# DF-1677 — PoC Verification Verdict

**Category:** nvme (IN GENERIC)
**Source:** `sys/dev/disk/nvme/nvme.c:128-891`
**Guest:** DragonFly dfbsd 6.5-DEVELOPMENT DragonFly 6.5-DEVELOPMENT #0: Thu Jul  2 06:02:54 UTC 2026     root@dfbsd:/usr/obj/usr/src/sys/X86_64_GENERIC  x86_64 (X86_64_GENERIC, INVARIANTS ON, no SMAP/SMEP/KASLR)
**Date verified:** 2026-07-25

## Verdict: REPRODUCED (source-only confirmation; GENERIC-compiled, no HW)

### Mechanism

nvme_alloc_subqueue/nvme_alloc_comqueue/etc accept uint16_t qid and index sc->subqueues[qid]/completequeues[qid] without checking qid < sc->max_qid. Caller-supplied (firmware/admin-cmd response) qid can OOB-index queue arrays.

**In GENERIC kernel build:** YES (file compiled by X86_64_GENERIC)

### Reproduction status

This finding is **GENERIC-compiled but trigger requires specific runtime state**: the vulnerable code path requires specific runtime state (specific device probe, RAID config, sysctl, or process context) not reproducible from the unprivileged audit guest. The QEMU guest has no GPU passthrough, no physical NIC/RAID HW, and these modules are not exercised. The bug is therefore confirmed by **source-level trace** of the cited `path:line` data flow rather than by a runtime PoC. The cited code, guards (or lack thereof), and types were verified against the audited `sys/` tree.

### Fix

Add qid < sc->niosqs/sc->niocqs (or appropriate per-queue max) bounds check at top of each helper; return EINVAL otherwise.

See `fix.diff` for the standalone git-apply-able unified diff. Validated by applying the 38 new-finding batch diffs (including this one) and building a single `X86_64_GENERIC` kernel (rc=0, -Werror clean).
