From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 427B7409283; Thu, 17 Sep 2026 18:01:15 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789668076; cv=none; b=Gu5BHgiBGxut7BUkK4CMAJqMJHIh5r0VwS7PR/91hbtB4+3iKJ0biJvpVUSfv14hoN3Orq48HlSJzvNuc+Mr2Eg31Uu4jzlFATyyuqwXeqGewQk4Qpi5YSiCE1CN5T+UsKMLAiH503s5ii4DldyBlVdQf0bimZq9E4qYqht1iC4= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789668076; c=relaxed/simple; bh=qXt8PU20567dyclQFOpx2JT9FjIH3Ev7zno67jCiHZs=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=fV4BT7adK6a+XCsUEHRfXbRiYgxPrSwMYzrKAKn8UkAvv77rr5LrjwurOModeHB/zUxpsJmDgr1MHrkpGSyTGjb1lnEvd/n4r2E9Kchjb4cud81X+kF7gFB7A0M8Z4Px+05Pz4gsGsQf5ETjr3IdmPyHZ2/krdLeK7asqsXGGN8= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=Vjqo8Ahc; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="Vjqo8Ahc" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 9E23F1F000FF; Thu, 17 Sep 2026 18:01:14 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxfoundation.org; s=korg; t=1789668075; bh=FH9ZozArJhWrO0JO+rwb2awezIbFV4MX80eZoDsuGZs=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=Vjqo8AhcRkba39maWqhV3gusTgNmMYWmoiUbtSfp4knKQjsqQ/R4wIAYlnahyYlbg NBW75LKeHoy+jEsXiy/cJ3uFlYMeoWCbzZ0NYg1GRrqHt8+3wz3qKoOCaMMQB0hYMo fZydEgOuEFKzQiD6HPDTb7ifsfsitc4qNTozS8D0= From: Greg Kroah-Hartman To: stable@vger.kernel.org Cc: Greg Kroah-Hartman , patches@lists.linux.dev, Iskhakov Daniil , Agalakov Daniil , Avigail Dahan , Tony Nguyen , Jakub Kicinski , Sasha Levin Subject: [PATCH 6.12 0305/1102] e1000e: limit endianness conversion to boundary words Date: Thu, 17 Sep 2026 16:04:08 +0100 Message-ID: <20260917151547.278197555@linuxfoundation.org> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260917151539.408551884@linuxfoundation.org> References: <20260917151539.408551884@linuxfoundation.org> User-Agent: quilt/0.69 X-stable: review X-Patchwork-Hint: ignore Precedence: bulk X-Mailing-List: patches@lists.linux.dev List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit 6.12-stable review patch. If anyone has any objections, please let me know. ------------------ From: Agalakov Daniil [ Upstream commit a5ecafcfb27baf2dba766c4fd99dbb947f4e85d8 ] [Why] In e1000_set_eeprom(), the eeprom_buff is allocated to hold a range of words. However, only the boundary words (the first and the last) are populated from the EEPROM if the write request is not word-aligned. The words in the middle of the buffer remain uninitialized because they are intended to be completely overwritten by the new data via memcpy(). The previous implementation had a loop that performed le16_to_cpus() on the entire buffer. This resulted in endianness conversion being performed on uninitialized memory for all interior words. Fix this by converting the endianness only for the boundary words immediately after they are successfully read from the EEPROM. Found by Linux Verification Center (linuxtesting.org) with SVACE. Co-developed-by: Iskhakov Daniil Signed-off-by: Iskhakov Daniil Signed-off-by: Agalakov Daniil Tested-by: Avigail Dahan Signed-off-by: Tony Nguyen Link: https://patch.msgid.link/20260609213559.178657-14-anthony.l.nguyen@intel.com Signed-off-by: Jakub Kicinski Signed-off-by: Sasha Levin --- drivers/net/ethernet/intel/e1000e/ethtool.c | 19 ++++++++++++------- 1 file changed, 12 insertions(+), 7 deletions(-) diff --git a/drivers/net/ethernet/intel/e1000e/ethtool.c b/drivers/net/ethernet/intel/e1000e/ethtool.c index 641a36dd0e604..e4de9bb2444c1 100644 --- a/drivers/net/ethernet/intel/e1000e/ethtool.c +++ b/drivers/net/ethernet/intel/e1000e/ethtool.c @@ -585,20 +585,25 @@ static int e1000_set_eeprom(struct net_device *netdev, /* need read/modify/write of first changed EEPROM word */ /* only the second byte of the word is being modified */ ret_val = e1000_read_nvm(hw, first_word, 1, &eeprom_buff[0]); + if (ret_val) + goto out; + + /* Device's eeprom is always little-endian, word addressable */ + le16_to_cpus(&eeprom_buff[0]); + ptr++; } - if (((eeprom->offset + eeprom->len) & 1) && (!ret_val)) + if ((eeprom->offset + eeprom->len) & 1) { /* need read/modify/write of last changed EEPROM word */ /* only the first byte of the word is being modified */ ret_val = e1000_read_nvm(hw, last_word, 1, &eeprom_buff[last_word - first_word]); + if (ret_val) + goto out; - if (ret_val) - goto out; - - /* Device's eeprom is always little-endian, word addressable */ - for (i = 0; i < last_word - first_word + 1; i++) - le16_to_cpus(&eeprom_buff[i]); + /* Device's eeprom is always little-endian, word addressable */ + le16_to_cpus(&eeprom_buff[last_word - first_word]); + } memcpy(ptr, bytes, eeprom->len); -- 2.53.0