From: Stephen Hemminger <stephen@networkplumber.org>
To: dev@dpdk.org
Cc: Kiran Kumar K <kirankumark@marvell.com>,
Stephen Hemminger <stephen@networkplumber.org>,
stable@dpdk.org, Aman Singh <aman.deep.singh@intel.com>,
Gregory Etelson <getelson@nvidia.com>,
Viacheslav Ovsiienko <viacheslavo@nvidia.com>
Subject: [PATCH 2/3] app/testpmd: fix flex item allocation overlap
Date: Mon, 7 Sep 2026 11:22:03 -0700 [thread overview]
Message-ID: <20260907182317.570481-3-stephen@networkplumber.org> (raw)
In-Reply-To: <20260907182317.570481-1-stephen@networkplumber.org>
flex_item_init() allocates struct flex_item together with the arrays it
points at, and places the first of them at base_size from the start of
the allocation. base_size is the size of the embedded flex_conf rather
than the size of the whole struct, so sample_data starts inside struct
flex_item itself. On x86-64 flex_conf is 112 bytes and struct flex_item
is 128, so sample_data[0] aliases flex_handle and flex_id.
Nothing reads flex_id and flex_handle is assigned after the config has
been consumed, so this is currently harmless, but any new member added
to the struct would be silently overwritten during parsing.
Fixes: 59f3a8acbcdb ("app/testpmd: add flex item commands")
Cc: stable@dpdk.org
Signed-off-by: Stephen Hemminger <stephen@networkplumber.org>
---
app/test-pmd/cmd_flex_item.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/app/test-pmd/cmd_flex_item.c b/app/test-pmd/cmd_flex_item.c
index e62afe3cb5..f4560d2cec 100644
--- a/app/test-pmd/cmd_flex_item.c
+++ b/app/test-pmd/cmd_flex_item.c
@@ -305,7 +305,7 @@ flex_item_init(void)
uint8_t (*pattern)[FLEX_MAX_FLOW_PATTERN_LENGTH];
int i;
- base_size = RTE_ALIGN(sizeof(*conf), sizeof(uintptr_t));
+ base_size = RTE_ALIGN(sizeof(*fp), sizeof(uintptr_t));
samples_size = RTE_ALIGN(FLEX_ITEM_MAX_SAMPLES_NUM *
sizeof(conf->sample_data[0]),
sizeof(uintptr_t));
--
2.53.0
next prev parent reply other threads:[~2026-09-07 18:26 UTC|newest]
Thread overview: 4+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-07 18:22 [PATCH 0/3] app/testpmd: fix more overflow issues Stephen Hemminger
2026-09-07 18:22 ` [PATCH 1/3] app/testpmd: fix stack overflow parsing flex item link Stephen Hemminger
2026-09-07 18:22 ` Stephen Hemminger [this message]
2026-09-07 18:22 ` [PATCH 3/3] app/testpmd: fix null dereference " Stephen Hemminger
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260907182317.570481-3-stephen@networkplumber.org \
--to=stephen@networkplumber.org \
--cc=aman.deep.singh@intel.com \
--cc=dev@dpdk.org \
--cc=getelson@nvidia.com \
--cc=kirankumark@marvell.com \
--cc=stable@dpdk.org \
--cc=viacheslavo@nvidia.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.