Re: [PATCH 6.6.y] scsi: lpfc: Handle mailbox timeouts in lpfc_get_sfp_info
From: Sasha Levin
Date: Thu Oct 01 2026 - 10:00:57 EST
> [ Backport to 6.6.y: v6.6 predates ext_buf and uses ctx_buf for the SLI3
> raw payload. Restore ctx_buf to the saved struct lpfc_dmabuf before
> testing LPFC_MBX_WAKE so a timed-out mailbox's late default completion
> sees the DMA descriptor rather than payload bytes. ]
This isn't safe on SLI3 HBAs. When the new 60s wait times out, ctx_buf
is pointed back at mpsave, a 40-byte struct lpfc_dmabuf, while
out_ext_byte_len is still 256. If the firmware completes between 60s and
the 300s mailbox timeout, the SLI3 interrupt handler copies those 256
bytes into the dmabuf. That is a slab overflow, and lpfc_mbuf_free() then
runs on the corrupted virt/phys.
--
Thanks,
Sasha