Skip to content

Unquoted caller path into system() in wdc, sandisk, and solidigm plugins is root command injection #4092

Description

@keithbusch

Call sites across the nvme-cli vendor plugins interpolate a caller-supplied path into a shell command string with no quoting and pass it to system(3). nvme-cli runs as root, so any principal that can invoke an affected subcommand with controlled arguments gets arbitrary command execution as root.

Proof of concept (not actually run):

nvme wdc vs-internal-log /dev/nvme0n1 -s 0x10000 -o '/tmp/a;chmod u+s $(command -v bash);#'

cmd_buf becomes:

tar --remove-files -czf /tmp/a;chmod u+s $(command -v bash);#.tar.gz /tmp/a;chmod u+s $(command -v bash);#

which /bin/sh splits into tar --remove-files -czf /tmp/a, then chmod u+s $(command -v bash) as root, then a comment. Result: setuid-root bash.

Don't do this. If you want to run a shell command sequence, then write a script to do it and let nvme-cli just do nvme stuff.

Activity

  1. changed the title [-]Unquoted caller path into system() in wdc and solidigm plugins is root command injection[/-] [+]Unquoted caller path into system() in wdc, sandisk, and solidigm plugins is root command injection[/+] on Sep 30, 2026
  2. itsmeut01 commented on Oct 1, 2026

    @itsmeut01
    Contributor

    The Solidigm side was fixed in 6d75ddc1f - system() replaced with posix_spawnp(). The same unquoted-into-system() pattern remains in WDC (wdc-nvme.c:4493, :4152, :10407) and Sandisk (sandisk-nvme.c:222).

  3. igaw commented on Oct 1, 2026

    @igaw
    Collaborator

    Still, this is a very bad design and it needs to be replaced, e.g. by using libarchive.

    I'll will rip out this code within a week if it is not fixed. I had a bad feeling when I accepted it. This was a mistake. This is a complete anti pattern and not acceptable at all.

    @h1219-kim @jeff-lien-sndk @lgdacunh

  4. jeff-lien-sndk commented on Oct 1, 2026

    @jeff-lien-sndk
    Contributor

    @igaw, @brandon-paupore-sndk is looking into fixes for the wdc and sndk plugins.

  5. lgdacunh commented on Oct 1, 2026

    @lgdacunh
    Contributor

    @igaw, @keithbusch, I am on the solidigm telemetry instance of this issue. Are you aware of other instances of this issue in the solidigm plugin?

  6. lgdacunh commented on Oct 2, 2026

    @lgdacunh
    Contributor
  7. h1219-kim commented on Oct 7, 2026

    @h1219-kim
    Contributor

    Sorry for the late response, and thanks for looking into this. I've caught up on the discussion and the changes in #4114 .

    Still, this is a very bad design and it needs to be replaced, e.g. by using libarchive.

    I'll will rip out this code within a week if it is not fixed. I had a bad feeling when I accepted it. This was a mistake. This is a complete anti pattern and not acceptable at all.

    @h1219-kim @jeff-lien-sndk @lgdacunh

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions