RE: [EXTERNAL] [PATCH 1/1] scsi: Fix possible buffer overflows in storvsc_queuecommand
From: KY Srinivasan <kys@microsoft.com>
Date: 2020-12-08 16:30:52
Also in:
linux-scsi, lkml
quoted hunk ↗ jump to hunk
-----Original Message----- From: Xiaohui Zhang <redacted> Sent: Tuesday, December 8, 2020 5:19 AM To: Xiaohui Zhang <redacted>; KY Srinivasan [off-list ref]; Haiyang Zhang [off-list ref]; Stephen Hemminger [off-list ref]; Wei Liu [off-list ref]; James E.J. Bottomley [off-list ref]; Martin K. Petersen [off-list ref]; linux-hyperv@vger.kernel.org; linux- scsi@vger.kernel.org; linux-kernel@vger.kernel.org Subject: [EXTERNAL] [PATCH 1/1] scsi: Fix possible buffer overflows in storvsc_queuecommand From: Zhang Xiaohui <redacted> storvsc_queuecommand() calls memcpy() without checking the destination size may trigger a buffer overflower, which a local user could use to cause denial of service or the execution of arbitrary code. Fix it by putting the length check before calling memcpy(). Signed-off-by: Zhang Xiaohui <redacted> --- drivers/scsi/storvsc_drv.c | 2 ++ 1 file changed, 2 insertions(+)diff --git a/drivers/scsi/storvsc_drv.c b/drivers/scsi/storvsc_drv.c index0c65fbd41..09b60a4c0 100644--- a/drivers/scsi/storvsc_drv.c +++ b/drivers/scsi/storvsc_drv.c@@ -1729,6 +1729,8 @@ static int storvsc_queuecommand(struct Scsi_Host*host, struct scsi_cmnd *scmnd) vm_srb->cdb_length = scmnd->cmd_len; + if (vm_srb->cdb_length > STORVSC_MAX_CMD_LEN) + vm_srb->cdb_length = STORVSC_MAX_CMD_LEN; memcpy(vm_srb->cdb, scmnd->cmnd, vm_srb->cdb_length);
The data structure is sized correctly to handle the max command length. Besides your check is bogus - you cannot truncate the command! K. Y
sgl = (struct scatterlist *)scsi_sglist(scmnd); -- 2.17.1