mirror of
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
synced 2026-09-22 09:34:56 +02:00
ata: libata-core: Reject an invalid concurrent positioning ranges count
[ Upstream commit533a0b940f] ata_dev_config_cpr() takes the number of range descriptors from buf[0] of the concurrent positioning ranges log (up to 255), which the device reports independently of the log size in the GPL directory. The count is then walked at a fixed 32-byte stride in two places with no bound: the log read here, and the INQUIRY VPD page B9h emitter, which writes one descriptor per range into the fixed 2048-byte ata_scsi_rbuf. A device reporting a count larger than its own log overflows the read buffer (up to 7704 bytes past a 512-byte slab), and a count above 62 overflows the response buffer on the emit side. Bound the count once, on probe, against both the log the device returned and the number of descriptors the VPD B9h response buffer can hold (ATA_DEV_MAX_CPR, derived from the rbuf size). Reject an out-of-range count with a warning; this keeps the emitter in bounds with no separate change there. Suggested-by: Damien Le Moal <dlemoal@kernel.org> Fixes:fe22e1c2f7("libata: support concurrent positioning ranges log") Fixes:c745dfc541("libata: fix reading concurrent positioning ranges log") Cc: stable@vger.kernel.org Signed-off-by: Bryam Vargas <hexlabsecurity@proton.me> Reviewed-by: Niklas Cassel <cassel@kernel.org> Signed-off-by: Damien Le Moal <dlemoal@kernel.org> [ adapted `kzalloc_flex()` allocation to `kzalloc(struct_size(...), GFP_KERNEL)` and adjusted context offsets. ] Signed-off-by: Sasha Levin <sashal@kernel.org> Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
This commit is contained in:
committed by
Greg Kroah-Hartman
parent
9466dc5e37
commit
4c1e8ccd86
@@ -2833,6 +2833,24 @@ static void ata_dev_config_cpr(struct ata_device *dev)
|
||||
if (!nr_cpr)
|
||||
goto out;
|
||||
|
||||
/*
|
||||
* The device reports the number of CPR descriptors independently of the
|
||||
* log size, and that count is also used to emit VPD page B9h into the
|
||||
* fixed-size rbuf. Reject a count larger than what that buffer can hold
|
||||
* (ATA_DEV_MAX_CPR) or larger than the log the device actually returned.
|
||||
*/
|
||||
if (nr_cpr > ATA_DEV_MAX_CPR) {
|
||||
ata_dev_warn(dev,
|
||||
"Too many concurrent positioning ranges\n");
|
||||
goto out;
|
||||
}
|
||||
|
||||
if (buf_len < 64 + (size_t)nr_cpr * 32) {
|
||||
ata_dev_warn(dev,
|
||||
"Invalid number of concurrent positioning ranges\n");
|
||||
goto out;
|
||||
}
|
||||
|
||||
cpr_log = kzalloc(struct_size(cpr_log, cpr, nr_cpr), GFP_KERNEL);
|
||||
if (!cpr_log)
|
||||
goto out;
|
||||
|
||||
@@ -37,8 +37,6 @@
|
||||
#include "libata.h"
|
||||
#include "libata-transport.h"
|
||||
|
||||
#define ATA_SCSI_RBUF_SIZE 2048
|
||||
|
||||
static DEFINE_SPINLOCK(ata_scsi_rbuf_lock);
|
||||
static u8 ata_scsi_rbuf[ATA_SCSI_RBUF_SIZE];
|
||||
|
||||
|
||||
@@ -144,6 +144,15 @@ static inline void ata_acpi_bind_dev(struct ata_device *dev) {}
|
||||
#endif
|
||||
|
||||
/* libata-scsi.c */
|
||||
#define ATA_SCSI_RBUF_SIZE 2048
|
||||
|
||||
/*
|
||||
* Maximum number of concurrent positioning ranges (CPR) supported. The ACS
|
||||
* specifications allow up to 255, but we limit this to the number of CPR
|
||||
* descriptors that fit in the rbuf buffer used to emit VPD page B9h.
|
||||
*/
|
||||
#define ATA_DEV_MAX_CPR min(255, ((ATA_SCSI_RBUF_SIZE - 64) / 32))
|
||||
|
||||
extern struct ata_device *ata_scsi_find_dev(struct ata_port *ap,
|
||||
const struct scsi_device *scsidev);
|
||||
extern int ata_scsi_add_hosts(struct ata_host *host,
|
||||
|
||||
Reference in New Issue
Block a user