DPDK-dev Archive on lore.kernel.org
 help / color / mirror / Atom feed
* [PATCH 0/2] net/bnxt: fix two ULP parser/mapper safety issues
@ 2026-10-05 15:17 Manish Kurup
  2026-10-05 15:17 ` [PATCH 1/2] net/bnxt: cap memcpy at field size Manish Kurup
  2026-10-05 15:17 ` [PATCH 2/2] net/bnxt: replace VLA with heap allocation Manish Kurup
  0 siblings, 2 replies; 3+ messages in thread
From: Manish Kurup @ 2026-10-05 15:17 UTC (permalink / raw)
  To: dev; +Cc: kishore.padmanabha

Two unrelated hardening fixes in the ULP parser/mapper found during
review:

- Patch 1 caps a header-field memcpy() at the field's spec size,
  fixing a potential overflow when the source value is larger than
  the destination field.

- Patch 2 replaces a variable-length array sized by caller input
  with a heap allocation, avoiding unbounded stack growth.

Dakota Sicher (2):
  net/bnxt: cap memcpy at field size
  net/bnxt: replace VLA with heap allocation

 drivers/net/bnxt/tf_ulp/ulp_mapper_tfc.c | 10 ++++++++--
 drivers/net/bnxt/tf_ulp/ulp_rte_parser.c | 10 ++++++++++
 2 files changed, 18 insertions(+), 2 deletions(-)

-- 
2.31.1


^ permalink raw reply	[flat|nested] 3+ messages in thread

* [PATCH 1/2] net/bnxt: cap memcpy at field size
  2026-10-05 15:17 [PATCH 0/2] net/bnxt: fix two ULP parser/mapper safety issues Manish Kurup
@ 2026-10-05 15:17 ` Manish Kurup
  2026-10-05 15:17 ` [PATCH 2/2] net/bnxt: replace VLA with heap allocation Manish Kurup
  1 sibling, 0 replies; 3+ messages in thread
From: Manish Kurup @ 2026-10-05 15:17 UTC (permalink / raw)
  To: dev; +Cc: kishore.padmanabha, Dakota Sicher, stable

From: Dakota Sicher <dakota.sicher@broadcom.com>

The memcpy() copying a header field's value in the parser does not
check whether the source size exceeds the field's spec size, so an
oversized value overflows the destination field.

Fixes: f63aa27db634 ("net/bnxt: support dynamic encap action")
Fixes: 741172be52de ("net/bnxt: refactor flow parser in ULP")
Cc: stable@dpdk.org

Signed-off-by: Dakota Sicher <dakota.sicher@broadcom.com>
Signed-off-by: Manish Kurup <manish.kurup@broadcom.com>
---
 drivers/net/bnxt/tf_ulp/ulp_rte_parser.c | 10 ++++++++++
 1 file changed, 10 insertions(+)

diff --git a/drivers/net/bnxt/tf_ulp/ulp_rte_parser.c b/drivers/net/bnxt/tf_ulp/ulp_rte_parser.c
index 442a795430..12f9cb80e9 100644
--- a/drivers/net/bnxt/tf_ulp/ulp_rte_parser.c
+++ b/drivers/net/bnxt/tf_ulp/ulp_rte_parser.c
@@ -66,6 +66,11 @@ ulp_rte_parser_fld_copy(struct ulp_rte_hdr_field *field,
 			const void *buffer,
 			uint32_t size)
 {
+	if (unlikely(size > RTE_PARSER_FLOW_HDR_FIELD_SIZE)) {
+		BNXT_DRV_DBG(ERR, "Field size %u exceeds max of %u, clamping",
+			     size, RTE_PARSER_FLOW_HDR_FIELD_SIZE);
+		size = RTE_PARSER_FLOW_HDR_FIELD_SIZE;
+	}
 	field->size = size;
 	memcpy(field->spec, buffer, field->size);
 	field++;
@@ -106,6 +111,11 @@ ulp_rte_prsr_fld_mask(struct ulp_rte_parser_params *params,
 {
 	struct ulp_rte_hdr_field *field = &params->hdr_field[*idx];
 
+	if (unlikely(size > RTE_PARSER_FLOW_HDR_FIELD_SIZE)) {
+		BNXT_DRV_DBG(ERR, "Field size %u exceeds max of %u, clamping",
+			     size, RTE_PARSER_FLOW_HDR_FIELD_SIZE);
+		size = RTE_PARSER_FLOW_HDR_FIELD_SIZE;
+	}
 	/* update the field size */
 	field->size = size;
 
-- 
2.31.1


^ permalink raw reply related	[flat|nested] 3+ messages in thread

* [PATCH 2/2] net/bnxt: replace VLA with heap allocation
  2026-10-05 15:17 [PATCH 0/2] net/bnxt: fix two ULP parser/mapper safety issues Manish Kurup
  2026-10-05 15:17 ` [PATCH 1/2] net/bnxt: cap memcpy at field size Manish Kurup
@ 2026-10-05 15:17 ` Manish Kurup
  1 sibling, 0 replies; 3+ messages in thread
From: Manish Kurup @ 2026-10-05 15:17 UTC (permalink / raw)
  To: dev; +Cc: kishore.padmanabha, Dakota Sicher, stable

From: Dakota Sicher <dakota.sicher@broadcom.com>

ulp_mapper_blob_block_swap() used a variable-length array on the
stack sized by caller input for swap memory. Use a heap allocation
instead to avoid unbounded stack growth.

Fixes: dd0191d5e70d ("net/bnxt/tf_ulp: support Thor2 ULP layer")
Cc: stable@dpdk.org

Signed-off-by: Dakota Sicher <dakota.sicher@broadcom.com>
Signed-off-by: Manish Kurup <manish.kurup@broadcom.com>
---
 drivers/net/bnxt/tf_ulp/ulp_mapper_tfc.c | 10 ++++++++--
 1 file changed, 8 insertions(+), 2 deletions(-)

diff --git a/drivers/net/bnxt/tf_ulp/ulp_mapper_tfc.c b/drivers/net/bnxt/tf_ulp/ulp_mapper_tfc.c
index 2d89f10d5e..934634c606 100644
--- a/drivers/net/bnxt/tf_ulp/ulp_mapper_tfc.c
+++ b/drivers/net/bnxt/tf_ulp/ulp_mapper_tfc.c
@@ -388,9 +388,8 @@ static const char * const mpc_error_str[] = {
 static int32_t
 ulp_mapper_blob_block_swap(struct ulp_blob *blob, uint32_t block_sz)
 {
-	uint8_t data[block_sz]; /* size of a block for temp storage */
 	uint16_t num_words, data_sz;
-	uint8_t *pdata;
+	uint8_t *pdata, *data;
 	int i;
 
 	/* Shouldn't happen since it is internal function, but check anyway */
@@ -407,6 +406,12 @@ ulp_mapper_blob_block_swap(struct ulp_blob *blob, uint32_t block_sz)
 		return -EINVAL;
 	}
 
+	data = rte_zmalloc(NULL, block_sz, 0);
+	if (unlikely(!data)) {
+		BNXT_DRV_DBG(ERR, "Failed to allocate swap buffer");
+		return -ENOMEM;
+	}
+
 	num_words = data_sz / block_sz;
 	for (i = 0; i < num_words / 2; i++) {
 		memcpy(data, &pdata[i * block_sz], block_sz);
@@ -415,6 +420,7 @@ ulp_mapper_blob_block_swap(struct ulp_blob *blob, uint32_t block_sz)
 		memcpy(&pdata[(num_words - 1 - i) * block_sz],
 		       data, block_sz);
 	}
+	rte_free(data);
 	return 0;
 }
 
-- 
2.31.1


^ permalink raw reply related	[flat|nested] 3+ messages in thread

end of thread, other threads:[~2026-10-05 15:18 UTC | newest]

Thread overview: 3+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-10-05 15:17 [PATCH 0/2] net/bnxt: fix two ULP parser/mapper safety issues Manish Kurup
2026-10-05 15:17 ` [PATCH 1/2] net/bnxt: cap memcpy at field size Manish Kurup
2026-10-05 15:17 ` [PATCH 2/2] net/bnxt: replace VLA with heap allocation Manish Kurup

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox