From: Raslan Darawsheh <rasland@nvidia.com>
To: Maayan Kashani <mkashani@nvidia.com>, dev@dpdk.org
Cc: stable@dpdk.org, Dariusz Sosnowski <dsosnowski@nvidia.com>,
Viacheslav Ovsiienko <viacheslavo@nvidia.com>,
Bing Zhao <bingz@nvidia.com>, Ori Kam <orika@nvidia.com>,
Suanming Mou <suanmingm@nvidia.com>,
Matan Azrad <matan@nvidia.com>,
Alexander Kozyrev <akozyrev@nvidia.com>
Subject: Re: [PATCH] net/mlx5: fix stack-buffer-overflow in indexed based rules
Date: Mon, 18 Aug 2025 09:31:01 +0300 [thread overview]
Message-ID: <6a474dbb-c021-4f7c-9df1-3cbbeaf040c7@nvidia.com> (raw)
In-Reply-To: <20250730071700.187675-1-mkashani@nvidia.com>
Hi,
On 30/07/2025 10:16 AM, Maayan Kashani wrote:
> During asynchronous flow creation by index,
> the items array was initialized with only one element,
> but the table metadata did not update the item count accordingly.
> This mismatch led to an out-of-bounds memcpy operation,
> as the code attempted to copy more elements than were actually allocated.
>
> To resolve this, since item matching is disregarded when inserting a
> rule by index (the rule is triggered when a packet reaches the
> specified index),
> the fix is to skip preparing the items array in this case.
> Instead, the items array should only contain a single element,
> RTE_FLOW_ITEM_TYPE_END, which indicates no match pattern is needed.
> This prevents unsafe memory operations and aligns the array size
> with its intended usage.
>
> Fixes: 36c379c82e82 ("net/mlx5: add flow rule insertion by index with pattern")
> Cc: stable@dpdk.org
>
> Signed-off-by: Maayan Kashani <mkashani@nvidia.com>
> Acked-by: Dariusz Sosnowski <dsosnowski@nvidia.com>
Patch applied to next-net-mlx,
Kindest regards
Raslan Darawsheh
prev parent reply other threads:[~2025-08-18 6:31 UTC|newest]
Thread overview: 2+ messages / expand[flat|nested] mbox.gz Atom feed top
2025-07-30 7:16 [PATCH] net/mlx5: fix stack-buffer-overflow in indexed based rules Maayan Kashani
2025-08-18 6:31 ` Raslan Darawsheh [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=6a474dbb-c021-4f7c-9df1-3cbbeaf040c7@nvidia.com \
--to=rasland@nvidia.com \
--cc=akozyrev@nvidia.com \
--cc=bingz@nvidia.com \
--cc=dev@dpdk.org \
--cc=dsosnowski@nvidia.com \
--cc=matan@nvidia.com \
--cc=mkashani@nvidia.com \
--cc=orika@nvidia.com \
--cc=stable@dpdk.org \
--cc=suanmingm@nvidia.com \
--cc=viacheslavo@nvidia.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.