Prior report for the nvmet-tcp unbounded SGL length fix in 7.3
Shivam Kumar
kumar.shivam43666 at gmail.com
Mon Aug 24 08:50:56 PDT 2026
On Mon, Aug 24, 2026 at 11:42 AM Shivam Kumar
<kumar.shivam43666 at gmail.com> wrote:
>
> Hi all,
>
> I originally reported this issue to security at kernel.org on 2026-03-17
> (Cc Sagi), Message-ID:
> <CA+ysrSJUFi8cHzU8g9Nrbbkcuo0F7vh8CMn3ht15gSk3BbK45A at mail.gmail.com>
> and posted the first patch for it in this thread,
> "[PATCH] nvmet-tcp: bound sgl->length check in nvmet_tcp_map_data()"
> (2026-03-19).
>
> Commit 4a3f002 ("nvmet-tcp: bound SGL data length before allocating
> command buffers"), merged for 7.3, adds the same NVMET_TCP_MAXH2CDATA
> bound with the same status code.
>
> These things happen independently, and I'm glad the issue is fixed.
> Would it be possible to get some acknowledgement for the original
> report?
>
> Thanks,
> Shivam
Adding Maurizio and Christoph, who reviewed the original patch.
To be clear, "this thread" above refers to the March thread, not this
one, I meant to send this as a reply there. Link for reference:
https://lore.kernel.org/all/CA+ysrS+fsJQ+4x7jHoSEX_tiYRQJC8LEhuH2stKA6Q4qSK-MWA@mail.gmail.com/
More information about the Linux-nvme
mailing list