| From 6efbc52237facda35d2d874fe1765bb4839275d8 Mon Sep 17 00:00:00 2001 |
| From: Yehyeong Lee <yhlee@isslab.korea.ac.kr> |
| Date: Wed, 29 Jul 2026 14:46:02 +0900 |
| Subject: nvme-tcp: fix host memory disclosure on R2T for a read command |
| |
| From: Yehyeong Lee <yhlee@isslab.korea.ac.kr> |
| |
| commit 6efbc52237facda35d2d874fe1765bb4839275d8 upstream. |
| |
| nvme_tcp_handle_r2t() does not check the direction of the request the |
| R2T refers to. A malicious controller can send an R2T for a READ and |
| the host will answer it: nvme_tcp_setup_h2c_data_pdu() builds the |
| H2CData header and nvme_tcp_try_send_data() sends the request's data |
| buffer. That buffer is the READ destination, so its contents go to the |
| controller. |
| |
| The command then completes normally and nothing is logged. |
| |
| Against a test controller that answers every READ with an R2T, a 4096 |
| byte buffered read returned all 4096 bytes, split over two R2Ts. The |
| pages contained stale kernel data, including an array of struct page |
| pointers. |
| |
| Reject an R2T for a request that is not a write. |
| |
| Fixes: 3f2304f8c6d6 ("nvme-tcp: add NVMe over TCP host driver") |
| Cc: stable@vger.kernel.org |
| Signed-off-by: Yehyeong Lee <yhlee@isslab.korea.ac.kr> |
| Signed-off-by: Keith Busch <kbusch@kernel.org> |
| Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org> |
| --- |
| drivers/nvme/host/tcp.c | 7 +++++++ |
| 1 file changed, 7 insertions(+) |
| |
| --- a/drivers/nvme/host/tcp.c |
| +++ b/drivers/nvme/host/tcp.c |
| @@ -677,6 +677,13 @@ static int nvme_tcp_handle_r2t(struct nv |
| } |
| req = blk_mq_rq_to_pdu(rq); |
| |
| + if (unlikely(rq_data_dir(rq) != WRITE)) { |
| + dev_err(queue->ctrl->ctrl.device, |
| + "req %d unexpected r2t for a non-write command\n", |
| + rq->tag); |
| + return -EPROTO; |
| + } |
| + |
| if (unlikely(!r2t_length)) { |
| dev_err(queue->ctrl->ctrl.device, |
| "req %d r2t len is %u, probably a bug...\n", |