From nobody Fri Oct 2 07:47:19 2026 Received: from mail-pl1-f181.google.com (mail-pl1-f181.google.com [209.85.214.181]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id D7AE342BEB2 for ; Tue, 4 Aug 2026 04:06:10 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.214.181 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785816373; cv=none; b=fzzrR1MdXlkWpPWbw9GWJVdBNjpV/Tfxzve5EFab1VAps+s57+00W9lLO/edNzFK/17oovQ6+RbG6cMW6L01j5eTVZkFauWyg4QIdO9+54qRPehQDq7WlugXI+Up3gSTXo/VMI8lNODhmXlIn6CqN/xD5On/0Vrf+Lvr5gnRtFc= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785816373; c=relaxed/simple; bh=5DE4KQsM7346xeBKvK3gf4RPk9kJfK5f72ku+Z9mtWQ=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=kTg4YsyzXkU/0mj150m+wqTpxd8aXXAwUCO84Yzw+PBl5xF0BB0ioXri6YpMLPmJqRUNjDGrGCOmGqQIVs6tSif4JXbYdE5kMdJfAsHyxWi6Gb6eyDHj9Uubp9bf9CgMo27T8PdZv7HgBFtwMYIJ+wXMJB0fwjF1ufIYssdxEuI= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=fail (p=none dis=none) header.from=isslab.korea.ac.kr; spf=none smtp.mailfrom=isslab.korea.ac.kr; dkim=pass (2048-bit key) header.d=isslab-korea-ac-kr.20251104.gappssmtp.com header.i=@isslab-korea-ac-kr.20251104.gappssmtp.com header.b=lUKemQmm; arc=none smtp.client-ip=209.85.214.181 Authentication-Results: smtp.subspace.kernel.org; dmarc=fail (p=none dis=none) header.from=isslab.korea.ac.kr Authentication-Results: smtp.subspace.kernel.org; spf=none smtp.mailfrom=isslab.korea.ac.kr Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=isslab-korea-ac-kr.20251104.gappssmtp.com header.i=@isslab-korea-ac-kr.20251104.gappssmtp.com header.b="lUKemQmm" Received: by mail-pl1-f181.google.com with SMTP id d9443c01a7336-2cacb8416a1so40950195ad.1 for ; Mon, 03 Aug 2026 21:06:10 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=isslab-korea-ac-kr.20251104.gappssmtp.com; s=20251104; t=1785816370; x=1786421170; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=za1Dlg5MtkIibFTGSkfNOwAtn76AnP6HPzWNLsvhv18=; b=lUKemQmm9QETeTffwq36G+BrDLCxd2IMl2zffaNwjs1HjIMRzDZtCXA6J55TUy2ue2 fHe4ZSEnS1Kn01UeKuMjCCpZEW9pKdX0up+XicdeqRXhcwwfgym6sraP75+L6kuNMHsG D48K9pNjwVOwTYlvJMLOAMhl1b4QpvPU3GUbkqeCm38V97eC/S1tPlefMa7mtU7ECcJ8 07JUMPi8xxGqR0+54hrrElvgDz0JZ1zbcv+St1mcgNMOs8EGtO5vZE/UFs/K/e6JcJ/j TdwxhxpsYdfz5IGuE2uW2Tle1Ip0e5RUa5QBLQ/KsDA9Es6xC67Vg0DbzZlPC5oL2qOU OrJA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785816370; x=1786421170; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=za1Dlg5MtkIibFTGSkfNOwAtn76AnP6HPzWNLsvhv18=; b=RRpeIJUI9ZVOaeuN+4QuA71UfxEyqusSPKmci9RSvk/mcaoPnBDasqNwLuKAgCHcjW kB4VNkPaMucBhXwm/A3/vyrMf1F3kF55bDgOOt+rPhyabQCsBXj+l2+BK5Rk61q0VsKr OI/RxCTmP+ab6HEqCrZxnxG4Fmxtkw01JvJT/V5HRHGRq17wsv21dg8DuSfs7HsKi4XR Xo/tpAkmJo3qD89HIdhGT0jIToSGcFEHW30LWnKEhrjFTWEaYi0OfKN0/hq2qXRYZH2E +ssMijh0fImoWJcM/IRUYUE0IQqw7aXRFNgYCg4nryenzrMCd8EpY/HPGvmkuZ4fMr3s FCrg== X-Forwarded-Encrypted: i=1; AHgh+RrgCN1OSc1pRhTPLqj18obX1HXPH1CTQ8o3a09hcrXBB+HEVcKTLod+uLnhgUynGPPVAhT9gnggd/4FPn0=@vger.kernel.org X-Gm-Message-State: AOJu0YxY7VXHq7wuD7QXfYjnh/rA7x61bJKNrO4F7cGQob1n9L3dWL6s T/DTjw5QTAvo7q4FaHn8KwfurwBe2W2sZlrYebosdAWMBVYhYi9Xz5h4SjROwaI8KJI= X-Gm-Gg: AR+sD12nSYHo1L0UBNviPvW54mkryI80EprejRYtvZBZzuLMCdDBD+2NL368uiGx3x6 9ZM/piDxM6CYrJKFRQkNqlEcgHQl+iQGZmQPSmOQ4M9mvkp3TLiQsJkgAvhFZlQCmR7C/WRl4Mj oGVY5Z1uMu5TpKJq2iinKaeVR/t3L90XbZIvUjmQfIY4NMHqfrFKXyadWme7Tmg93/P+bGbSNaZ 5vVN+4sBhLd/fT8crPJw2C0zteLKBekHB9Lwvsjd1LL3bbcxoDVwXyxqi1QsT700tCIjDt0PosQ ZLvGX5PuB7N481/tpMO0HitB7Cqm320bnuUESslusyE0LQOU6p7F6/lZha9sQ2RssiOSoTZ23Ut L3w00VVh43gnn6poslLs8vXGKabOapLqCHI/53j7t7OG8CqdpsddHyyGyVaYRe/SqujpI2h4eno Ptc26m4uQFkVcpEhH7EJb3u3cw4h09fUOAL64F5JQZPZEcnpeFrvjXb/bZxoBuMPybDC8h X-Received: by 2002:a17:902:ea0d:b0:2cf:83bf:6b05 with SMTP id d9443c01a7336-2d0523e144emr111189575ad.41.1785816370167; Mon, 03 Aug 2026 21:06:10 -0700 (PDT) Received: from yhlee-960QFG.. ([125.131.91.97]) by smtp.gmail.com with ESMTPSA id d9443c01a7336-2d04b11f9a9sm46075465ad.57.2026.08.03.21.06.07 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 03 Aug 2026 21:06:09 -0700 (PDT) From: Yehyeong Lee To: lduncan@suse.com, cleech@redhat.com, michael.christie@oracle.com, James.Bottomley@HansenPartnership.com, martin.petersen@oracle.com Cc: open-iscsi@googlegroups.com, linux-scsi@vger.kernel.org, linux-kernel@vger.kernel.org, Yehyeong Lee , stable@vger.kernel.org Subject: [PATCH v2 1/3] scsi: libiscsi: reject a negative task index from parse_pdu_itt Date: Tue, 4 Aug 2026 13:05:44 +0900 Message-ID: <20260804040546.2264137-2-yhlee@isslab.korea.ac.kr> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260804040546.2264137-1-yhlee@isslab.korea.ac.kr> References: <20260804040546.2264137-1-yhlee@isslab.korea.ac.kr> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" A transport that implements parse_pdu_itt hands libiscsi an index taken from the PDU, and both lookups bound it from above only: if (i >=3D session->cmds_max) i and cmds_max are both int, so a negative index passes and session->cmds[i] is read from before the array. be2iscsi produces one. beiscsi_parse_pdu() assigns the raw tag, *index =3D (int)itt; and beiscsi_complete_pdu() forwards an unsolicited NOP-In from the hardware async ring without replacing its ITT, so the value is the target's. It also reports the session's own age rather than the one in the tag, which leaves the age comparison in iscsi_verify_itt() with nothing to reject. Bound the index from below in both lookups. Fixes: bfead3b2cb46 ("[SCSI] be2iscsi: Adding msix and mcc_rings V3") Cc: stable@vger.kernel.org Signed-off-by: Yehyeong Lee --- Not reproduced: I have no be2iscsi hardware. The reachability argument is in the commit message. drivers/scsi/libiscsi.c | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/drivers/scsi/libiscsi.c b/drivers/scsi/libiscsi.c index 160f02f2f51d..7a74bc697d23 100644 --- a/drivers/scsi/libiscsi.c +++ b/drivers/scsi/libiscsi.c @@ -1191,7 +1191,7 @@ struct iscsi_task *iscsi_itt_to_task(struct iscsi_con= n *conn, itt_t itt) session->tt->parse_pdu_itt(conn, itt, &i, NULL); else i =3D get_itt(itt); - if (i >=3D session->cmds_max) + if (i < 0 || i >=3D session->cmds_max) return NULL; =20 return session->cmds[i]; @@ -1384,7 +1384,7 @@ int iscsi_verify_itt(struct iscsi_conn *conn, itt_t i= tt) return ISCSI_ERR_BAD_ITT; } =20 - if (i >=3D session->cmds_max) { + if (i < 0 || i >=3D session->cmds_max) { iscsi_conn_printk(KERN_ERR, conn, "received invalid itt index %u (max cmds " "%u.\n", i, session->cmds_max); --=20 2.43.0 From nobody Fri Oct 2 07:47:19 2026 Received: from mail-pl1-f176.google.com (mail-pl1-f176.google.com [209.85.214.176]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 8E240423E9F for ; Tue, 4 Aug 2026 04:06:14 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.214.176 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785816376; cv=none; b=Gsh4rxTsrrm36ZNZv3Zu7Nb8lVQh+zBR1VZcJovxwyNnzYIr+LRKLhqmC8Y4ZeIaySCZjZsJOXCAIW9tEguXi4+62WnnYGC4aqPSVtfRrq4NTsuSwbgijQO1dyaY3JXL0pRKz/GSfM8K3iQ7IN/HR9gI4ql/Witgkqw6ukHerWM= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785816376; c=relaxed/simple; bh=Pb1m5gtR1Waz2T4Dlo1TBMbTvyQgrBK6r64ajRbo/kM=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=jy6yngKaIptyEySBA+nVUaqNljdAe7HcupRKSfRGipQDqM9Qi/tYDFdHXeamQJqZEXauHL87v1ISs/S2vCcmWOQDXqbWS5IRNKSj3Rk+/nO48irQv6LEeyz5fiK3iH+tlmmpLK0RGrvl5BvFxZHMYCYPxitPIauk/Uiehjpl5+k= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=fail (p=none dis=none) header.from=isslab.korea.ac.kr; spf=none smtp.mailfrom=isslab.korea.ac.kr; dkim=pass (2048-bit key) header.d=isslab-korea-ac-kr.20251104.gappssmtp.com header.i=@isslab-korea-ac-kr.20251104.gappssmtp.com header.b=tlVyqcbL; arc=none smtp.client-ip=209.85.214.176 Authentication-Results: smtp.subspace.kernel.org; dmarc=fail (p=none dis=none) header.from=isslab.korea.ac.kr Authentication-Results: smtp.subspace.kernel.org; spf=none smtp.mailfrom=isslab.korea.ac.kr Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=isslab-korea-ac-kr.20251104.gappssmtp.com header.i=@isslab-korea-ac-kr.20251104.gappssmtp.com header.b="tlVyqcbL" Received: by mail-pl1-f176.google.com with SMTP id d9443c01a7336-2cc61541f8cso6514855ad.0 for ; Mon, 03 Aug 2026 21:06:14 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=isslab-korea-ac-kr.20251104.gappssmtp.com; s=20251104; t=1785816374; x=1786421174; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=ktrD5Au+y2fdveRAMa1uUs9Ni5kpAlV0uMWrALgQG98=; b=tlVyqcbLMHQUaRobLitLFDIY4nkxJXPZNCbnyjSOTE/84Oc3+tEEl8vFNTpjpUGxiv LsnwAUGFkCYkcXvExRRVl0PhbNI870Yj6jEO66vRKW4i1kFFzgkPbTvnoUkEqUqkWSEA Ubc91ino8+TpY2VC6hEVDQ0FXMrDdlPzfR58hSLGX0iLadvElO1ES42+j0XB6AMgeya5 8pWMpm/ye4tz1KKgGu6gLSmfqHJivD0FiYHRkWjH/OWzpXrLhpZbB6Uk8dzL+buIBtoB Fe4DQQr0N/ftg2YHd3OFBjg6onySnCtRLSlzdrfwRhrRAQGglLYy1h1uXag0pDODoZRQ VeQg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785816374; x=1786421174; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=ktrD5Au+y2fdveRAMa1uUs9Ni5kpAlV0uMWrALgQG98=; b=DgRQIGw/WMp4j8fkG/yX4PlMCG1lZJGyvnuYJ5MOYBVYbEfKf64aPwqO7CC/z6wcRa ulp8S98sVLl9sVYhDdvS31ZnQs6IY+6Ef8ISthD49tgVTZUBQnPxIG9+OqVzGFeVZFWh 4iVk/9JRb+KL/So8YK/athip21KZ8gJms9pp6eNVM58AduoGvvVyHIZRuLlmtjGhqBcW p/k3BxLd+3AERF8myWiIxCC2d+/XF3p53Glw85NYxgZDYIvF2Go8ih0PRwBefZ0s3bcE bYdFdl1syQPsfyAF1kp6VjRyAdfzshXLkaHsDvR5PhMgdldlmiOuSXXrG5aXxT2G8uRG ZfsQ== X-Forwarded-Encrypted: i=1; AHgh+RpxLzPIz+EAVPlM+bYJ9hNyLl9ZE5ljBZgbmb19VZTfdppdqp93aBDvAiq4u9/E+x29cCUs8SDQyRoBV3I=@vger.kernel.org X-Gm-Message-State: AOJu0YzDnWDop9EEIAgSxIYjGxwOiC0PcYcesJgaK2z0LxmBZu29QG5K o0WNKCWJ6ukuWbu4xmDzjwl3vI90QEfpXSjNm0YgAi6Z4ahOQcCeikdoqSlwc6gh9XI= X-Gm-Gg: AR+sD104dnA1X2gZaA1C5iQ66Ft3Ze+MonIVJWggWt9XCqr2MbJs9tFk5WsVStCfqJH T/TlczQ7WkarY1RbLFidH9uuR8/OW4YWoyOQc5X+77TSai5idwX0CGSblhqpibp46AlZB3/fOEA S4dDj23KXpFIzfhRBApuMbiNyktsEyjrZiFEqZQjip5/Xd5E8vJAT2txfDahOxqPLxAkDa9Q5Ro JYeMlA+WumlwbK3HGb4nbQHak9AHCpETQ3av9jYxgpWwI3IxivcRbANG10NKlueQjTUBSVSgD3D 5V7WufADVN0TYR49Y9BjbkDTR9vs2A2PK2KXx3S6dnZv2ZVqLp4o+8OhqdqErf9KAtd8LoxxXoR +U9nMn+iYchE2dQBCEZBkRap5F97RJv2Cw/frOs/15CuCeKm8eOqh/P63U/NHulyYo4lZq0lOi7 5T6Vf5FL84eaG3D8xduRUnTBNtpnoIPe9icuU5YYZB4/Ko5YpGgaiuQ25xe8/T6T1+ODPD X-Received: by 2002:a17:902:ced0:b0:2cf:41ba:96c2 with SMTP id d9443c01a7336-2d08aad82b4mr18597015ad.12.1785816373710; Mon, 03 Aug 2026 21:06:13 -0700 (PDT) Received: from yhlee-960QFG.. ([125.131.91.97]) by smtp.gmail.com with ESMTPSA id d9443c01a7336-2d04b11f9a9sm46075465ad.57.2026.08.03.21.06.11 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 03 Aug 2026 21:06:13 -0700 (PDT) From: Yehyeong Lee To: lduncan@suse.com, cleech@redhat.com, michael.christie@oracle.com, James.Bottomley@HansenPartnership.com, martin.petersen@oracle.com Cc: open-iscsi@googlegroups.com, linux-scsi@vger.kernel.org, linux-kernel@vger.kernel.org, Yehyeong Lee , stable@vger.kernel.org Subject: [PATCH v2 2/3] scsi: libiscsi: validate the ITT reflected in a Reject PDU Date: Tue, 4 Aug 2026 13:05:45 +0900 Message-ID: <20260804040546.2264137-3-yhlee@isslab.korea.ac.kr> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260804040546.2264137-1-yhlee@isslab.korea.ac.kr> References: <20260804040546.2264137-1-yhlee@isslab.korea.ac.kr> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" A Reject PDU carries a copy of the header it rejects, and iscsi_handle_reject() takes the ITT out of that copy to find the task to clean up: memcpy(&rejected_pdu, data, sizeof(struct iscsi_hdr)); ... task =3D iscsi_itt_to_task(conn, rejected_pdu.itt); That value is whatever the target put there. iscsi_itt_to_task() bounds the index against cmds_max and checks nothing else, so any task in the pool can be named, and iscsi_nop_out_rsp() then completes it. An index that has never been used gives a NULL task->conn: the pool is zeroed at session setup and conn is assigned only when a task is allocated. If the task was used and returned, iscsi_complete_task() hits its WARN_ON_ONCE(task->state =3D=3D ISCSI_TASK_FREE) and the refcount underflows. An in-flight SCSI command is completed as successful - a 1 MiB read returned 1048576 with none of its buffer written and no warning. Validate the reflected ITT the way iscsi_itt_to_ctask() validates a command ITT, and require the task to be in flight and not a SCSI command. [ 6.248477] Oops: general protection fault, probably for non-canonical a= ddress 0xdffffc000000000c: 0000 [#1] SMP KASAN NOPTI [ 6.249357] KASAN: null-ptr-deref in range [0x0000000000000060-0x0000000= 000000067] [ 6.249951] CPU: 1 UID: 0 PID: 0 Comm: swapper/1 Not tainted 7.2.0-rc5-I= SCSI1-gf5098b6bae76 #1 PREEMPT(lazy) [ 6.250718] Hardware name: QEMU Ubuntu 24.04 PC v2 (i440FX + PIIX, arch_= caps fix, 1996), BIOS 1.16.3-debian-1.16.3-2 04/01/2014 [ 6.251616] RIP: 0010:iscsi_nop_out_rsp.constprop.0+0x46/0x160 [ 6.252043] Code: c1 ea 03 48 83 ec 08 80 3c 02 00 0f 85 f5 00 00 00 48 = b8 00 00 00 00 00 fc ff df 48 8b 6b 58 48 8d 7d 60 48 89 fa 48 c1 ea 03 <80= > 3c 02 00 0f 85 c0 00 00 00 48 8b 45 60 48 39 c3 74 50 48 b8 00 [ 6.252813] RSP: 0018:ffff88806c907b80 EFLAGS: 00010206 [ 6.253042] RAX: dffffc0000000000 RBX: ffff88800607e000 RCX: ffffffff8d5= 71a25 [ 6.253345] RDX: 000000000000000c RSI: ffff88806c907c38 RDI: 00000000000= 00060 [ 6.253642] RBP: 0000000000000000 R08: 0000000000000000 R09: fffffbfff23= 5a504 [ 6.253947] R10: 0000000000000003 R11: 7463656e6e6f6320 R12: 00000000000= 00000 [ 6.254251] R13: 0000000000000000 R14: ffff88806c907c38 R15: 00000000000= 00000 [ 6.254549] FS: 0000000000000000(0000) GS:ffff8880d95bc000(0000) knlGS:= 0000000000000000 [ 6.254887] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [ 6.255140] CR2: 00007fc393e8ffc0 CR3: 0000000005252006 CR4: 00000000007= 70ef0 [ 6.255439] PKRU: 55555554 [ 6.255564] Call Trace: [ 6.255674] [ 6.255768] __iscsi_complete_pdu+0x18bf/0x22a0 [ 6.256733] iscsi_complete_pdu+0x54/0xa0 [ 6.256905] iscsi_tcp_data_recv_done+0xf4/0x250 [ 6.257103] iscsi_tcp_recv_skb+0x31e/0xec0 [ 6.257680] iscsi_sw_tcp_recv+0x12f/0x390 [ 6.258061] __tcp_read_sock+0x1ab/0x810 [ 6.258853] iscsi_sw_tcp_data_ready+0x18b/0x510 [ 6.259808] tcp_data_queue+0x1f13/0x4cd0 [ 6.260567] tcp_rcv_established+0x8a5/0x3a00 [ 6.261931] tcp_v4_do_rcv+0x449/0x960 [ 6.262269] tcp_v4_rcv+0x2245/0x3bc0 Fixes: 8afa1439fcff ("[SCSI] libiscsi: handle immediate command rejections") Cc: stable@vger.kernel.org Signed-off-by: Yehyeong Lee --- Measured on 7.2-rc5 with KASAN over a proxy that injects one Reject PDU. Unpatched: the unused index oopses, the returned index warns and underflows the refcount, and the in-flight read returns 1048576 with 0 bytes filled. With the patch the reject is refused in all three cases and the connection is failed the way an unknown ITT already is. A NOP-Out ping reflected in a Reject - the case this branch exists for - completes normally on both kernels. drivers/scsi/libiscsi.c | 7 +++++-- 1 file changed, 5 insertions(+), 2 deletions(-) diff --git a/drivers/scsi/libiscsi.c b/drivers/scsi/libiscsi.c index 7a74bc697d23..774ed4739891 100644 --- a/drivers/scsi/libiscsi.c +++ b/drivers/scsi/libiscsi.c @@ -1147,8 +1147,11 @@ static int iscsi_handle_reject(struct iscsi_conn *co= nn, struct iscsi_hdr *hdr, * Our nop as ping got dropped. We know the target * and transport are ok so just clean up */ - task =3D iscsi_itt_to_task(conn, rejected_pdu.itt); - if (!task) { + task =3D NULL; + if (!iscsi_verify_itt(conn, rejected_pdu.itt)) + task =3D iscsi_itt_to_task(conn, rejected_pdu.itt); + if (!task || task->state =3D=3D ISCSI_TASK_FREE || + task->sc) { iscsi_conn_printk(KERN_ERR, conn, "Invalid pdu reject. Could " "not lookup rejected task.\n"); --=20 2.43.0 From nobody Fri Oct 2 07:47:19 2026 Received: from mail-pl1-f182.google.com (mail-pl1-f182.google.com [209.85.214.182]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 747AA439F67 for ; Tue, 4 Aug 2026 04:06:18 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.214.182 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785816379; cv=none; b=rFjPyH8XpSjG7ANsedNGZiwmxgmW7tHKm7SviB4DOxge0zUoNrjLmSk58TpZg8vVksLKgIZAU0tUIhjUHrnRURupfhVkHI2Yu6MKYlOg5U0xFh/Or35kpwSiReUsjg9fBST0bM3FdQZ0XKIYMZc2zmcCh1MCJLZB2mnGAt/vCBg= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785816379; c=relaxed/simple; bh=c8tpaQw6h+4PJrv3+oEbnYXEVyHOwxSI+jSTWfX3sdk=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=GBDqyLhr6Xb/SDT27kv82PG8RXFhgBSYIaX1OOJPJ2LhQgIkIMxlGhRBtGZsTcJ7la+e9qTIEGJTFzgMHEZnawAbYdmjVH28bWjRxSMRcX1HTmNYy8ueuIuA+c3wm6JpXa4LVBzrff6sbcnspenaEdf4p8BDjoDMwrZqKFmVREw= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=fail (p=none dis=none) header.from=isslab.korea.ac.kr; spf=none smtp.mailfrom=isslab.korea.ac.kr; dkim=pass (2048-bit key) header.d=isslab-korea-ac-kr.20251104.gappssmtp.com header.i=@isslab-korea-ac-kr.20251104.gappssmtp.com header.b=yx3rO7rN; arc=none smtp.client-ip=209.85.214.182 Authentication-Results: smtp.subspace.kernel.org; dmarc=fail (p=none dis=none) header.from=isslab.korea.ac.kr Authentication-Results: smtp.subspace.kernel.org; spf=none smtp.mailfrom=isslab.korea.ac.kr Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=isslab-korea-ac-kr.20251104.gappssmtp.com header.i=@isslab-korea-ac-kr.20251104.gappssmtp.com header.b="yx3rO7rN" Received: by mail-pl1-f182.google.com with SMTP id d9443c01a7336-2cab973140bso51535205ad.3 for ; Mon, 03 Aug 2026 21:06:18 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=isslab-korea-ac-kr.20251104.gappssmtp.com; s=20251104; t=1785816378; x=1786421178; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=95xetes3VqtMnIXr5wKpo+TbCiS/2h8e0gf4Of94Vw8=; b=yx3rO7rNhY4q6Ee0RL9HTrkpwC/4iMT9Q4sbYpEAjmyOf20YqSE/R/LgMmTN3o7yFo nVFPt2clTinIOUnfZQqlr1u8jnEUaYDykYaIdwqpRmxp5kkiO1nro0075EHr3IZOsslL DOGyUpE7gv8Ls4dAgG9mxXu7yl8T7DJ5CXXZqJab+X0i6BmR+G1YNbsannDN5nxo2A3V rwOik3ILZpgs9opj0zkUEF3bO25DSVy5QpE6RRp8i4tsmNr8x3gX3zbhXs4G3p/AeQXJ YbsIos/EDuRGVL2/UqYPQLFSiwHgEPMYP3/WXuPbfaceEi1Mos9uJFoGuoN8Zx+qyQ9A GqMQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785816378; x=1786421178; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=95xetes3VqtMnIXr5wKpo+TbCiS/2h8e0gf4Of94Vw8=; b=SfQxEa+WhGAM9qK+/1Xlau6ku5KUShY1sm7IB+gvaQaB+sOMaaZ9pe9pkbrxi3Hs3/ U8ujSYHbv5yDRTfsQFVAi0oZBiLaXheecICCtu+b4K8+9kBO/iQ/N0WNxA/9NYj6I4GE Z3JWujUt8YDe4KYMaVqiSb+sX211DacmZh3f7+jsm15QClcd9RPRQIWybYWqjfusQGDH n5EWF7/nPPNed/vL+Fc0NnXF67r0aEHImsmK4le6o7hNT442NNCueUZNHtH1ofPIdb7b m4V9hkaPAcHGpP5OMUUfvKsmZSaDxu3JsOQ1uv1f7jPQI/NRrqYPcAWEEcpQV8dzvrMq XkYw== X-Forwarded-Encrypted: i=1; AHgh+Rr7lXoEnkzD4lw25X70gshKP7ewUuHNuNQIW96GX1zcDUk8VzwTK+w0UIvVnSQwyENwODuUJmgSQb95qJ0=@vger.kernel.org X-Gm-Message-State: AOJu0Yx31p7kx3XhwRtTGIIp/j3AfNQFmffT+XQBMYeVfCwiLK2h/XEu ljIdQnQRSCIEZegmLVcEE3f2l7PE3QKycW+L6wwE2S2KF/djvfRe1WIk9vlnIxWVzVc= X-Gm-Gg: AR+sD11PzcB1aauItjgK5NzMDzSxNk1e13UF/V7Q8QJ/vj+0RC2xfkRWKIl7ix+G+eq cs1GKx1DSmhbS9Mkv+oSr5EWw9HEUv4MWPFCyDPFstaln15SZveDs5ixGKh+lgwRAng9D3MZqKZ dlOZPWcZcMEgbU6E5wEUrwSyF6OArewP8HQfNazYc0BJnFtyyfT97yv5ye0rJ/YuArDaUvT1X/7 41+ugmY6gzRXRbHkjwn5u9GgKV5AVAZPZaW8LskbwUx1e+yjgXYhkPFvZS0Luc7FyS+mahBEktI 0zzBNMsnLZqF1K5YY/asj0goF6TknvqYPUR1OXuWBf4hh8RfQ8skVQxBUCHrNh/Y4pHT+cgasUh 6xBmSu4WrRkzaKTIp2lsakVGh7xnrheYurKm3ExrMI8QVrzBwBCAQ/S5IW9bC+0vRg+dj1KkpQ+ +jjjBk3QzjSHnlJA28yS9vifD/U8fO4B4s/pp+5JrFeEYt4BxEYzCHGsgMdXA9WPTgVWDs X-Received: by 2002:a17:902:ecd1:b0:2cf:b69a:8f58 with SMTP id d9443c01a7336-2d0523e7d92mr114058285ad.37.1785816377839; Mon, 03 Aug 2026 21:06:17 -0700 (PDT) Received: from yhlee-960QFG.. ([125.131.91.97]) by smtp.gmail.com with ESMTPSA id d9443c01a7336-2d04b11f9a9sm46075465ad.57.2026.08.03.21.06.15 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 03 Aug 2026 21:06:16 -0700 (PDT) From: Yehyeong Lee To: lduncan@suse.com, cleech@redhat.com, michael.christie@oracle.com, James.Bottomley@HansenPartnership.com, martin.petersen@oracle.com Cc: open-iscsi@googlegroups.com, linux-scsi@vger.kernel.org, linux-kernel@vger.kernel.org, Yehyeong Lee , stable@vger.kernel.org Subject: [PATCH v2 3/3] scsi: libiscsi: validate the task named by a management response Date: Tue, 4 Aug 2026 13:05:46 +0900 Message-ID: <20260804040546.2264137-4-yhlee@isslab.korea.ac.kr> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260804040546.2264137-1-yhlee@isslab.korea.ac.kr> References: <20260804040546.2264137-1-yhlee@isslab.korea.ac.kr> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" __iscsi_complete_pdu() fetches the task for five response types from one place and checks only that the index resolved: case ISCSI_OP_LOGOUT_RSP: case ISCSI_OP_LOGIN_RSP: case ISCSI_OP_TEXT_RSP: case ISCSI_OP_SCSI_TMFUNC_RSP: case ISCSI_OP_NOOP_IN: task =3D iscsi_itt_to_task(conn, hdr->itt); if (!task) return ISCSI_ERR_BAD_ITT; iscsi_itt_to_task() bounds the index against cmds_max and looks at nothing else, so a target can name any slot in the pool, including one that has never been used. task->conn is then NULL, and both iscsi_nop_out_rsp() and iscsi_complete_task() dereference it. One unsolicited NOP-In is enough; a Text Response carrying the same ITT crashes in iscsi_complete_task() instead. Require the task to be in flight and not a SCSI command, the way iscsi_itt_to_ctask() does for the command opcodes. [ 6.298634] Oops: general protection fault, probably for non-canonical a= ddress 0xdffffc000000000c: 0000 [#1] SMP KASAN NOPTI [ 6.298642] KASAN: null-ptr-deref in range [0x0000000000000060-0x0000000= 000000067] [ 6.298652] CPU: 1 UID: 0 PID: 111 Comm: iscsistart Not tainted 7.2.0-rc= 5-ISCSI1-gf5098b6bae76 #1 PREEMPT(lazy) [ 6.298654] Hardware name: QEMU Ubuntu 24.04 PC v2 (i440FX + PIIX, arch_= caps fix, 1996), BIOS 1.16.3-debian-1.16.3-2 04/01/2014 [ 6.298656] RIP: 0010:iscsi_nop_out_rsp.constprop.0+0x46/0x160 [ 6.298691] Code: c1 ea 03 48 83 ec 08 80 3c 02 00 0f 85 f5 00 00 00 48 = b8 00 00 00 00 00 fc ff df 48 8b 6b 58 48 8d 7d 60 48 89 fa 48 c1 ea 03 <80= > 3c 02 00 0f 85 c0 00 00 00 48 8b 45 60 48 39 c3 74 50 48 b8 00 [ 6.298698] RSP: 0018:ffff88806c907be8 EFLAGS: 00010206 [ 6.298701] RAX: dffffc0000000000 RBX: ffff888006116800 RCX: 00000000000= 00020 [ 6.298702] RDX: 000000000000000c RSI: ffff88800525d578 RDI: 00000000000= 00060 [ 6.298703] RBP: 0000000000000000 R08: 0000000000000000 R09: 00000000000= 00000 [ 6.298706] R10: 0000000000000020 R11: 0000000000000000 R12: 00000000000= 00000 [ 6.298706] R13: 000000000000002e R14: ffff8880056eb440 R15: ffff8880061= 16800 [ 6.298707] FS: 00007fc02d1c2740(0000) GS:ffff8880b29bc000(0000) knlGS:= 0000000000000000 [ 6.298710] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [ 6.298711] CR2: 000055fe3b56ddf8 CR3: 00000000053b9004 CR4: 00000000007= 70ef0 [ 6.298712] PKRU: 55555554 [ 6.298713] Call Trace: [ 6.298714] [ 6.298714] __iscsi_complete_pdu+0x13a8/0x22a0 [ 6.298758] iscsi_complete_pdu+0x54/0xa0 [ 6.298759] iscsi_tcp_hdr_recv_done+0x870/0x2c80 [ 6.298778] iscsi_tcp_recv_skb+0x31e/0xec0 [ 6.298800] iscsi_sw_tcp_recv+0x12f/0x390 [ 6.298804] __tcp_read_sock+0x1ab/0x810 [ 6.298812] iscsi_sw_tcp_data_ready+0x18b/0x510 [ 6.298814] tcp_rcv_established+0x1f56/0x3a00 [ 6.298842] tcp_v4_do_rcv+0x449/0x960 [ 6.298847] tcp_v4_rcv+0x2245/0x3bc0 Fixes: 7996a778ff8c ("[SCSI] iscsi: add libiscsi") Cc: stable@vger.kernel.org Signed-off-by: Yehyeong Lee --- Measured on 7.2-rc5 with KASAN over a proxy that injects one PDU. An unsolicited NOP-In naming an unused index oopses in 5 of 5 runs and none of 5 with the patch; a Text Response carrying the same ITT oopses in 5 of 5 and none of 5. A Reject reflecting the ITT of an in-flight abort TMF warns and underflows the refcount unpatched and does neither with the series. Normal I/O and a NOP-Out ping rejected by the target are unchanged. drivers/scsi/libiscsi.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/drivers/scsi/libiscsi.c b/drivers/scsi/libiscsi.c index 774ed4739891..d62d6c5ef8d6 100644 --- a/drivers/scsi/libiscsi.c +++ b/drivers/scsi/libiscsi.c @@ -1287,7 +1287,7 @@ int __iscsi_complete_pdu(struct iscsi_conn *conn, str= uct iscsi_hdr *hdr, case ISCSI_OP_SCSI_TMFUNC_RSP: case ISCSI_OP_NOOP_IN: task =3D iscsi_itt_to_task(conn, hdr->itt); - if (!task) + if (!task || task->state =3D=3D ISCSI_TASK_FREE || task->sc) return ISCSI_ERR_BAD_ITT; break; default: --=20 2.43.0