ACK/Cmnt: [SRU][J][PATCH 0/1] CVE-2023-53320
Edoardo Canepa
edoardo.canepa at canonical.com
Tue Sep 22 09:07:14 UTC 2026
Acked-by: Edoardo Canepa <edoardo.canepa at canonical.com>
When I checked upstream history, the next commit to touch the function
is eeb270aee3e0, "scsi: mpi3mr: Remove unnecessary memcpy()
toĀ alltgt_info->dmi".
It is patch 2 of the same upstream series and carries the same `Fixes:`
and `Cc: stable` tags. It removes a `memcpy` whose source and
destination are the same pointer (`devmap_
info == alltgt_info->dmi`). That call is redundant, and technically
overlapping-memcpy undefined behaviour, but it causes no memory-safety
problem. Picking it up would be a reasonable addition, bu
t it isn't a security fix and doesn't block this submission.
On 9/18/26 23:46, Cengiz Can via kernel-team wrote:
> https://ubuntu.com/security/CVE-2023-53320
>
> [ Impact ]
>
> In the Linux kernel, the following vulnerability has been resolved:
>
> scsi: mpi3mr: Fix issues in mpi3mr_get_all_tgt_info()
>
> The function mpi3mr_get_all_tgt_info() has four issues:
>
> 1) It calculates valid entry length in alltgt_info assuming the header part of
> the struct mpi3mr_device_map_info would equal to sizeof(u32). The correct size
> is sizeof(u64).
>
> 2) When it calculates the valid entry length kern_entrylen, it excludes one
> entry by subtracting 1 from num_devices.
>
> 3) It copies num_device by calling memcpy(). Substitution is enough.
>
> 4) It does not specify the calculated length to sg_copy_from_buffer(). Instead,
> it specifies the payload length which is larger than the alltgt_info size. It
> causes "BUG: KASAN: slab-out-of-bounds".
>
> Fix the issues by using the correct header size, removing the subtraction from
> num_devices, replacing the memcpy() with substitution and specifying the
> correct length to sg_copy_from_buffer().
>
> [ Fix ]
>
> jammy/linux: clean cherry-pick of fb428a2005fc
>
> [ Test Plan ]
>
> Build and boot tested.
>
> [ Where Problems Could Occur ]
>
> The change is confined to the mpi3mr driver's handling of the get-all-target
> info driver command, so any regression would surface on systems using Broadcom
> MPI3-based SAS/NVMe storage controllers when userspace queries target
> information. Miscalculating the copy length could return truncated or malformed
> target data to management tools. Systems without mpi3mr hardware are not
> affected.
>
> [ Other Info ]
>
> Kybele flow-v12-15-gbd497840. Reference: c4b57794/v1
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.ubuntu.com/archives/kernel-team/attachments/20260922/0375a85e/attachment-0001.html>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: OpenPGP_signature.asc
Type: application/pgp-signature
Size: 840 bytes
Desc: OpenPGP digital signature
URL: <https://lists.ubuntu.com/archives/kernel-team/attachments/20260922/0375a85e/attachment-0001.sig>
More information about the kernel-team
mailing list