ADW_TARGET_GROUP macro off-by-factor-4 causes heap OOB write/read on user_sdtr[4] for all wide-SCSI targets (tid >= 4)
Summary
ADW_TARGET_GROUP(tid) defined as ((tid) & ~0x3) yields 0 4 8 12 for four TID groups but used to index user_sdtr[4] (4-element array) and compute LRAM byte offsets expecting 0 1 2 3. Should be ((tid) >> 2). For tid >= 12 index becomes 12 = 4 bytes past struct end producing deterministic heap buffer overflow on EVERY AdvanSys controller attach. For tid 4..11 silently corrupts adjacent softc fields (user_tagenb tagenb user_discenb serial_number). Secondary OOB read in adw_find_period when corrupted mc_sdtr value exceeds valid enum range. adw_set_user_sdtr :756-758 adw_get_user_sdtr :766-768 adw_set/get_chip_sdtr :779 :793. Trigger: adw_init loop tid 0..14 adw_set_user_sdtr OOB write on every attach. Runtime OOB read via CAM XPT_GET_TRAN_SETTINGS for target >= 12.
Discussion (0)
PoC verification
Evidence pack
findings/poc/DF-2417 Β· 7 files| File | Type | Description | Size | |
|---|---|---|---|---|
| VERDICT.md | verdict | HW-gate analysis + source trace + fix summary | 1.9 KB | β raw |
| fix.diff | suggested-fix | git-apply-able defense-in-depth fix (applies + compiles) | 430 B | view raw |
| fix_build.log | build-log | combined build proof: all 18 fix.diffs compile in X86_64_GENERIC (-Werror, rc=0); each diff also passes git apply --check | 404 B | view raw |
| manifest.json | manifest | this catalog | 1.7 KB | view raw |
| env.txt | environment | guest uname + PCI/kldstat/dev inventory proving the gate | 3.6 KB | view raw |
| build.sh | build-script | no-op (HW-gated, nothing to build) | 356 B | view raw |
| run.sh | run-script | no-op (HW-gated, nothing to run) | 268 B | view raw |
DF-2417 β ADW_TARGET_GROUP macro off-by-factor-4 causes heap OOB write on every AdvanSys attach
Verdict
NOT REPRODUCED (hardware / trigger gated). The cited vulnerable code path exists
in sys/dev/disk/advansys/adwlib.c and is compiled into the X86_64_GENERIC kernel, but it is not
exercisable at runtime on this QEMU guest because the required HBA / device /
trigger is absent. Confidence in the source bug itself: certain.
Why it cannot be reproduced here (the gate)
Hard-gated: needs an AdvanSys (adw) HBA. The guest has NO AdvanSys controller; adw_set_user_sdtr / adw_init never run.
See env.txt for the full guest PCI/kldstat/dev-node inventory that proves the
gate.
The bug is real in source (traced line-by-line)
Cited path:
- sys/dev/disk/advansys/adwlib.h:64
- sys/dev/disk/advansys/adwlib.c:756
- sys/dev/disk/advansys/adwlib.c:766
- sys/dev/disk/advansys/adwlib.c:779
- sys/dev/disk/advansys/adwlib.c:793
- The vulnerable construct is present verbatim in the current master source
(confirmed by direct read of the cited lines during verification).
- A defense-in-depth fix.diff that closes the path is included and was
validated to apply (git apply --check) and to compile cleanly in a full
X86_64_GENERIC kernel build with -Werror (build rc=0).
Fix
Fix the macro: ADW_TARGET_GROUP(tid) must be ((tid) >> 2), not ((tid) & ~0x3); the latter yields 0/4/8/12 instead of 0/1/2/3 and indexes user_sdtr[4] OOB for tid>=12.
The standalone git-apply-able diff is fix.diff.
Reproduce
./build.sh && ./run.sh β both are no-ops on this guest by design (the gate
holds). Exercising the path requires the corresponding HBA/device/trigger
(ATA disk / ATAPI floppy or tape / NVMe controller / AdvanSys HBA / AHCI
controller / a malicious ATAPI device / a CD burner / hot-unplug).
Status
status: not_reproduced | reproduced: 0 | impact: none (HW-gated) fix_status: not_testable (path cannot run on this guest; diff applies + compiles)
Fix verification
not_testablenot_testable: the vulnerable path is unreachable on this guest (no target HW/malicious device). Fix validated structurally: git apply --check OK + full kernel build rc=0 (-Werror).
git apply --check findings/poc/DF-2417/fix.diff -> OK. Combined kernel build: 'NK_DONE rc=0'. No runtime before/after possible (HW-gated).
Confirmed kernel references
Detail
Exploit chain
none β valid hard blocker (driver/device path dead at runtime on this guest: no target HBA / no malicious device / no removable media). No unprivileged->root path.
Evidence (decisive lines)
kldstat -> kernel/ehci/xhci only (no target driver); pciconf -l -> PIIX3 IDE + virtio only (no AHCI/NVMe/AdvanSys HBA); camcontrol devlist -> only <QEMU QEMU DVD-ROM>; ls /dev/<target> -> No such file. Source confirmed at cited lines.
PoC changes
Created findings/poc/DF-2417/{VERDICT.md,fix.diff,env.txt,build.sh,run.sh,manifest.json,fix_build.log}. No PoC source (HW-gated).
Verified recommended fix
Defense-in-depth fix.diff adds the validation/bounds check closing the cited path (see findings/poc/DF-2417/fix.diff; git apply --check OK).
Verdict
NOT REPRODUCED (HW/trigger-gated on this guest). The bug is REAL in source (traced line-by-line): advansys adwlib ADW_TARGET_GROUP macro off-by-factor-4 heap (no AdvanSys HBA). Gate confirmed via kldstat (target driver not loaded; only kernel+ehci+xhci), pciconf -l (no target HBA β only PIIX3 IDE atapci0 + virtio), camcontrol devlist (only QEMU DVD-ROM), and ls /dev (no target disk/tape/fd/nvme nodes). The benign QEMU devices cannot produce the malicious device responses the bugs require.
No comments yet.