From: Manish Kurup <manish.kurup@broadcom.com>
To: dev@dpdk.org
Cc: kishore.padmanabha@broadcom.com,
Farah Smith <farah.smith@broadcom.com>,
stable@dpdk.org, Shahaji Bhosle <shahaji.bhosle@broadcom.com>
Subject: [PATCH] net/bnxt: fix out-of-bounds read in TCAM get
Date: Mon, 5 Oct 2026 10:16:55 -0500 [thread overview]
Message-ID: <20261005151655.1705915-1-manish.kurup@broadcom.com> (raw)
From: Farah Smith <farah.smith@broadcom.com>
A missing return after a buffer size check allowed execution to fall
through into memcpy calls using firmware-controlled lengths, causing
an out-of-bounds read from the response buffer and potential overflow
of the caller's key, mask, and remap buffers.
Fix by returning immediately on error before any data is copied out.
Also validate that firmware-reported sizes are consistent with the
fixed-size response data array before copying, and ensure firmware
response sizes are converted to host byte order before use. Cast
result_size to size_t in the new bounds check to match key_size and
avoid a -Wsign-compare warning against the size_t from sizeof().
Fixes: 80317ff6adfd ("net/bnxt/tf_core: support Thor2")
Cc: stable@dpdk.org
Signed-off-by: Farah Smith <farah.smith@broadcom.com>
Signed-off-by: Shahaji Bhosle <shahaji.bhosle@broadcom.com>
Signed-off-by: Manish Kurup <manish.kurup@broadcom.com>
---
drivers/net/bnxt/tf_core/v3/tfc_msg.c | 28 ++++++++++++++++++---------
1 file changed, 19 insertions(+), 9 deletions(-)
diff --git a/drivers/net/bnxt/tf_core/v3/tfc_msg.c b/drivers/net/bnxt/tf_core/v3/tfc_msg.c
index cf72d09184..df11910dc3 100644
--- a/drivers/net/bnxt/tf_core/v3/tfc_msg.c
+++ b/drivers/net/bnxt/tf_core/v3/tfc_msg.c
@@ -1154,18 +1154,28 @@ tfc_msg_tcam_get(struct tfc *tfcp, uint16_t fid, uint16_t sid,
rc = bnxt_hwrm_tf_message_direct(bp, false, HWRM_TFC_TCAM_GET,
&req, sizeof(req), &resp, sizeof(resp));
- if (rc ||
- *key_size < rte_le_to_cpu_16(resp.key_size) ||
+ if (rc)
+ return rc;
+
+ if ((size_t)rte_le_to_cpu_16(resp.key_size) * 2 +
+ (size_t)rte_le_to_cpu_16(resp.result_size) > sizeof(resp.dev_data)) {
+ rc = -EINVAL;
+ PMD_DRV_LOG_LINE(ERR, "%s: FW sizes exceed TCAM bounds, rc:%d",
+ __func__, rc);
+ return rc;
+ }
+ if (*key_size < rte_le_to_cpu_16(resp.key_size) ||
*remap_size < rte_le_to_cpu_16(resp.result_size)) {
- PMD_DRV_LOG_LINE(ERR, "Key buffer is too small, rc:%s",
- strerror(EINVAL));
rc = -EINVAL;
+ PMD_DRV_LOG_LINE(ERR, "%s: Caller buffer too small, rc:%d",
+ __func__, rc);
+ return rc;
}
- *key_size = resp.key_size;
- *remap_size = resp.result_size;
- memcpy(key, &resp.dev_data[0], resp.key_size);
- memcpy(mask, &resp.dev_data[resp.key_size], resp.key_size);
- memcpy(remap, &resp.dev_data[resp.key_size * 2], resp.result_size);
+ *key_size = rte_le_to_cpu_16(resp.key_size);
+ *remap_size = rte_le_to_cpu_16(resp.result_size);
+ memcpy(key, &resp.dev_data[0], *key_size);
+ memcpy(mask, &resp.dev_data[*key_size], *key_size);
+ memcpy(remap, &resp.dev_data[*key_size * 2], *remap_size);
return rc;
}
--
2.31.1
reply other threads:[~2026-10-05 15:17 UTC|newest]
Thread overview: [no followups] expand[flat|nested] mbox.gz Atom feed
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20261005151655.1705915-1-manish.kurup@broadcom.com \
--to=manish.kurup@broadcom.com \
--cc=dev@dpdk.org \
--cc=farah.smith@broadcom.com \
--cc=kishore.padmanabha@broadcom.com \
--cc=shahaji.bhosle@broadcom.com \
--cc=stable@dpdk.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox