From: Manish Kurup <manish.kurup@broadcom.com>
To: dev@dpdk.org
Cc: kishore.padmanabha@broadcom.com,
Farah Smith <farah.smith@broadcom.com>,
stable@dpdk.org
Subject: [PATCH] net/bnxt: add response bounds checks for TruFlow messages
Date: Mon, 5 Oct 2026 15:25:07 -0500 [thread overview]
Message-ID: <20261005202507.17770-1-manish.kurup@broadcom.com> (raw)
From: Farah Smith <farah.smith@broadcom.com>
Add explicit input validation against fixed response data buffer
sizes in TruFlow message getters. This prevents potential stack
over-reads if a caller passes a requested size exceeding the local
response buffer size.
Add the same guard to tf_msg_get_tbl_entry(), tf_msg_get_global_cfg(),
and tf_msg_get_if_tbl_entry() - each copies firmware response data
into a caller buffer using a caller-supplied size without first
checking that size against the local, fixed-size response buffer.
Also use the caller's own size value directly for the final memcpy
in tf_msg_get_global_cfg() and tf_msg_get_if_tbl_entry() instead of
a re-derived field, avoiding any possible mismatch between the two.
Fixes: e2a002d88c44 ("net/bnxt: update RM to support HCAPI only")
Fixes: a11f87d3b2ca ("net/bnxt: add global config set and get functions")
Fixes: 37ff91c158a3 ("net/bnxt: add SRAM manager model")
Cc: stable@dpdk.org
Signed-off-by: Farah Smith <farah.smith@broadcom.com>
Signed-off-by: Manish Kurup <manish.kurup@broadcom.com>
---
drivers/net/bnxt/tf_core/tf_msg.c | 13 +++++++++++--
1 file changed, 11 insertions(+), 2 deletions(-)
diff --git a/drivers/net/bnxt/tf_core/tf_msg.c b/drivers/net/bnxt/tf_core/tf_msg.c
index 645a4b1e66..aab8d05d81 100644
--- a/drivers/net/bnxt/tf_core/tf_msg.c
+++ b/drivers/net/bnxt/tf_core/tf_msg.c
@@ -1406,6 +1406,9 @@ tf_msg_get_tbl_entry(struct tf *tfp,
struct tf_session *tfs;
uint32_t flags = 0;
+ if (size > sizeof(resp.data))
+ return -EINVAL;
+
/* Retrieve the session information */
rc = tf_session_get_session_internal(tfp, &tfs);
if (rc) {
@@ -1493,6 +1496,9 @@ tf_msg_get_global_cfg(struct tf *tfp,
struct tf_dev_info *dev;
struct tf_session *tfs;
+ if (params->config_sz_in_bytes > sizeof(resp.data))
+ return -EINVAL;
+
/* Retrieve the session information */
rc = tf_session_get_session_internal(tfp, &tfs);
if (rc) {
@@ -1552,7 +1558,7 @@ tf_msg_get_global_cfg(struct tf *tfp,
if (params->config)
tfp_memcpy(params->config,
resp.data,
- resp_size);
+ params->config_sz_in_bytes);
else
return -EFAULT;
@@ -1746,6 +1752,9 @@ tf_msg_get_if_tbl_entry(struct tf *tfp,
struct tf_dev_info *dev;
struct tf_session *tfs;
+ if (params->data_sz_in_bytes > sizeof(resp.data))
+ return -EINVAL;
+
/* Retrieve the session information */
rc = tf_session_get_session(tfp, &tfs);
if (rc) {
@@ -1790,7 +1799,7 @@ tf_msg_get_if_tbl_entry(struct tf *tfp,
if (rc != 0)
return rc;
- tfp_memcpy(¶ms->data[0], resp.data, req.size);
+ tfp_memcpy(¶ms->data[0], resp.data, params->data_sz_in_bytes);
return 0;
}
--
2.31.1
reply other threads:[~2026-10-05 20:25 UTC|newest]
Thread overview: [no followups] expand[flat|nested] mbox.gz Atom feed
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20261005202507.17770-1-manish.kurup@broadcom.com \
--to=manish.kurup@broadcom.com \
--cc=dev@dpdk.org \
--cc=farah.smith@broadcom.com \
--cc=kishore.padmanabha@broadcom.com \
--cc=stable@dpdk.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox