mirror of
https://github.com/torvalds/linux.git
synced 2026-09-27 02:22:02 +02:00
nvme: clamp FDP nruhsd to allocated RUH status descriptor count
nvme_query_fdp_info() allocates the RUH status buffer for at most S8_MAX - 1 descriptors, and then copies ruhs->ruhsd[] into head->plids[] using the controller reported ruhs->nruhsd directly as the loop bound. However, that count wasn't taken into account for the actual buffer's size, so there was a chance for a controller reporting a larger nruhsd to cause the copy to overflow the buffer. Clamp nr_plids to the same bound used for the allocation. Assisted-by: gkh_clanker_t1000 Reviewed-by: Christoph Hellwig <hch@lst.de> Signed-off-by: Hari Mishal <harimishal1@gmail.com> Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org> Signed-off-by: Keith Busch <kbusch@kernel.org>
This commit is contained in:
parent
3c568b35a0
commit
29261f8bb4
|
|
@ -2361,7 +2361,7 @@ static int nvme_query_fdp_info(struct nvme_ns *ns, struct nvme_ns_info *info)
|
|||
goto free;
|
||||
}
|
||||
|
||||
head->nr_plids = le16_to_cpu(ruhs->nruhsd);
|
||||
head->nr_plids = min(le16_to_cpu(ruhs->nruhsd), S8_MAX - 1);
|
||||
if (!head->nr_plids)
|
||||
goto free;
|
||||
|
||||
|
|
|
|||
Loading…
Reference in New Issue
Block a user