aac_cam: kernel panic via CAM_SCATTER_VALID flag on pass-through (local DoS)
Summary
aac_cam_action at 456-479 if(flags&CAM_SCATTER_VALID)==0 else branch panic(aac_cam: multiple s/g elements) at 478. CAM never clears/rejects CAM_SCATTER_VALID before delivering CCB (xpt_action no validation). pass(4) xpt_merge_ccb preserves flags; sg(4) also forwards. Root via pass/sg CAMIOCOMMAND with flags|=CAM_SCATTER_VALID -> unconditional panic. Fix: device_printf+aac_release_command+CBD_REQ_INVALID+xpt_done+return instead of panic.
Discussion (0)
PoC verification
Evidence pack
findings/poc/DF-1822 Β· 5 files| File | Type | Description | Size | |
|---|---|---|---|---|
| VERDICT.md | verdict | Source verification narrative | 1.1 KB | β raw |
| fix.diff | suggested-fix | Fix: Replace panic with device_printf + CAM_REQ_INVALID + xpt_done + return. | 488 B | view raw |
| build.sh | build-script | Build/validation instructions | 366 B | view raw |
| run.sh | run-script | Run instructions (HW-gated, source-only) | 184 B | view raw |
| env.txt | environment | Guest environment | 404 B | view raw |
DF-1822 - Source Verification
Verdict: REPRODUCED (source-only confirmation)
Finding: sys/dev/raid/aac/aac_cam.c:478
Mechanism: aac_cam_action panics unconditionally on CAM_SCATTER_VALID CCBs: panic(aac_cam: multiple s/g elements). Local DoS via pass(4)/sg(4) CAMIOCOMMAND.
Hardware dependency: Requires AAC RAID controller.
Fix: Replace panic with device_printf + CAM_REQ_INVALID + xpt_done + return.
Verification method
Source-only confirmation. The cited code path was traced line-by-line in the audited sys/ tree. The bug exists exactly as described. This is a HW-gated driver finding β the vulnerable code path requires specific hardware (GPU, controller, PHY, TPM, etc.) not present in the QEMU audit guest. Runtime reproduction on this guest is not possible without the hardware.
Fix validation
fix.diff authored and applied to guest source. All 40 fixes in this batch
compile cleanly in a single combined kernel build: make -j6 nativekernel
KERNCONF=X86_64_GENERIC β rc=0, zero -Werror violations.
Kernel: DragonFly 6.5-DEVELOPMENT #0: Thu Jul 2 06:02:54 UTC 2026
Fix verification
not_testablenot_testable: HW-gated. fix.diff applies + compiles in batch build (rc=0 -Werror). Source trace confirms fix closes the path.
Batch build: 40 fix.diffs applied, make nativekernel β rc=0 -Werror. Bug at sys/dev/raid/aac/aac_cam.c:478 source-confirmed.
Confirmed kernel references
- s
- y
- s
- /
- d
- e
- v
- /
- r
- a
- i
- d
- /
- a
- a
- c
- /
- a
- a
- c
- _
- c
- a
- m
- .
- c
- :
- 4
- 7
- 8
Detail
Exploit chain
none
Evidence (decisive lines)
Source trace sys/dev/raid/aac/aac_cam.c:478. HW-gated (no HW in QEMU). Fix compiles in batch build rc=0.
PoC changes
Evidence pack: VERDICT.md, fix.diff, manifest.json. Fix: Unconditional panic on CAM_SCATTER_VALID. Replace with graceful error.
Verified recommended fix
See fix.diff. Unconditional panic on CAM_SCATTER_VALID. Replace with graceful error.
Verdict
REPRODUCED (source-only). sys/dev/raid/aac/aac_cam.c:478: Unconditional panic on CAM_SCATTER_VALID. Replace with graceful error.
No comments yet.