DPDK-dev Archive on lore.kernel.org
 help / color / mirror / Atom feed
From: Manish Kurup <manish.kurup@broadcom.com>
To: dev@dpdk.org
Cc: kishore.padmanabha@broadcom.com,
	Dakota Sicher <dakota.sicher@broadcom.com>,
	stable@dpdk.org
Subject: [PATCH 1/2] net/bnxt: cap memcpy at field size
Date: Mon,  5 Oct 2026 10:17:26 -0500	[thread overview]
Message-ID: <20261005151727.1706155-2-manish.kurup@broadcom.com> (raw)
In-Reply-To: <20261005151727.1706155-1-manish.kurup@broadcom.com>

From: Dakota Sicher <dakota.sicher@broadcom.com>

The memcpy() copying a header field's value in the parser does not
check whether the source size exceeds the field's spec size, so an
oversized value overflows the destination field.

Fixes: f63aa27db634 ("net/bnxt: support dynamic encap action")
Fixes: 741172be52de ("net/bnxt: refactor flow parser in ULP")
Cc: stable@dpdk.org

Signed-off-by: Dakota Sicher <dakota.sicher@broadcom.com>
Signed-off-by: Manish Kurup <manish.kurup@broadcom.com>
---
 drivers/net/bnxt/tf_ulp/ulp_rte_parser.c | 10 ++++++++++
 1 file changed, 10 insertions(+)

diff --git a/drivers/net/bnxt/tf_ulp/ulp_rte_parser.c b/drivers/net/bnxt/tf_ulp/ulp_rte_parser.c
index 442a795430..12f9cb80e9 100644
--- a/drivers/net/bnxt/tf_ulp/ulp_rte_parser.c
+++ b/drivers/net/bnxt/tf_ulp/ulp_rte_parser.c
@@ -66,6 +66,11 @@ ulp_rte_parser_fld_copy(struct ulp_rte_hdr_field *field,
 			const void *buffer,
 			uint32_t size)
 {
+	if (unlikely(size > RTE_PARSER_FLOW_HDR_FIELD_SIZE)) {
+		BNXT_DRV_DBG(ERR, "Field size %u exceeds max of %u, clamping",
+			     size, RTE_PARSER_FLOW_HDR_FIELD_SIZE);
+		size = RTE_PARSER_FLOW_HDR_FIELD_SIZE;
+	}
 	field->size = size;
 	memcpy(field->spec, buffer, field->size);
 	field++;
@@ -106,6 +111,11 @@ ulp_rte_prsr_fld_mask(struct ulp_rte_parser_params *params,
 {
 	struct ulp_rte_hdr_field *field = &params->hdr_field[*idx];
 
+	if (unlikely(size > RTE_PARSER_FLOW_HDR_FIELD_SIZE)) {
+		BNXT_DRV_DBG(ERR, "Field size %u exceeds max of %u, clamping",
+			     size, RTE_PARSER_FLOW_HDR_FIELD_SIZE);
+		size = RTE_PARSER_FLOW_HDR_FIELD_SIZE;
+	}
 	/* update the field size */
 	field->size = size;
 
-- 
2.31.1


  reply	other threads:[~2026-10-05 15:17 UTC|newest]

Thread overview: 3+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-10-05 15:17 [PATCH 0/2] net/bnxt: fix two ULP parser/mapper safety issues Manish Kurup
2026-10-05 15:17 ` Manish Kurup [this message]
2026-10-05 15:17 ` [PATCH 2/2] net/bnxt: replace VLA with heap allocation Manish Kurup

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20261005151727.1706155-2-manish.kurup@broadcom.com \
    --to=manish.kurup@broadcom.com \
    --cc=dakota.sicher@broadcom.com \
    --cc=dev@dpdk.org \
    --cc=kishore.padmanabha@broadcom.com \
    --cc=stable@dpdk.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox