[PATCH 6.6.y v2 0/2] scsi: lpfc: Backport SFP mailbox timeout handling
From: Artem Dinaburg
Date: Fri Oct 02 2026 - 14:22:19 EST
Hi Sasha and lpfc maintainers,
Thanks for catching the SLI3 overflow in v1.
This v2 takes the ext_buf portion of upstream commit 115d137aa918 first.
That leaves the SLI3 response in the existing 1,024-byte DMA buffer while
ctx_buf continues to point to the descriptor used by cleanup. Patch 2 then
backports the original CVE-2024-46842 fix from ede596b1434b.
Could you please queue these two patches for 6.6.y?
Changes in v2:
- replace the unsafe ctx_buf restoration with the ext_buf prerequisite;
- send the prerequisite and CVE fix as a two-patch series;
- keep the generic upstream ownership race out of this backport; and
- rebase and rebuild after the current 6.6 stable queue.
v1: https://lore.kernel.org/r/20260930024505.96440-1-artem@xxxxxxxxxxxxxxx
Review: https://lore.kernel.org/r/2026-09-30-1-daily-reply-0014-lpfc-sfp-info-mbox-timeout-6-6@xxxxxxxxxx
Thanks,
Artem Dinaburg
Justin Tee (2):
scsi: lpfc: Define lpfc_dmabuf type for ctx_buf ptr
scsi: lpfc: Handle mailbox timeouts in lpfc_get_sfp_info
drivers/scsi/lpfc/lpfc_bsg.c | 2 +-
drivers/scsi/lpfc/lpfc_els.c | 21 +++++++++++++--------
drivers/scsi/lpfc/lpfc_sli.c | 20 ++++++++++----------
drivers/scsi/lpfc/lpfc_sli.h | 1 +
4 files changed, 25 insertions(+), 19 deletions(-)
base-commit: 79643295eba17affbd16ca97f3ef04c90266b28c
--
2.39.5