From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id ED5ED519912; Wed, 30 Sep 2026 17:15:23 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790788525; cv=none; b=sGaXObFQT2Lh37YfLf3j6OukhBMt/rX1VUayJXiU6pT5vhpC66pbWlRV9TCVDRI0Zm19B2YdYM2pyuY3vKu/I2VvnsgZkGeQAJJ1xSN0rTIIxxX3Q+swBeS8jQLQNxv/YahObcWA47UwosU2l4q/EabqPffZM0/m9HVWvtnN6YY= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790788525; c=relaxed/simple; bh=hNKaezMaljJ3WTROXEtqY0CPdsvBLppkzSetSeIPO5g=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version:Content-Type; b=mbjPV51D6qKedqsMwq+vop8qpU/oiTd3dkG9b46EoBIfWeHEN53IGs4L2cjeP2xHhfuE+ccuLQy2+cqodKBQvmOHrV+B56PiGXI83y3EF1FrrC33wUmPjzQ8y67xytLTkwzA0JDeurKIr4qNwdBAo9N3DPop1S8hM5MIpN9292o= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=JcLHDz7q; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="JcLHDz7q" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 5062E1F000FF; Wed, 30 Sep 2026 17:15:23 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxfoundation.org; s=korg; t=1790788523; bh=W7gulRopiX/RNmMx5Ghn0jhp8uJE98G7tBnaGYrsGMg=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=JcLHDz7qBLgHZMWmBXD09/svscR2I+rf7uuI1dBNHWzqazHB9RNMznqEaWnKPev6u yfYrwZN8TUiYabeZlHYoPCSk1+M+Uc/LDBuP5zqWwYOtaYkM3U+TyMKZW29qmAQDym JnptE4undnhU+5XNUAuX2LSb3F7iMYWre7ZV9Z3s= From: Greg Kroah-Hartman To: stable@vger.kernel.org Cc: Greg Kroah-Hartman , patches@lists.linux.dev, Dmitriy Okunev , Paolo Abeni , Sasha Levin Subject: [PATCH 6.12 153/877] net: mvpp2: prevent buffer overflow in page_pool allocation Date: Wed, 30 Sep 2026 17:17:44 +0200 Message-ID: <20260930152418.023682506@linuxfoundation.org> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260930152414.738996857@linuxfoundation.org> References: <20260930152414.738996857@linuxfoundation.org> User-Agent: quilt/0.69 X-stable: review X-Patchwork-Hint: ignore Precedence: bulk X-Mailing-List: patches@lists.linux.dev List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit 6.12-stable review patch. If anyone has any objections, please let me know. ------------------ From: Dmitriy Okunev [ Upstream commit 14cb1e7702e5cb3c58888f6aed498381a73927d2 ] The per‑processor buffering scheme is supported only if the number of pools (nrxqs * 2) does not exceed MVPP2_BM_MAX_POOLS (8). This is already checked in mvpp2_probe() during the initial activation of percpu_pools. However, mvpp2_change_mtu() may later call mvpp2_bm_switch_buffers(priv, true) without this check, which can lead to an out-of-bounds access in the priv->page_pool array in mvpp2_bm_init(). The array is sized to hold MVPP2_PORT_MAX_RXQ entries, and mvpp2_get_nrxqs() may return exactly that value. The per-CPU scheme then doubles it to nrxqs * 2, exceeding the array bounds. Check that the hardware version is MVPP22 or newer and that the number of pools (nrxqs * 2) does not exceed MVPP2_BM_MAX_POOLS before switching to per-CPU mode. Found by Linux Verification Center (linuxtesting.org) with SVACE. Fixes: 7d04b0b13b11 ("mvpp2: percpu buffers") Signed-off-by: Dmitriy Okunev Link: https://patch.msgid.link/20260914091557.71769-1-dokunevdmitriy@gmail.com Signed-off-by: Paolo Abeni Signed-off-by: Sasha Levin --- drivers/net/ethernet/marvell/mvpp2/mvpp2_main.c | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/drivers/net/ethernet/marvell/mvpp2/mvpp2_main.c b/drivers/net/ethernet/marvell/mvpp2/mvpp2_main.c index 325a3a657249d..8096b46b654fd 100644 --- a/drivers/net/ethernet/marvell/mvpp2/mvpp2_main.c +++ b/drivers/net/ethernet/marvell/mvpp2/mvpp2_main.c @@ -5099,7 +5099,8 @@ static int mvpp2_change_mtu(struct net_device *dev, int mtu) netdev_warn(dev, "mtu %d too high, switching to shared buffers", mtu); mvpp2_bm_switch_buffers(priv, false); } - } else { + } else if (priv->hw_version >= MVPP22 && + mvpp2_get_nrxqs(priv) * 2 <= MVPP2_BM_MAX_POOLS) { bool jumbo = false; int i; -- 2.53.0