Linux RDMA and InfiniBand development
 help / color / mirror / Atom feed
* [PATCH] RDMA/mana_ib: Prevent array underflow in mana_ib_create_qp_raw()
@ 2023-01-24 15:20 Dan Carpenter
  2023-01-24 18:54 ` Long Li
                   ` (2 more replies)
  0 siblings, 3 replies; 9+ messages in thread
From: Dan Carpenter @ 2023-01-24 15:20 UTC (permalink / raw)
  To: Long Li
  Cc: Ajay Sharma, Jason Gunthorpe, Leon Romanovsky, Dexuan Cui,
	linux-rdma, kernel-janitors

The "port" comes from the user and if it is zero then the:

	ndev = mc->ports[port - 1];

assignment does an out of bounds read.  I have changed the if
statement to fix this and to mirror how it is done in
mana_ib_create_qp_rss().

Fixes: 0266a177631d ("RDMA/mana_ib: Add a driver for Microsoft Azure Network Adapter")
Signed-off-by: Dan Carpenter <error27@gmail.com>
---
 drivers/infiniband/hw/mana/qp.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/drivers/infiniband/hw/mana/qp.c b/drivers/infiniband/hw/mana/qp.c
index ea15ec77e321..54b61930a7fd 100644
--- a/drivers/infiniband/hw/mana/qp.c
+++ b/drivers/infiniband/hw/mana/qp.c
@@ -289,7 +289,7 @@ static int mana_ib_create_qp_raw(struct ib_qp *ibqp, struct ib_pd *ibpd,
 
 	/* IB ports start with 1, MANA Ethernet ports start with 0 */
 	port = ucmd.port;
-	if (ucmd.port > mc->num_ports)
+	if (port < 1 || port > mc->num_ports)
 		return -EINVAL;
 
 	if (attr->cap.max_send_wr > MAX_SEND_BUFFERS_PER_QUEUE) {
-- 
2.35.1


^ permalink raw reply related	[flat|nested] 9+ messages in thread

end of thread, other threads:[~2023-02-02  8:39 UTC | newest]

Thread overview: 9+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2023-01-24 15:20 [PATCH] RDMA/mana_ib: Prevent array underflow in mana_ib_create_qp_raw() Dan Carpenter
2023-01-24 18:54 ` Long Li
2023-01-26 10:18 ` Leon Romanovsky
2023-01-26 11:00   ` Dan Carpenter
2023-01-26 12:18     ` Leon Romanovsky
2023-01-27  6:41       ` Long Li
2023-01-29 11:27         ` Leon Romanovsky
2023-02-02  8:39           ` Leon Romanovsky
2023-02-02  8:39 ` Leon Romanovsky

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox