β¬’ DragonFlyBSD Kernel Audit
← triage Β· dashboard
DF-2514

Divide-by-zero kernel panic in XPT_CALC_GEOMETRY from block_size > 1MB

Summary

SBP driver has stale inline copy of disk geometry calculation that divides volume_size by (1048576/block_size) without checking whether inner division yields zero. When block_size exceeds 1048576 inner division evaluates to 0 outer division volume_size/0 triggers #DE fault panicking kernel. Only guard checks block_size==0 missing >1MB case. Canonical cam_calc_geometry was already fixed but this drivers copy predates fix. block_size from device READ CAPACITY response fully controlled by attached FireWire SBP-2 device. Two vectors: malicious FW device at plug-in or local user via /dev/pass with XPT_CALC_GEOMETRY CCB.

Discussion (0)

No comments yet.

PoC verification

Evidence pack

findings/poc/DF-2514 Β· 6 files
FileTypeDescriptionSize
VERDICT.md verdict Source trace confirming DF-2514 bug is real but HW-gated 1.3 KB ↓ raw
fix.diff suggested-fix Extend block_size guard to also reject > (1024L*1024L) 459 B view raw
env.txt environment Guest gate proof: kldstat, pciconf, camcontrol (no target HBA) 1.1 KB view raw
build.sh build-script No buildable PoC (HW-gated) 384 B view raw
run.sh run-script Gate verification commands 411 B view raw
README.md readme Overview of HW-gated finding 791 B ↓ raw
README.md readme Overview of HW-gated finding
↓ download raw

HW-gated SCSI/FC HBA driver finding

This finding targets a SCSI/FC/SATA HBA driver that is not present in this QEMU/KVM guest (only PIIX3 IDE + virtio). The driver cannot attach and the cited code path is unreachable at runtime.

Reproduction status: NOT REPRODUCED (HW-gated)

  • The source bug is confirmed real by line-by-line source trace (see VERDICT.md).
  • It cannot be triggered because the HBA hardware/driver does not exist on this guest.
  • A defense-in-depth fix.diff has been authored and validated with git apply --check.

Evidence

  • VERDICT.md β€” full source trace and analysis
  • env.txt β€” guest environment (kldstat, pciconf, camcontrol gate proof)
  • fix.diff β€” git-apply-able defense-in-depth fix
  • manifest.json β€” machine-readable catalog
VERDICT.md verdict Source trace confirming DF-2514 bug is real but HW-gated
↓ download raw

DF-2514 β€” Divide-by-zero in XPT_CALC_GEOMETRY

Verdict: NOT REPRODUCED (HW-gated) β€” source bug CONFIRMED

Hardware gate

No FireWire (SBP-2) controller in guest: kldstat shows only kernel/ehci/xhci; pciconf -l shows no FireWire controller. The sbp driver does not attach.

Source trace (confirmed real bug)

File: sys/dev/disk/sbp/sbp.c:2385-2386

if (ccg->block_size == 0) {              // line 2370: only checks ==0
    ...
}
size_mb = ccg->volume_size
    / ((1024L * 1024L) / ccg->block_size);  // line 2385-2386: inner div β†’ 0 if block_size > 1MB

The guard checks block_size == 0 but not block_size > (1024*1024). When block_size > 1048576, the inner division (1024*1024)/block_size evaluates to 0 (integer truncation), and the outer division volume_size / 0 triggers #DE and panics. The canonical cam_calc_geometry was already fixed; this driver's stale inline copy predates that fix. block_size comes from device READ CAPACITY response, fully controlled by an attached FireWire SBP-2 device.

Fix

Changed if (ccg->block_size == 0) to if (ccg->block_size == 0 || ccg->block_size > (1024L * 1024L)). See fix.diff.

Impact (on HW that has the controller)

Medium β€” kernel panic from malicious FireWire SBP-2 device or local user via /dev/pass XPT_CALC_GEOMETRY CCB with block_size > 1MB.

Fix verification

not_testable
baseline no→ patch + rebuild →patched clean

not_testable: target driver cannot attach (no target HBA). fix.diff validated with git apply --check (EXIT=0); fix is correct by source trace.

git apply --check findings/poc/DF-2514/fix.diff => EXIT=0. No runtime test possible (no target HBA).
↓ fix.diffDragonFly 6.5-DEVELOPMENT #0 (unpatched with-src baseline β€” target driver not loadable on this guest)

Confirmed kernel references

Detail

Exploit chain

none β€” valid hard blocker (driver code path dead at runtime on this guest: no target HBA). No unprivileged->root path.

Evidence (decisive lines)

kldstat -> kernel/ehci/xhci only (no target driver); pciconf -l -> PIIX3 IDE + virtio only (no target HBA); camcontrol devlist -> only <QEMU QEMU DVD-ROM>. Source confirmed at cited lines.

PoC changes

Created findings/poc/DF-2514/{VERDICT.md,fix.diff,manifest.json,env.txt,build.sh,run.sh,README.md}. No PoC source (HW-gated).

Verified recommended fix

Defense-in-depth fix.diff closes the cited path (see findings/poc/DF-2514/fix.diff; git apply --check OK).

Verdict

NOT REPRODUCED (HW-gated). The bug is REAL in source (traced line-by-line): sbp divide-by-zero in XPT_CALC_GEOMETRY (needs FireWire SBP-2 device). Gate confirmed: kldstat (only kernel+ehci+xhci; no isp/mpt/sili/trm/sbp module loaded), pciconf -l (no QLogic ISP/LSI MPT/SiliconImage/Tekram/FireWire HBA β€” only PIIX3 IDE atapci0 + virtio), camcontrol devlist (only QEMU DVD-ROM). The target driver cannot attach so the cited code path is dead at runtime on this guest.