|
Daniel Wagner |
9e47e9 |
From: James Smart <jsmart2021@gmail.com>
|
|
Daniel Wagner |
9e47e9 |
Date: Wed, 7 Jul 2021 11:43:42 -0700
|
|
Daniel Wagner |
9e47e9 |
Subject: scsi: lpfc: Fix KASAN slab-out-of-bounds in lpfc_unreg_rpi() routine
|
|
Takashi Iwai |
0a347d |
Patch-mainline: v5.15-rc1
|
|
Daniel Wagner |
9e47e9 |
Git-commit: affbe24429410fddf4e50ca456c090ed6d8e05bf
|
|
Daniel Wagner |
9e47e9 |
References: bsc#1189385
|
|
Daniel Wagner |
9e47e9 |
|
|
Daniel Wagner |
9e47e9 |
In lpfc_offline_prep() an RPI is freed and nlp_rpi set to 0xFFFF before
|
|
Daniel Wagner |
9e47e9 |
calling lpfc_unreg_rpi(). Unfortunately, lpfc_unreg_rpi() uses nlp_rpi to
|
|
Daniel Wagner |
9e47e9 |
index the sli4_hba.rpi_ids[] array.
|
|
Daniel Wagner |
9e47e9 |
|
|
Daniel Wagner |
9e47e9 |
In lpfc_offline_prep(), unreg rpi before freeing the rpi.
|
|
Daniel Wagner |
9e47e9 |
|
|
Daniel Wagner |
9e47e9 |
Link: https://lore.kernel.org/r/20210707184351.67872-12-jsmart2021@gmail.com
|
|
Daniel Wagner |
9e47e9 |
Co-developed-by: Justin Tee <justin.tee@broadcom.com>
|
|
Daniel Wagner |
9e47e9 |
Signed-off-by: Justin Tee <justin.tee@broadcom.com>
|
|
Daniel Wagner |
9e47e9 |
Signed-off-by: James Smart <jsmart2021@gmail.com>
|
|
Daniel Wagner |
9e47e9 |
Signed-off-by: Martin K. Petersen <martin.petersen@oracle.com>
|
|
Daniel Wagner |
9e47e9 |
Acked-by: Daniel Wagner <dwagner@suse.de>
|
|
Daniel Wagner |
9e47e9 |
---
|
|
Daniel Wagner |
9e47e9 |
drivers/scsi/lpfc/lpfc_init.c | 3 ++-
|
|
Daniel Wagner |
9e47e9 |
1 file changed, 2 insertions(+), 1 deletion(-)
|
|
Daniel Wagner |
9e47e9 |
|
|
Daniel Wagner |
9e47e9 |
--- a/drivers/scsi/lpfc/lpfc_init.c
|
|
Daniel Wagner |
9e47e9 |
+++ b/drivers/scsi/lpfc/lpfc_init.c
|
|
Daniel Wagner |
9e47e9 |
@@ -3541,6 +3541,8 @@ lpfc_offline_prep(struct lpfc_hba *phba,
|
|
Daniel Wagner |
9e47e9 |
spin_lock_irq(&ndlp->lock);
|
|
Daniel Wagner |
9e47e9 |
ndlp->nlp_flag &= ~NLP_NPR_ADISC;
|
|
Daniel Wagner |
9e47e9 |
spin_unlock_irq(&ndlp->lock);
|
|
Daniel Wagner |
9e47e9 |
+
|
|
Daniel Wagner |
9e47e9 |
+ lpfc_unreg_rpi(vports[i], ndlp);
|
|
Daniel Wagner |
9e47e9 |
/*
|
|
Daniel Wagner |
9e47e9 |
* Whenever an SLI4 port goes offline, free the
|
|
Daniel Wagner |
9e47e9 |
* RPI. Get a new RPI when the adapter port
|
|
Daniel Wagner |
9e47e9 |
@@ -3556,7 +3558,6 @@ lpfc_offline_prep(struct lpfc_hba *phba,
|
|
Daniel Wagner |
9e47e9 |
lpfc_sli4_free_rpi(phba, ndlp->nlp_rpi);
|
|
Daniel Wagner |
9e47e9 |
ndlp->nlp_rpi = LPFC_RPI_ALLOC_ERROR;
|
|
Daniel Wagner |
9e47e9 |
}
|
|
Daniel Wagner |
9e47e9 |
- lpfc_unreg_rpi(vports[i], ndlp);
|
|
Daniel Wagner |
9e47e9 |
|
|
Daniel Wagner |
9e47e9 |
if (ndlp->nlp_type & NLP_FABRIC) {
|
|
Daniel Wagner |
9e47e9 |
lpfc_disc_state_machine(vports[i], ndlp,
|