From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 6A4644FE2F2; Wed, 30 Sep 2026 15:37:46 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790782672; cv=none; b=Q8sp/XJZvvHobmT4yKp9/wUK4SO3xFth6Pqu5cmHGyndqVjKrBOAJ/fRIknw3CeVWrJREPLehFU2QeSK2fEOmNULobpu+RjJgROhjYPJI5oTyzRkQGEZl3wF0eSaIlSiIxKhdjSu76/6ViZaFS4YKCiti2wKvaYJEMHMTKfw36k= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790782672; c=relaxed/simple; bh=6aF2WKVRRu1aSwNG92CPKjzN9cselWmBgaFJflFy0uU=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=lXnrut/xMGkCUSwIHIhort++INOlPqLmjPT+9kc7LbXcNLd6TV7VyLSx+AU1TTOsmtW8R16h/6FL4o3u5a+Jk9aR4YUHr3/TMU559hj/RVZipSkAmvZCbqLtC41mRedIJ6rLnaOQTiMKj96+ARzUI99yKjWdWhlk53yTsaz/pbk= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=YaQ9PWc3; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="YaQ9PWc3" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 3FC231F00899; Wed, 30 Sep 2026 15:37:43 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxfoundation.org; s=korg; t=1790782663; bh=8HNMwz+s/C+iYu1K05BS3WiwJ/JMAZ8wcS2ppvZWP1c=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=YaQ9PWc3mQ09/LnAqwRFMa+JEGwxqJKt7CY92kD+wZgrNSx4CVBLUsMKHauoKAdoV 2Ew3wXzGlZFZVvSCaAkV2cYfaijY48rDYw4rlzPzY56LCagDdRqUm5Xxu6rS8aLFgi nYOHqcM7r56XVnIR9IqFE3ISAkG0zOsnDTjtmi+o= From: Greg Kroah-Hartman To: stable@vger.kernel.org Cc: Greg Kroah-Hartman , patches@lists.linux.dev, Iskhakov Daniil , Agalakov Daniil , Avigail Dahan , Tony Nguyen , Jakub Kicinski , Sasha Levin Subject: [PATCH 5.10 127/595] e1000e: limit endianness conversion to boundary words Date: Wed, 30 Sep 2026 17:20:20 +0200 Message-ID: <20260930152350.470164964@linuxfoundation.org> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260930152347.700140858@linuxfoundation.org> References: <20260930152347.700140858@linuxfoundation.org> User-Agent: quilt/0.69 X-stable: review X-Patchwork-Hint: ignore Precedence: bulk X-Mailing-List: patches@lists.linux.dev List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit 5.10-stable review patch. If anyone has any objections, please let me know. ------------------ From: Agalakov Daniil [ Upstream commit a5ecafcfb27baf2dba766c4fd99dbb947f4e85d8 ] [Why] In e1000_set_eeprom(), the eeprom_buff is allocated to hold a range of words. However, only the boundary words (the first and the last) are populated from the EEPROM if the write request is not word-aligned. The words in the middle of the buffer remain uninitialized because they are intended to be completely overwritten by the new data via memcpy(). The previous implementation had a loop that performed le16_to_cpus() on the entire buffer. This resulted in endianness conversion being performed on uninitialized memory for all interior words. Fix this by converting the endianness only for the boundary words immediately after they are successfully read from the EEPROM. Found by Linux Verification Center (linuxtesting.org) with SVACE. Co-developed-by: Iskhakov Daniil Signed-off-by: Iskhakov Daniil Signed-off-by: Agalakov Daniil Tested-by: Avigail Dahan Signed-off-by: Tony Nguyen Link: https://patch.msgid.link/20260609213559.178657-14-anthony.l.nguyen@intel.com Signed-off-by: Jakub Kicinski Signed-off-by: Sasha Levin --- drivers/net/ethernet/intel/e1000e/ethtool.c | 19 ++++++++++++------- 1 file changed, 12 insertions(+), 7 deletions(-) diff --git a/drivers/net/ethernet/intel/e1000e/ethtool.c b/drivers/net/ethernet/intel/e1000e/ethtool.c index 4aca854783e2d..fe2e0ba7d434a 100644 --- a/drivers/net/ethernet/intel/e1000e/ethtool.c +++ b/drivers/net/ethernet/intel/e1000e/ethtool.c @@ -597,20 +597,25 @@ static int e1000_set_eeprom(struct net_device *netdev, /* need read/modify/write of first changed EEPROM word */ /* only the second byte of the word is being modified */ ret_val = e1000_read_nvm(hw, first_word, 1, &eeprom_buff[0]); + if (ret_val) + goto out; + + /* Device's eeprom is always little-endian, word addressable */ + le16_to_cpus(&eeprom_buff[0]); + ptr++; } - if (((eeprom->offset + eeprom->len) & 1) && (!ret_val)) + if ((eeprom->offset + eeprom->len) & 1) { /* need read/modify/write of last changed EEPROM word */ /* only the first byte of the word is being modified */ ret_val = e1000_read_nvm(hw, last_word, 1, &eeprom_buff[last_word - first_word]); + if (ret_val) + goto out; - if (ret_val) - goto out; - - /* Device's eeprom is always little-endian, word addressable */ - for (i = 0; i < last_word - first_word + 1; i++) - le16_to_cpus(&eeprom_buff[i]); + /* Device's eeprom is always little-endian, word addressable */ + le16_to_cpus(&eeprom_buff[last_word - first_word]); + } memcpy(ptr, bytes, eeprom->len); -- 2.53.0