Re: [PATCH v2] scsi: libiscsi_tcp: bound SCSI Response data segment to the connection buffer

From: Chris Leech

Date: Thu Jul 16 2026 - 09:59:10 EST


On Thu, Jul 16, 2026 at 03:58:48PM +0900, HyeongJun An wrote:
> iscsi_tcp_hdr_dissect() receives the data segment of several PDU types
> into the fixed-size conn->data buffer, which is allocated for
> ISCSI_DEF_MAX_RECV_SEG_LEN (8192) bytes. For the LOGIN_RSP, TEXT_RSP,
> REJECT and ASYNC_EVENT opcodes the dissect path already rejects a PDU
> whose DataSegmentLength exceeds that buffer.
>
> The SCSI Command Response (ISCSI_OP_SCSI_CMD_RSP) path also copies its
> data segment (sense/response data) into conn->data via
> iscsi_tcp_data_recv_prep(), but it does so without the same check. The
> only upstream bound on in.datalen is conn->max_recv_dlength, the
> initiator's advertised MaxRecvDataSegmentLength, which is commonly
> negotiated well above 8192 (open-iscsi defaults to 262144). A target
> that returns a SCSI Response with a DataSegmentLength between 8193 and
> max_recv_dlength therefore overflows the 8192-byte conn->data buffer.
>
> Once the same bound applies, ISCSI_OP_SCSI_CMD_RSP is handled exactly
> like those responses: bound the data segment, receive it into conn->data
> when present, and otherwise complete the PDU with no data. Fold the
> opcode into that case group rather than duplicating the check.
>
> Fixes: a081c13e39b5 ("[SCSI] iscsi_tcp: split module into lib and lld")
> Suggested-by: Chris Leech <cleech@xxxxxxxxxx>
> Assisted-by: Claude:claude-opus-4-8
> Signed-off-by: HyeongJun An <sammiee5311@xxxxxxxxx>
> ---
> v2: Fold ISCSI_OP_SCSI_CMD_RSP into the LOGIN_RSP/TEXT_RSP/REJECT/
> ASYNC_EVENT case group instead of duplicating the bounds check, as
> suggested by Chris Leech. The handling is identical: both bound the
> data segment to conn->data, receive it when present, and otherwise
> complete the PDU with no data (the latter via the LOGOUT_RSP
> fallthrough). No functional change from v1.
>
> v1: https://lore.kernel.org/all/20260710050645.1194212-1-sammiee5311@xxxxxxxxx/
>
> drivers/scsi/libiscsi_tcp.c | 8 +-------
> 1 file changed, 1 insertion(+), 7 deletions(-)

Acked-by: Chris Leech <cleech@xxxxxxxxxx>