[PATCH] nvmet-auth: reject short AUTH_SEND buffers

Jérémy Jean Jeremy.Jean at oss.cyber.gouv.fr
Tue Aug 11 11:03:35 PDT 2026


nvmet_execute_auth_send() copies the host-supplied transfer length into a
fresh allocation, but only rejects a zero length before treating that
allocation as a DH-HMAC-CHAP message. A one-byte AUTH_SEND therefore reaches
the auth_id read past the end of the allocation before any complete message
header has been validated. KASAN reports a slab-out-of-bounds in
nvmet_execute_auth_send().

Reject payloads shorter than the smallest fixed DH-HMAC-CHAP message header
before reading any common fields.

Fixes: db1312dd9548 ("nvmet: implement basic In-Band Authentication")
Assisted-by: Codex:gpt-5
Signed-off-by: Jérémy Jean <Jeremy.Jean at oss.cyber.gouv.fr>
---
 drivers/nvme/target/fabrics-cmd-auth.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/drivers/nvme/target/fabrics-cmd-auth.c b/drivers/nvme/target/fabrics-cmd-auth.c
index 92f8a76f10ff..d12ff9cb3dad 100644
--- a/drivers/nvme/target/fabrics-cmd-auth.c
+++ b/drivers/nvme/target/fabrics-cmd-auth.c
@@ -275,7 +275,7 @@ void nvmet_execute_auth_send(struct nvmet_req *req)
 		goto done;
 	}
 	tl = nvmet_auth_send_data_len(req);
-	if (!tl) {
+	if (tl < sizeof(struct nvmf_auth_dhchap_failure_data)) {
 		status = NVME_SC_INVALID_FIELD | NVME_STATUS_DNR;
 		req->error_loc =
 			offsetof(struct nvmf_auth_send_command, tl);
-- 
2.47.3




More information about the Linux-nvme mailing list