nvme: clamp FDP nruhsd to allocated RUH status descriptor count

nvme_query_fdp_info() allocates the RUH status buffer for at most S8_MAX
- 1 descriptors, and then copies ruhs->ruhsd[] into head->plids[] using
the controller reported ruhs->nruhsd directly as the loop bound.
However, that count wasn't taken into account for the actual buffer's
size, so there was a chance for a controller reporting a larger nruhsd
to cause the copy to overflow the buffer.  Clamp nr_plids to the same
bound used for the allocation.

Assisted-by: gkh_clanker_t1000
Reviewed-by: Christoph Hellwig <hch@lst.de>
Signed-off-by: Hari Mishal <harimishal1@gmail.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Keith Busch <kbusch@kernel.org>
This commit is contained in:
Hari Mishal 2026-07-09 14:30:33 +02:00 committed by Keith Busch
parent 3c568b35a0
commit 29261f8bb4

View File

@ -2361,7 +2361,7 @@ static int nvme_query_fdp_info(struct nvme_ns *ns, struct nvme_ns_info *info)
goto free;
}
head->nr_plids = le16_to_cpu(ruhs->nruhsd);
head->nr_plids = min(le16_to_cpu(ruhs->nruhsd), S8_MAX - 1);
if (!head->nr_plids)
goto free;