From: Mohammad Shuab Siddique <mohammad-shuab.siddique@broadcom.com>
To: dev@dpdk.org
Cc: kishore.padmanabha@broadcom.com, stable@dpdk.org,
Mohammad Shuab Siddique <mohammad-shuab.siddique@broadcom.com>
Subject: [PATCH] net/bnxt: fix bounds in RSS queue match and ctx initializer
Date: Sun, 20 Sep 2026 21:06:40 -0600 [thread overview]
Message-ID: <20260921030640.1034836-1-Mohammad-Shuab.Siddique@broadcom.com> (raw)
From: Kishore Padmanabha <kishore.padmanabha@broadcom.com>
Two independent out-of-bounds issues:
- match_vnic_rss_cfg() indexed bp->rx_queues[] with firmware/
application-supplied RSS queue IDs without validating them against
bp->rx_nr_rings first, and dereferenced the resulting (possibly
NULL) queue pointer unconditionally.
- bnxt_init_ctx_initializer() computed ctxm->init_offset from a
firmware-supplied byte offset without checking it against the
context entry's own size, allowing an out-of-range init offset to
be used later when initializing backing-store entries.
Fixes: adc0f81c6552 ("net/bnxt: support RSS action")
Fixes: fe2f715ca580 ("net/bnxt: support backing store v2")
Cc: stable@dpdk.org
Signed-off-by: Kishore Padmanabha <kishore.padmanabha@broadcom.com>
Signed-off-by: Mohammad Shuab Siddique <mohammad-shuab.siddique@broadcom.com>
---
drivers/net/bnxt/bnxt_flow.c | 13 +++++++++++++
drivers/net/bnxt/bnxt_hwrm.c | 14 +++++++++++---
2 files changed, 24 insertions(+), 3 deletions(-)
diff --git a/drivers/net/bnxt/bnxt_flow.c b/drivers/net/bnxt/bnxt_flow.c
index a2e590540b..12d21c4853 100644
--- a/drivers/net/bnxt/bnxt_flow.c
+++ b/drivers/net/bnxt/bnxt_flow.c
@@ -968,10 +968,23 @@ static int match_vnic_rss_cfg(struct bnxt *bp,
{
unsigned int match = 0, i;
+ if (rss->queue_num > bp->rx_nr_rings)
+ return -EINVAL;
+
if (vnic->rx_queue_cnt != rss->queue_num)
return -EINVAL;
for (i = 0; i < rss->queue_num; i++) {
+ if (rss->queue[i] >= bp->rx_nr_rings) {
+ PMD_DRV_LOG_LINE(ERR, "Queue ID %u for RSS exceeds ring count %u",
+ rss->queue[i], bp->rx_nr_rings);
+ return -EINVAL;
+ }
+ if (!bp->rx_queues[rss->queue[i]]) {
+ PMD_DRV_LOG_LINE(ERR, "Queue ID %u for RSS is not configured",
+ rss->queue[i]);
+ return -EINVAL;
+ }
if (!bp->rx_queues[rss->queue[i]]->vnic->rx_queue_cnt &&
!bp->rx_queues[rss->queue[i]]->rx_started)
return -EINVAL;
diff --git a/drivers/net/bnxt/bnxt_hwrm.c b/drivers/net/bnxt/bnxt_hwrm.c
index 1615b36aae..8d2253160f 100644
--- a/drivers/net/bnxt/bnxt_hwrm.c
+++ b/drivers/net/bnxt/bnxt_hwrm.c
@@ -6770,10 +6770,18 @@ static void bnxt_init_ctx_initializer(struct bnxt_ctx_mem *ctxm,
{
ctxm->init_value = init_val;
ctxm->init_offset = BNXT_CTX_INIT_INVALID_OFFSET;
- if (init_mask_set)
- ctxm->init_offset = init_offset * 4;
- else
+ if (init_mask_set) {
+ ctxm->init_offset = (uint16_t)(init_offset * 4);
+ if (ctxm->init_offset >= ctxm->entry_size) {
+ PMD_DRV_LOG_LINE(WARNING,
+ "ctx type 0x%x: init_offset %u >= entry_size %u, disabling init",
+ ctxm->type, ctxm->init_offset, ctxm->entry_size);
+ ctxm->init_value = 0;
+ ctxm->init_offset = BNXT_CTX_INIT_INVALID_OFFSET;
+ }
+ } else {
ctxm->init_value = 0;
+ }
}
static int bnxt_alloc_all_ctx_pg_info(struct bnxt *bp)
--
2.47.3
reply other threads:[~2026-09-21 3:03 UTC|newest]
Thread overview: [no followups] expand[flat|nested] mbox.gz Atom feed
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260921030640.1034836-1-Mohammad-Shuab.Siddique@broadcom.com \
--to=mohammad-shuab.siddique@broadcom.com \
--cc=dev@dpdk.org \
--cc=kishore.padmanabha@broadcom.com \
--cc=stable@dpdk.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox