drivers/scsi/libiscsi.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-)
iscsi_scsi_cmd_rsp() copies the sense data of a SCSI Response from the
target-supplied data segment. The segment carries a 2-byte sense length
followed by the sense bytes, so it must hold 2 + senselen bytes, but the
bounds check only requires datalen >= senselen:
senselen = get_unaligned_be16(data);
if (datalen < senselen)
goto invalid_datalen;
memcpy(sc->sense_buffer, data + 2,
min_t(uint16_t, senselen, SCSI_SENSE_BUFFERSIZE));
A target that returns a SCSI Response whose datalen equals senselen (with
senselen <= SCSI_SENSE_BUFFERSIZE) makes the memcpy() from data + 2 read
up to two bytes past the received data. Those bytes are stale conn->data
contents and end up in the command's sense buffer, which is returned to
userspace.
Account for the 2-byte sense length prefix in the check.
Fixes: 7996a778ff8c ("[SCSI] iscsi: add libiscsi")
Suggested-by: Sashiko AI <sashiko-bot@kernel.org>
Assisted-by: Claude:claude-opus-4-8
Signed-off-by: HyeongJun An <sammiee5311@gmail.com>
---
drivers/scsi/libiscsi.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/scsi/libiscsi.c b/drivers/scsi/libiscsi.c
index 160f02f2f51d..5cbc51899de0 100644
--- a/drivers/scsi/libiscsi.c
+++ b/drivers/scsi/libiscsi.c
@@ -918,7 +918,7 @@ static void iscsi_scsi_cmd_rsp(struct iscsi_conn *conn, struct iscsi_hdr *hdr,
}
senselen = get_unaligned_be16(data);
- if (datalen < senselen)
+ if (datalen < senselen + 2)
goto invalid_datalen;
memcpy(sc->sense_buffer, data + 2,
--
2.43.0
On Tue, Jul 14, 2026 at 07:49:34PM +0900, HyeongJun An wrote:
> iscsi_scsi_cmd_rsp() copies the sense data of a SCSI Response from the
> target-supplied data segment. The segment carries a 2-byte sense length
> followed by the sense bytes, so it must hold 2 + senselen bytes, but the
> bounds check only requires datalen >= senselen:
>
> senselen = get_unaligned_be16(data);
> if (datalen < senselen)
> goto invalid_datalen;
> memcpy(sc->sense_buffer, data + 2,
> min_t(uint16_t, senselen, SCSI_SENSE_BUFFERSIZE));
>
> A target that returns a SCSI Response whose datalen equals senselen (with
> senselen <= SCSI_SENSE_BUFFERSIZE) makes the memcpy() from data + 2 read
> up to two bytes past the received data. Those bytes are stale conn->data
> contents and end up in the command's sense buffer, which is returned to
> userspace.
>
> Account for the 2-byte sense length prefix in the check.
>
> Fixes: 7996a778ff8c ("[SCSI] iscsi: add libiscsi")
> Suggested-by: Sashiko AI <sashiko-bot@kernel.org>
> Assisted-by: Claude:claude-opus-4-8
> Signed-off-by: HyeongJun An <sammiee5311@gmail.com>
> ---
This looks like a good fix to me.
Acked-by: Chris Leech <cleech@redhat.com>
> drivers/scsi/libiscsi.c | 2 +-
> 1 file changed, 1 insertion(+), 1 deletion(-)
>
> diff --git a/drivers/scsi/libiscsi.c b/drivers/scsi/libiscsi.c
> index 160f02f2f51d..5cbc51899de0 100644
> --- a/drivers/scsi/libiscsi.c
> +++ b/drivers/scsi/libiscsi.c
> @@ -918,7 +918,7 @@ static void iscsi_scsi_cmd_rsp(struct iscsi_conn *conn, struct iscsi_hdr *hdr,
> }
>
> senselen = get_unaligned_be16(data);
> - if (datalen < senselen)
> + if (datalen < senselen + 2)
> goto invalid_datalen;
>
> memcpy(sc->sense_buffer, data + 2,
> --
> 2.43.0
>
© 2016 - 2026 Red Hat, Inc.