7.8

CVE-2026-74470

scsi: scsi_debug: Fix REPORT ZONES alloc_len underflow OOB write

In the Linux kernel, the following vulnerability has been resolved:

scsi: scsi_debug: Fix REPORT ZONES alloc_len underflow OOB write

resp_report_zones() sizes the reply buffer from the CDB allocation
length. The v3 fix rounds alloc_len up with ALIGN() before deriving the
descriptor count:

	rep_max_zones = (ALIGN((u64)alloc_len, RZONES_DESC_HD) -
			 RZONES_DESC_HD) >> ilog2(RZONES_DESC_HD);
	arr_len = (u64)RZONES_DESC_HD * (rep_max_zones + 1);

For alloc_len in 0xFFFFFFC1..0xFFFFFFFF, ALIGN() rounds up to
0x100000000, so arr_len is 4 GB. On 32-bit, kzalloc()'s size_t is 32-bit
and truncates 0x100000000 to 0; kzalloc(0) returns ZERO_SIZE_PTR, which
passes the !arr check, and desc = arr + 64 is then dereferenced in the
loop -> out-of-bounds write / panic.

Clamp rep_max_zones to devip->nr_zones. The loop already stops at
sdebug_capacity (after nr_zones zones), so a report can never hold more
than nr_zones descriptors; the clamp does not change the report, it only
bounds arr_len to (nr_zones + 1) * RZONES_DESC_HD, a real device
property that can never reach 0x100000000.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerLinux
Produkt Linux
Default Statusunaffected
Version ebacb44cb2042b90951140eda806bedad23ef554
Version < 7b615fc139e35c81077046df44725c532f7e2404
Status affected
Version 7db0e0c8190a086ef92ce5bb960836cde49540aa
Version < 5d3e1d006bbb543259f9e31824caadbfff6a5465
Status affected
Version 7db0e0c8190a086ef92ce5bb960836cde49540aa
Version < 49e5b25a0b74dbac595f122e5608fdce2918cc4e
Status affected
Version 7db0e0c8190a086ef92ce5bb960836cde49540aa
Version < 495058429ca55ab7fcc21977b63b92907ad68066
Status affected
Version 7db0e0c8190a086ef92ce5bb960836cde49540aa
Version < 2047ed09bf13453b7d6f9431b112ec07984dd69b
Status affected
Version 7db0e0c8190a086ef92ce5bb960836cde49540aa
Version < d6e6da6bc3b53231fac77ffab428da8173ee729c
Status affected
Version 7db0e0c8190a086ef92ce5bb960836cde49540aa
Version < 93dde0bf2f39a0f9f57fd610aa3201ce5b753433
Status affected
Version c4d2d7c935a4ad20e8e726ca10499cefe4537103
Status affected
Version 5.15.8
Version < 5.15.217
Status affected
Version 5.10.85
Version < 5.11
Status affected
HerstellerLinux
Produkt Linux
Default Statusaffected
Version 5.16
Status affected
Version 0
Version < 5.16
Status unaffected
Version <= 5.15.*
Version 5.15.217
Status unaffected
Version <= 6.1.*
Version 6.1.183
Status unaffected
Version <= 6.6.*
Version 6.6.151
Status unaffected
Version <= 6.12.*
Version 6.12.103
Status unaffected
Version <= 6.18.*
Version 6.18.44
Status unaffected
Version <= 7.1.*
Version 7.1.8
Status unaffected
Version <= *
Version 7.2
Status unaffected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.13% 0.029
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
416baaa9-dc9f-4396-8d5f-8c081fb06d67 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://git.kernel.org/stable/c/49e5b25a0b74dbac595f122e5608fdce2918cc4e
https://git.kernel.org/stable/c/495058429ca55ab7fcc21977b63b92907ad68066
https://git.kernel.org/stable/c/2047ed09bf13453b7d6f9431b112ec07984dd69b
https://git.kernel.org/stable/c/d6e6da6bc3b53231fac77ffab428da8173ee729c
https://git.kernel.org/stable/c/93dde0bf2f39a0f9f57fd610aa3201ce5b753433
https://git.kernel.org/stable/c/5d3e1d006bbb543259f9e31824caadbfff6a5465
https://git.kernel.org/stable/c/7b615fc139e35c81077046df44725c532f7e2404