When the controller posts command completions or sense data, firmware
provides physical DMA addresses that the driver translates into virtual
addresses within its pre-allocated reply and sense buffer pools.
Previously, these address translation helpers lacked complete validation:
- The reply buffer lookup checked only the starting physical address without verifying that the full frame size fit within the pool, and did not check whether the address aligned to the fixed reply frame stride.
- The sense buffer lookup performed no bounds checking whatsoever, blindly computing an offset from the pool base.
If firmware reported a corrupted address or an unaligned offset, the driver
computed an invalid virtual pointer, leading to memory access outside the
allocated buffer pools.
Validate that physical addresses for both reply and sense buffers fall
strictly within their respective pool bounds, ensure the complete frame size
fits within the pool, and enforce exact alignment to frame size boundaries.