senselen (with
> senselen <= SCSI_SENSE_BUFFERSIZE) makes the memcpy() from data + 2 read
> up to two bytes past the received data.  Those bytes are stale conn->data
> contents and end up in the command's sense buffer, which is returned to
> userspace.
> 
> Account for the 2-byte sense length prefix in the check.
> 
> Fixes: 7996a778ff8c ("[SCSI] iscsi: add libiscsi")
> Suggested-by: Sashiko AI <sashiko-bot@kernel.org>
> Assisted-by: Claude:claude-opus-4-8
> Signed-off-by: HyeongJun An <sammiee5311@gmail.com>
> ---

This looks like a good fix to me.

Acked-by: Chris Leech <cleech@redhat.com>

>  drivers/scsi/libiscsi.c | 2 +-
>  1 file changed, 1 insertion(+), 1 deletion(-)
> 
> diff --git a/drivers/scsi/libiscsi.c b/drivers/scsi/libiscsi.c
> index 160f02f2f51d..5cbc51899de0 100644
> --- a/drivers/scsi/libiscsi.c
> +++ b/drivers/scsi/libiscsi.c
> @@ -918,7 +918,7 @@ static void iscsi_scsi_cmd_rsp(struct iscsi_conn *conn, struct iscsi_hdr *hdr,
>  		}
>  
>  		senselen = get_unaligned_be16(data);
> -		if (datalen < senselen)
> +		if (datalen < senselen + 2)
>  			goto invalid_datalen;
>  
>  		memcpy(sc->sense_buffer, data + 2,
> -- 
> 2.43.0
>