DPDK-dev Archive on lore.kernel.org
 help / color / mirror / Atom feed
* [PATCH] net/bnxt: fix out-of-bounds read in TCAM get
@ 2026-10-05 15:16 Manish Kurup
  0 siblings, 0 replies; only message in thread
From: Manish Kurup @ 2026-10-05 15:16 UTC (permalink / raw)
  To: dev; +Cc: kishore.padmanabha, Farah Smith, stable, Shahaji Bhosle

From: Farah Smith <farah.smith@broadcom.com>

A missing return after a buffer size check allowed execution to fall
through into memcpy calls using firmware-controlled lengths, causing
an out-of-bounds read from the response buffer and potential overflow
of the caller's key, mask, and remap buffers.

Fix by returning immediately on error before any data is copied out.

Also validate that firmware-reported sizes are consistent with the
fixed-size response data array before copying, and ensure firmware
response sizes are converted to host byte order before use. Cast
result_size to size_t in the new bounds check to match key_size and
avoid a -Wsign-compare warning against the size_t from sizeof().

Fixes: 80317ff6adfd ("net/bnxt/tf_core: support Thor2")
Cc: stable@dpdk.org

Signed-off-by: Farah Smith <farah.smith@broadcom.com>
Signed-off-by: Shahaji Bhosle <shahaji.bhosle@broadcom.com>
Signed-off-by: Manish Kurup <manish.kurup@broadcom.com>
---
 drivers/net/bnxt/tf_core/v3/tfc_msg.c | 28 ++++++++++++++++++---------
 1 file changed, 19 insertions(+), 9 deletions(-)

diff --git a/drivers/net/bnxt/tf_core/v3/tfc_msg.c b/drivers/net/bnxt/tf_core/v3/tfc_msg.c
index cf72d09184..df11910dc3 100644
--- a/drivers/net/bnxt/tf_core/v3/tfc_msg.c
+++ b/drivers/net/bnxt/tf_core/v3/tfc_msg.c
@@ -1154,18 +1154,28 @@ tfc_msg_tcam_get(struct tfc *tfcp, uint16_t fid, uint16_t sid,
 	rc = bnxt_hwrm_tf_message_direct(bp, false, HWRM_TFC_TCAM_GET,
 					 &req, sizeof(req), &resp, sizeof(resp));
 
-	if (rc ||
-	    *key_size < rte_le_to_cpu_16(resp.key_size) ||
+	if (rc)
+		return rc;
+
+	if ((size_t)rte_le_to_cpu_16(resp.key_size) * 2 +
+	    (size_t)rte_le_to_cpu_16(resp.result_size) > sizeof(resp.dev_data)) {
+		rc = -EINVAL;
+		PMD_DRV_LOG_LINE(ERR, "%s: FW sizes exceed TCAM bounds, rc:%d",
+				 __func__, rc);
+		return rc;
+	}
+	if (*key_size < rte_le_to_cpu_16(resp.key_size) ||
 	    *remap_size < rte_le_to_cpu_16(resp.result_size)) {
-		PMD_DRV_LOG_LINE(ERR, "Key buffer is too small, rc:%s",
-				 strerror(EINVAL));
 		rc = -EINVAL;
+		PMD_DRV_LOG_LINE(ERR, "%s: Caller buffer too small, rc:%d",
+				 __func__, rc);
+		return rc;
 	}
-	*key_size = resp.key_size;
-	*remap_size = resp.result_size;
-	memcpy(key, &resp.dev_data[0], resp.key_size);
-	memcpy(mask, &resp.dev_data[resp.key_size], resp.key_size);
-	memcpy(remap, &resp.dev_data[resp.key_size * 2], resp.result_size);
+	*key_size = rte_le_to_cpu_16(resp.key_size);
+	*remap_size = rte_le_to_cpu_16(resp.result_size);
+	memcpy(key, &resp.dev_data[0], *key_size);
+	memcpy(mask, &resp.dev_data[*key_size], *key_size);
+	memcpy(remap, &resp.dev_data[*key_size * 2], *remap_size);
 
 	return rc;
 }
-- 
2.31.1


^ permalink raw reply related	[flat|nested] only message in thread

only message in thread, other threads:[~2026-10-05 15:17 UTC | newest]

Thread overview: (only message) (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-10-05 15:16 [PATCH] net/bnxt: fix out-of-bounds read in TCAM get Manish Kurup

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox