* [PATCH 1/2] net/bnxt: cap memcpy at field size
2026-10-05 15:17 [PATCH 0/2] net/bnxt: fix two ULP parser/mapper safety issues Manish Kurup
@ 2026-10-05 15:17 ` Manish Kurup
2026-10-05 15:17 ` [PATCH 2/2] net/bnxt: replace VLA with heap allocation Manish Kurup
1 sibling, 0 replies; 3+ messages in thread
From: Manish Kurup @ 2026-10-05 15:17 UTC (permalink / raw)
To: dev; +Cc: kishore.padmanabha, Dakota Sicher, stable
From: Dakota Sicher <dakota.sicher@broadcom.com>
The memcpy() copying a header field's value in the parser does not
check whether the source size exceeds the field's spec size, so an
oversized value overflows the destination field.
Fixes: f63aa27db634 ("net/bnxt: support dynamic encap action")
Fixes: 741172be52de ("net/bnxt: refactor flow parser in ULP")
Cc: stable@dpdk.org
Signed-off-by: Dakota Sicher <dakota.sicher@broadcom.com>
Signed-off-by: Manish Kurup <manish.kurup@broadcom.com>
---
drivers/net/bnxt/tf_ulp/ulp_rte_parser.c | 10 ++++++++++
1 file changed, 10 insertions(+)
diff --git a/drivers/net/bnxt/tf_ulp/ulp_rte_parser.c b/drivers/net/bnxt/tf_ulp/ulp_rte_parser.c
index 442a795430..12f9cb80e9 100644
--- a/drivers/net/bnxt/tf_ulp/ulp_rte_parser.c
+++ b/drivers/net/bnxt/tf_ulp/ulp_rte_parser.c
@@ -66,6 +66,11 @@ ulp_rte_parser_fld_copy(struct ulp_rte_hdr_field *field,
const void *buffer,
uint32_t size)
{
+ if (unlikely(size > RTE_PARSER_FLOW_HDR_FIELD_SIZE)) {
+ BNXT_DRV_DBG(ERR, "Field size %u exceeds max of %u, clamping",
+ size, RTE_PARSER_FLOW_HDR_FIELD_SIZE);
+ size = RTE_PARSER_FLOW_HDR_FIELD_SIZE;
+ }
field->size = size;
memcpy(field->spec, buffer, field->size);
field++;
@@ -106,6 +111,11 @@ ulp_rte_prsr_fld_mask(struct ulp_rte_parser_params *params,
{
struct ulp_rte_hdr_field *field = ¶ms->hdr_field[*idx];
+ if (unlikely(size > RTE_PARSER_FLOW_HDR_FIELD_SIZE)) {
+ BNXT_DRV_DBG(ERR, "Field size %u exceeds max of %u, clamping",
+ size, RTE_PARSER_FLOW_HDR_FIELD_SIZE);
+ size = RTE_PARSER_FLOW_HDR_FIELD_SIZE;
+ }
/* update the field size */
field->size = size;
--
2.31.1
^ permalink raw reply related [flat|nested] 3+ messages in thread* [PATCH 2/2] net/bnxt: replace VLA with heap allocation
2026-10-05 15:17 [PATCH 0/2] net/bnxt: fix two ULP parser/mapper safety issues Manish Kurup
2026-10-05 15:17 ` [PATCH 1/2] net/bnxt: cap memcpy at field size Manish Kurup
@ 2026-10-05 15:17 ` Manish Kurup
1 sibling, 0 replies; 3+ messages in thread
From: Manish Kurup @ 2026-10-05 15:17 UTC (permalink / raw)
To: dev; +Cc: kishore.padmanabha, Dakota Sicher, stable
From: Dakota Sicher <dakota.sicher@broadcom.com>
ulp_mapper_blob_block_swap() used a variable-length array on the
stack sized by caller input for swap memory. Use a heap allocation
instead to avoid unbounded stack growth.
Fixes: dd0191d5e70d ("net/bnxt/tf_ulp: support Thor2 ULP layer")
Cc: stable@dpdk.org
Signed-off-by: Dakota Sicher <dakota.sicher@broadcom.com>
Signed-off-by: Manish Kurup <manish.kurup@broadcom.com>
---
drivers/net/bnxt/tf_ulp/ulp_mapper_tfc.c | 10 ++++++++--
1 file changed, 8 insertions(+), 2 deletions(-)
diff --git a/drivers/net/bnxt/tf_ulp/ulp_mapper_tfc.c b/drivers/net/bnxt/tf_ulp/ulp_mapper_tfc.c
index 2d89f10d5e..934634c606 100644
--- a/drivers/net/bnxt/tf_ulp/ulp_mapper_tfc.c
+++ b/drivers/net/bnxt/tf_ulp/ulp_mapper_tfc.c
@@ -388,9 +388,8 @@ static const char * const mpc_error_str[] = {
static int32_t
ulp_mapper_blob_block_swap(struct ulp_blob *blob, uint32_t block_sz)
{
- uint8_t data[block_sz]; /* size of a block for temp storage */
uint16_t num_words, data_sz;
- uint8_t *pdata;
+ uint8_t *pdata, *data;
int i;
/* Shouldn't happen since it is internal function, but check anyway */
@@ -407,6 +406,12 @@ ulp_mapper_blob_block_swap(struct ulp_blob *blob, uint32_t block_sz)
return -EINVAL;
}
+ data = rte_zmalloc(NULL, block_sz, 0);
+ if (unlikely(!data)) {
+ BNXT_DRV_DBG(ERR, "Failed to allocate swap buffer");
+ return -ENOMEM;
+ }
+
num_words = data_sz / block_sz;
for (i = 0; i < num_words / 2; i++) {
memcpy(data, &pdata[i * block_sz], block_sz);
@@ -415,6 +420,7 @@ ulp_mapper_blob_block_swap(struct ulp_blob *blob, uint32_t block_sz)
memcpy(&pdata[(num_words - 1 - i) * block_sz],
data, block_sz);
}
+ rte_free(data);
return 0;
}
--
2.31.1
^ permalink raw reply related [flat|nested] 3+ messages in thread