Executive brief
The Linux kernel's SCSI Enclosure Services (SES) driver improperly validates pointer boundaries when processing enclosure device data, allowing memory reads or writes beyond allocated buffer boundaries. An attacker with local access to a system with vulnerable SCSI enclosure hardware could trigger a kernel crash (denial of service) or potentially execute code with kernel privileges.
Technical details
The vulnerability is an out-of-bounds memory access in the ses_enclosure_data_process() function in drivers/scsi/ses.c. The vulnerable code failed to validate that the addl_desc_ptr pointer remained within the bounds of the page10 buffer before dereferencing it in ses_process_descriptor(). The fix adds bounds checking by passing a max_desc_len parameter and validating descriptor lengths before accessing memory offsets (e.g., checking if max_desc_len <= 7, 23, or 27 bytes depending on protocol type). Exploitation requires a malformed SCSI SES response from attached hardware or network-accessible SAS/FC enclosure devices. The vulnerability affects all Linux kernel versions that include the vulnerable SES driver code prior to the fix commit db95d4df71cb55506425b6e4a5f8d68e3a765b63.
Affected products
- Linux Linux kernel prior to commit db95d4df71cb55506425b6e4a5f8d68e3a765b63
Timeline
- 2023-02-02: disclosed
- 2023-03-10: patched: fix committed upstream and backported to stable branches