* [PATCH] net/bnxt: add response bounds checks for TruFlow messages
@ 2026-10-05 20:25 Manish Kurup
0 siblings, 0 replies; only message in thread
From: Manish Kurup @ 2026-10-05 20:25 UTC (permalink / raw)
To: dev; +Cc: kishore.padmanabha, Farah Smith, stable
From: Farah Smith <farah.smith@broadcom.com>
Add explicit input validation against fixed response data buffer
sizes in TruFlow message getters. This prevents potential stack
over-reads if a caller passes a requested size exceeding the local
response buffer size.
Add the same guard to tf_msg_get_tbl_entry(), tf_msg_get_global_cfg(),
and tf_msg_get_if_tbl_entry() - each copies firmware response data
into a caller buffer using a caller-supplied size without first
checking that size against the local, fixed-size response buffer.
Also use the caller's own size value directly for the final memcpy
in tf_msg_get_global_cfg() and tf_msg_get_if_tbl_entry() instead of
a re-derived field, avoiding any possible mismatch between the two.
Fixes: e2a002d88c44 ("net/bnxt: update RM to support HCAPI only")
Fixes: a11f87d3b2ca ("net/bnxt: add global config set and get functions")
Fixes: 37ff91c158a3 ("net/bnxt: add SRAM manager model")
Cc: stable@dpdk.org
Signed-off-by: Farah Smith <farah.smith@broadcom.com>
Signed-off-by: Manish Kurup <manish.kurup@broadcom.com>
---
drivers/net/bnxt/tf_core/tf_msg.c | 13 +++++++++++--
1 file changed, 11 insertions(+), 2 deletions(-)
diff --git a/drivers/net/bnxt/tf_core/tf_msg.c b/drivers/net/bnxt/tf_core/tf_msg.c
index 645a4b1e66..aab8d05d81 100644
--- a/drivers/net/bnxt/tf_core/tf_msg.c
+++ b/drivers/net/bnxt/tf_core/tf_msg.c
@@ -1406,6 +1406,9 @@ tf_msg_get_tbl_entry(struct tf *tfp,
struct tf_session *tfs;
uint32_t flags = 0;
+ if (size > sizeof(resp.data))
+ return -EINVAL;
+
/* Retrieve the session information */
rc = tf_session_get_session_internal(tfp, &tfs);
if (rc) {
@@ -1493,6 +1496,9 @@ tf_msg_get_global_cfg(struct tf *tfp,
struct tf_dev_info *dev;
struct tf_session *tfs;
+ if (params->config_sz_in_bytes > sizeof(resp.data))
+ return -EINVAL;
+
/* Retrieve the session information */
rc = tf_session_get_session_internal(tfp, &tfs);
if (rc) {
@@ -1552,7 +1558,7 @@ tf_msg_get_global_cfg(struct tf *tfp,
if (params->config)
tfp_memcpy(params->config,
resp.data,
- resp_size);
+ params->config_sz_in_bytes);
else
return -EFAULT;
@@ -1746,6 +1752,9 @@ tf_msg_get_if_tbl_entry(struct tf *tfp,
struct tf_dev_info *dev;
struct tf_session *tfs;
+ if (params->data_sz_in_bytes > sizeof(resp.data))
+ return -EINVAL;
+
/* Retrieve the session information */
rc = tf_session_get_session(tfp, &tfs);
if (rc) {
@@ -1790,7 +1799,7 @@ tf_msg_get_if_tbl_entry(struct tf *tfp,
if (rc != 0)
return rc;
- tfp_memcpy(¶ms->data[0], resp.data, req.size);
+ tfp_memcpy(¶ms->data[0], resp.data, params->data_sz_in_bytes);
return 0;
}
--
2.31.1
^ permalink raw reply related [flat|nested] only message in thread
only message in thread, other threads:[~2026-10-05 20:25 UTC | newest]
Thread overview: (only message) (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-10-05 20:25 [PATCH] net/bnxt: add response bounds checks for TruFlow messages Manish Kurup
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox