Executive brief
The Linux kernel's SCSI Enclosure Services (SES) driver contains a buffer over-read vulnerability in enclosure data processing. An attacker with access to a malicious SCSI enclosure device could trigger a kernel memory read beyond allocated boundaries, potentially causing a denial of service or information disclosure.
Technical details
The vulnerability is a slab-out-of-bounds read in the ses_enclosure_data_process() function within drivers/scsi/ses.c. The vulnerable code fails to properly bounds-check pointer arithmetic when traversing additional descriptor pointers in enclosure status pages. Specifically, the code increments a pointer (addl_desc_ptr) based on size values from untrusted enclosure data without verifying the resulting pointer remains within the allocated page buffer. A local or adjacent attacker with access to present a malicious SCSI enclosure device can craft page10 data with specially-sized descriptors to cause the kernel to read beyond the slab allocation. The fix adds a bounds check after pointer arithmetic to ensure the pointer does not exceed the page buffer limits, setting it to NULL if it does. A patch was merged upstream in February 2023 and backported to stable kernel branches.
Affected products
- Linux Linux Kernel Multiple versions (patched in stable branches)
Timeline
- 2025-12-09: disclosed
- 2023-03-10: patched: Patches merged into stable kernel branches
- 2023-02-02: other: Fix authored by Tomas Henzl