[PATCH 6.6.y v2 0/2] scsi: lpfc: Backport SFP mailbox timeout handling

From: Artem Dinaburg

Date: Fri Oct 02 2026 - 14:22:19 EST


Hi Sasha and lpfc maintainers,

Thanks for catching the SLI3 overflow in v1.

This v2 takes the ext_buf portion of upstream commit 115d137aa918 first.
That leaves the SLI3 response in the existing 1,024-byte DMA buffer while
ctx_buf continues to point to the descriptor used by cleanup. Patch 2 then
backports the original CVE-2024-46842 fix from ede596b1434b.

Could you please queue these two patches for 6.6.y?

Changes in v2:
- replace the unsafe ctx_buf restoration with the ext_buf prerequisite;
- send the prerequisite and CVE fix as a two-patch series;
- keep the generic upstream ownership race out of this backport; and
- rebase and rebuild after the current 6.6 stable queue.

v1: https://lore.kernel.org/r/20260930024505.96440-1-artem@xxxxxxxxxxxxxxx
Review: https://lore.kernel.org/r/2026-09-30-1-daily-reply-0014-lpfc-sfp-info-mbox-timeout-6-6@xxxxxxxxxx

Thanks,
Artem Dinaburg

Justin Tee (2):
scsi: lpfc: Define lpfc_dmabuf type for ctx_buf ptr
scsi: lpfc: Handle mailbox timeouts in lpfc_get_sfp_info

drivers/scsi/lpfc/lpfc_bsg.c | 2 +-
drivers/scsi/lpfc/lpfc_els.c | 21 +++++++++++++--------
drivers/scsi/lpfc/lpfc_sli.c | 20 ++++++++++----------
drivers/scsi/lpfc/lpfc_sli.h | 1 +
4 files changed, 25 insertions(+), 19 deletions(-)

base-commit: 79643295eba17affbd16ca97f3ef04c90266b28c
--
2.39.5