DPDK-dev Archive on lore.kernel.org
 help / color / mirror / Atom feed
* [PATCH] net/bnxt: add response bounds checks for TruFlow messages
@ 2026-10-05 20:25 Manish Kurup
  0 siblings, 0 replies; only message in thread
From: Manish Kurup @ 2026-10-05 20:25 UTC (permalink / raw)
  To: dev; +Cc: kishore.padmanabha, Farah Smith, stable

From: Farah Smith <farah.smith@broadcom.com>

Add explicit input validation against fixed response data buffer
sizes in TruFlow message getters. This prevents potential stack
over-reads if a caller passes a requested size exceeding the local
response buffer size.

Add the same guard to tf_msg_get_tbl_entry(), tf_msg_get_global_cfg(),
and tf_msg_get_if_tbl_entry() - each copies firmware response data
into a caller buffer using a caller-supplied size without first
checking that size against the local, fixed-size response buffer.
Also use the caller's own size value directly for the final memcpy
in tf_msg_get_global_cfg() and tf_msg_get_if_tbl_entry() instead of
a re-derived field, avoiding any possible mismatch between the two.

Fixes: e2a002d88c44 ("net/bnxt: update RM to support HCAPI only")
Fixes: a11f87d3b2ca ("net/bnxt: add global config set and get functions")
Fixes: 37ff91c158a3 ("net/bnxt: add SRAM manager model")
Cc: stable@dpdk.org

Signed-off-by: Farah Smith <farah.smith@broadcom.com>
Signed-off-by: Manish Kurup <manish.kurup@broadcom.com>
---
 drivers/net/bnxt/tf_core/tf_msg.c | 13 +++++++++++--
 1 file changed, 11 insertions(+), 2 deletions(-)

diff --git a/drivers/net/bnxt/tf_core/tf_msg.c b/drivers/net/bnxt/tf_core/tf_msg.c
index 645a4b1e66..aab8d05d81 100644
--- a/drivers/net/bnxt/tf_core/tf_msg.c
+++ b/drivers/net/bnxt/tf_core/tf_msg.c
@@ -1406,6 +1406,9 @@ tf_msg_get_tbl_entry(struct tf *tfp,
 	struct tf_session *tfs;
 	uint32_t flags = 0;
 
+	if (size > sizeof(resp.data))
+		return -EINVAL;
+
 	/* Retrieve the session information */
 	rc = tf_session_get_session_internal(tfp, &tfs);
 	if (rc) {
@@ -1493,6 +1496,9 @@ tf_msg_get_global_cfg(struct tf *tfp,
 	struct tf_dev_info *dev;
 	struct tf_session *tfs;
 
+	if (params->config_sz_in_bytes > sizeof(resp.data))
+		return -EINVAL;
+
 	/* Retrieve the session information */
 	rc = tf_session_get_session_internal(tfp, &tfs);
 	if (rc) {
@@ -1552,7 +1558,7 @@ tf_msg_get_global_cfg(struct tf *tfp,
 	if (params->config)
 		tfp_memcpy(params->config,
 			   resp.data,
-			   resp_size);
+			   params->config_sz_in_bytes);
 	else
 		return -EFAULT;
 
@@ -1746,6 +1752,9 @@ tf_msg_get_if_tbl_entry(struct tf *tfp,
 	struct tf_dev_info *dev;
 	struct tf_session *tfs;
 
+	if (params->data_sz_in_bytes > sizeof(resp.data))
+		return -EINVAL;
+
 	/* Retrieve the session information */
 	rc = tf_session_get_session(tfp, &tfs);
 	if (rc) {
@@ -1790,7 +1799,7 @@ tf_msg_get_if_tbl_entry(struct tf *tfp,
 	if (rc != 0)
 		return rc;
 
-	tfp_memcpy(&params->data[0], resp.data, req.size);
+	tfp_memcpy(&params->data[0], resp.data, params->data_sz_in_bytes);
 
 	return 0;
 }
-- 
2.31.1


^ permalink raw reply related	[flat|nested] only message in thread

only message in thread, other threads:[~2026-10-05 20:25 UTC | newest]

Thread overview: (only message) (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-10-05 20:25 [PATCH] net/bnxt: add response bounds checks for TruFlow messages Manish Kurup

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox