Re: [PATCH] scsi: core: Validate MODE SENSE lengths in scsi_cdl_enable()

From: Damien Le Moal

Date: Mon Sep 07 2026 - 00:09:04 EST


On 9/4/26 22:54, Alberto Carboneri wrote:
> scsi_cdl_enable() uses length fields returned by MODE SENSE to locate the
> ATA feature mode page in a 64-byte stack buffer. A target can report a
> total length shorter than its mode header and block descriptors. The
> unsigned subtraction used for the MODE SELECT length can wrap, and the
> separately computed buf_data can point beyond buf.
>
> During automatic scan, enable is false, so the read-modify-write of
> buf_data[4] can clear the low two bits of a target-selected out-of-bounds
> stack byte. scsi_mode_select() can then copy up to 64 bytes from outside
> the buffer into the outgoing MODE SELECT payload, disclosing stack contents
> to the target.
>
> This is reachable while scanning a USB storage device that identifies as
> an ATA device and advertises CDL support. No filesystem mount or userspace
> access to the block device is required.
>
> On upstream commit cee9395acd80 ("Linux 7.3-rc1"), a build-specific,
> one-vCPU QEMU/Raw Gadget proof using QEMU-only multi-UDC allocator
> sampling executed a fixed proof command inside the guest and created a
> UID-0-owned marker during automatic enumeration, with KASLR and NX
> enabled.
>
> The issue was independently found during security research at Drivesec
> S.r.l.
>
> Cap the available length to the buffer size. Validate and consume the mode
> header and block descriptor lengths before using the page, and require the
> five bytes needed to access the CDL field.
>
> Fixes: 1b22cfb14142 ("scsi: core: Allow enabling and disabling command duration limits")
> Reported-by: Sashiko AI Review <sashiko-bot@xxxxxxxxxx>
> Closes: https://lore.kernel.org/linux-scsi/20260717192313.93D791F000E9@xxxxxxxxxxxxxxx/
> Link: https://lore.kernel.org/linux-scsi/20260717222931.AC4EE1F000E9@xxxxxxxxxxxxxxx/
> Link: https://lore.kernel.org/linux-scsi/df13ec87ac9b28e3b0a2d9eb26477e276ff0278a.camel@xxxxxxxxxxxxxxxxxxxxx/
> Cc: stable@xxxxxxxxxxxxxxx
> Assisted-by: LLM
> Co-developed-by: Pimen Flavian Dei (Drivesec S.r.l.) <fdei@xxxxxxxxxxxx>
> Signed-off-by: Pimen Flavian Dei (Drivesec S.r.l.) <fdei@xxxxxxxxxxxx>
> Signed-off-by: Alberto Carboneri (Drivesec S.r.l.) <acarboneri@xxxxxxxxxxxx>

Looks good.

Reviewed-by: Damien Le Moal <dlemoal@xxxxxxxxxx>

--
Damien Le Moal
Western Digital Research