β¬’ DragonFlyBSD Kernel Audit
← triage Β· dashboard
DF-1921

Early-return error paths leak mfi cmds and DMA resources: cmd-pool exhaustion DoS

Summary

L193 cmd=mrsas_get_mfi_cmd removes from free list (32 total MRSAS_MAX_MFI_CMDS). Error branches L237/243/250 (tag_create/dmamem_alloc/dmamap_load failures) and sense L278/283/289 return(ENOMEM) directly bypassing out: label which releases cmd at L367. Each leak permanently removes one cmd from pool. After 32 calls mrsas_get_mfi_cmd returns NULL forever controller unusable for both ioctl and I/O. Also leaks DMA memory. Trigger: iov_len=0x80000000 high-bit set (int)-2GB bus_dma_tag_create fails. 32x ioctl -> controller dead. Operator-group. Fix: replace return(ENOMEM) with ret=ENOMEM;goto out at all 6 sites.

Discussion (0)

No comments yet.

PoC verification

Evidence pack

findings/poc/DF-1921 Β· 2 files
FileTypeDescriptionSize
fix.diff suggested-fix git-apply-able unified diff; validated as part of combined 41-finding kernel build (rc=0, -Werror clean) 2.1 KB view raw
VERDICT.md verdict source-only confirmation + HW/module gating explanation 1.5 KB ↓ raw
VERDICT.md verdict source-only confirmation + HW/module gating explanation
↓ download raw

DF-1921 Verification

Verdict

SOURCE-CONFIRMED, INCONCLUSIVE-RUNTIME (HW/module gated).

The cited defect exists in the audited source at sys/dev/raid/mrsas/mrsas_ioctl.c:193-250. Reproduction on the running guest is not possible because the affected code path is gated behind hardware that is not present in the audit QEMU/KVM guest (no AMD/i915 GPU, no LSI MegaRAID, no MMC/SDHCI controller, no FireWire, no ATAPI floppy, etc.) and/or lives in a kernel module that is not loaded on the GENERIC-running guest.

Mechanism (source-only confirmation)

mrsas IS in GENERIC but no HW. Source: L193 cmd=mrsas_get_mfi_cmd removes from free list (32 total). Error branches L237/243/250 (tag_create/dmamem_alloc/dmamap_load) and sense L278/283/289 return(ENOMEM) directly, bypassing the out: label which releases cmd at L367 (mrsas_release_mfi_cmd). Repeated failures exhaust the 32-cmd pool β†’ DoS.

Replace the early return (ENOMEM) with goto out so cmd is released via the existing cleanup.

The full git apply-able diff lives in fix.diff in this folder; it was applied as part of a single combined 41-finding kernel build that compiled cleanly (rc=0, -Werror clean) β€” see ../fix_build_summary.txt.

Build validation

  • git apply --check on this fix.diff: OK
  • Combined kernel build (X86_64_GENERIC, INVARIANTS ON) with all 41 findings' fix.diffs applied: rc=0, no warnings, no errors.
  • The patched kernel was not booted/run because the affected code path requires hardware that the audit guest does not have.

Confirmed kernel references

Detail

Exploit chain

none β€” non-corruption classes (info leak / DoS / div0 / logic) or HW/module gated. No memory-corruption primitive reachable from userspace on this guest.

Evidence (decisive lines)

Source-only confirmation. Combined kernel build with all 41 fix.diffs applied: === NK_DONE rc=0 === at Wed Jul 22 18:05:21 UTC 2026 (no errors, no warnings). See findings/poc/fix_build_summary.txt.

PoC changes

Authored findings/poc/DF-1921/fix.diff (minimal targeted guard). VERDICT.md and manifest.json written. fix.diff validated by combined build.

Verified recommended fix

Replace the early return (ENOMEM) with goto out so cmd is released via the existing cleanup. Full git-apply-able diff in findings/poc/DF-1921/fix.diff; validated as part of combined 41-finding kernel build (rc=0).

Verdict

SOURCE-CONFIRMED, INCONCLUSIVE-RUNTIME. The cited defect exists at sys/dev/raid/mrsas/mrsas_ioctl.c:193-250. mrsas IS in GENERIC but no HW. L193 cmd=mrsas_get_mfi_cmd removes from free list (32 total). Error branches L237/243/250 and sense L278/283/289 return(ENOMEM) directly, bypassing out: label which releases cmd at L367. Repeated failures exhaust the 32-cmd pool -> DoS. HW gated.