DF-2513
Unvalidated device-controlled shift in namespace block-size computation
Summary
nsc->blksize computed as 1<<lbafmt->sect_size where lbafmt->sect_size is device-controlled uint8_t from Identify Namespace DMA response with no range validation. For sect_size in [32 255] shift is UB (C11). For sect_size==31 yields INT_MIN becomes 2^31 in uint32. Resulting garbage blksize used as divisor and in byte-count products in nvme_disk.c enabling corrupted geometry nonsensical media sizes and integer overflow in nlba*blksize I/O sizing.
No comments yet.