DragonFlyBSD Kernel Audit
← triage · dashboard
DF-2513

Unvalidated device-controlled shift in namespace block-size computation

Summary

nsc->blksize computed as 1<<lbafmt->sect_size where lbafmt->sect_size is device-controlled uint8_t from Identify Namespace DMA response with no range validation. For sect_size in [32 255] shift is UB (C11). For sect_size==31 yields INT_MIN becomes 2^31 in uint32. Resulting garbage blksize used as divisor and in byte-count products in nvme_disk.c enabling corrupted geometry nonsensical media sizes and integer overflow in nlba*blksize I/O sizing.

Discussion (0)

No comments yet.