DPDK-dev Archive on lore.kernel.org
 help / color / mirror / Atom feed
From: Manish Kurup <manish.kurup@broadcom.com>
To: dev@dpdk.org
Cc: kishore.padmanabha@broadcom.com,
	Farah Smith <farah.smith@broadcom.com>,
	stable@dpdk.org
Subject: [PATCH] net/bnxt: add response bounds checks for TruFlow messages
Date: Mon,  5 Oct 2026 15:25:07 -0500	[thread overview]
Message-ID: <20261005202507.17770-1-manish.kurup@broadcom.com> (raw)

From: Farah Smith <farah.smith@broadcom.com>

Add explicit input validation against fixed response data buffer
sizes in TruFlow message getters. This prevents potential stack
over-reads if a caller passes a requested size exceeding the local
response buffer size.

Add the same guard to tf_msg_get_tbl_entry(), tf_msg_get_global_cfg(),
and tf_msg_get_if_tbl_entry() - each copies firmware response data
into a caller buffer using a caller-supplied size without first
checking that size against the local, fixed-size response buffer.
Also use the caller's own size value directly for the final memcpy
in tf_msg_get_global_cfg() and tf_msg_get_if_tbl_entry() instead of
a re-derived field, avoiding any possible mismatch between the two.

Fixes: e2a002d88c44 ("net/bnxt: update RM to support HCAPI only")
Fixes: a11f87d3b2ca ("net/bnxt: add global config set and get functions")
Fixes: 37ff91c158a3 ("net/bnxt: add SRAM manager model")
Cc: stable@dpdk.org

Signed-off-by: Farah Smith <farah.smith@broadcom.com>
Signed-off-by: Manish Kurup <manish.kurup@broadcom.com>
---
 drivers/net/bnxt/tf_core/tf_msg.c | 13 +++++++++++--
 1 file changed, 11 insertions(+), 2 deletions(-)

diff --git a/drivers/net/bnxt/tf_core/tf_msg.c b/drivers/net/bnxt/tf_core/tf_msg.c
index 645a4b1e66..aab8d05d81 100644
--- a/drivers/net/bnxt/tf_core/tf_msg.c
+++ b/drivers/net/bnxt/tf_core/tf_msg.c
@@ -1406,6 +1406,9 @@ tf_msg_get_tbl_entry(struct tf *tfp,
 	struct tf_session *tfs;
 	uint32_t flags = 0;
 
+	if (size > sizeof(resp.data))
+		return -EINVAL;
+
 	/* Retrieve the session information */
 	rc = tf_session_get_session_internal(tfp, &tfs);
 	if (rc) {
@@ -1493,6 +1496,9 @@ tf_msg_get_global_cfg(struct tf *tfp,
 	struct tf_dev_info *dev;
 	struct tf_session *tfs;
 
+	if (params->config_sz_in_bytes > sizeof(resp.data))
+		return -EINVAL;
+
 	/* Retrieve the session information */
 	rc = tf_session_get_session_internal(tfp, &tfs);
 	if (rc) {
@@ -1552,7 +1558,7 @@ tf_msg_get_global_cfg(struct tf *tfp,
 	if (params->config)
 		tfp_memcpy(params->config,
 			   resp.data,
-			   resp_size);
+			   params->config_sz_in_bytes);
 	else
 		return -EFAULT;
 
@@ -1746,6 +1752,9 @@ tf_msg_get_if_tbl_entry(struct tf *tfp,
 	struct tf_dev_info *dev;
 	struct tf_session *tfs;
 
+	if (params->data_sz_in_bytes > sizeof(resp.data))
+		return -EINVAL;
+
 	/* Retrieve the session information */
 	rc = tf_session_get_session(tfp, &tfs);
 	if (rc) {
@@ -1790,7 +1799,7 @@ tf_msg_get_if_tbl_entry(struct tf *tfp,
 	if (rc != 0)
 		return rc;
 
-	tfp_memcpy(&params->data[0], resp.data, req.size);
+	tfp_memcpy(&params->data[0], resp.data, params->data_sz_in_bytes);
 
 	return 0;
 }
-- 
2.31.1


                 reply	other threads:[~2026-10-05 20:25 UTC|newest]

Thread overview: [no followups] expand[flat|nested]  mbox.gz  Atom feed

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20261005202507.17770-1-manish.kurup@broadcom.com \
    --to=manish.kurup@broadcom.com \
    --cc=dev@dpdk.org \
    --cc=farah.smith@broadcom.com \
    --cc=kishore.padmanabha@broadcom.com \
    --cc=stable@dpdk.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox