From: syzbot <syzbot+e0abb1d45ac291ebebeb@syzkaller.appspotmail.com>
To: linux-kernel@vger.kernel.org, syzkaller-bugs@googlegroups.com
Subject: Forwarded: [PATCH net] e100: fix shift-out-of-bounds in e100_eeprom_load()
Date: Sun, 09 Aug 2026 21:35:49 -0700 [thread overview]
Message-ID: <6a795525.b50370da.49fe0.004c.GAE@google.com> (raw)
In-Reply-To: <6a74aa04.01d0871a.3a0d52.0025.GAE@google.com>
For archival purposes, forwarding an incoming command email to
linux-kernel@vger.kernel.org, syzkaller-bugs@googlegroups.com.
***
Subject: [PATCH net] e100: fix shift-out-of-bounds in e100_eeprom_load()
Author: malathi.a2000@gmail.com
#syz test: git://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git f9a2394a23482bfd330911e9c8295b71724feacd
e100_eeprom_load() and e100_eeprom_save() start with an address length
of 8 and call e100_eeprom_read() to auto-detect the real EEPROM address
length. e100_eeprom_read() adjusts the length with
*addr_len -= (i - 16);
based on when the EEPROM drives a dummy zero onto EEDO. A malfunctioning
or emulated device that drives EEDO low too early makes (i - 16) exceed
the current length, underflowing the u16 addr_len to a large value such
as 65529.
That value is then used as a shift count:
nic->eeprom_wc = 1 << addr_len;
which is undefined behaviour and additionally overflows the fixed-size
nic->eeprom[256] cache.
UBSAN: shift-out-of-bounds in drivers/net/ethernet/intel/e100.c:768:21
shift exponent 65529 is too large for 32-bit type 'int'
The EEPROM cache holds at most 256 words, so a valid address length is
never larger than 8. Reject larger values before using addr_len.
Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
Reported-by: syzbot+e0abb1d45ac291ebebeb@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=e0abb1d45ac291ebebeb
Signed-off-by: Malathi <malathi.a2000@gmail.com>
---
drivers/net/ethernet/intel/e100.c | 10 ++++++++++
1 file changed, 10 insertions(+)
diff --git a/drivers/net/ethernet/intel/e100.c b/drivers/net/ethernet/intel/e100.c
index 29960762e64a..a236273f5e65 100644
--- a/drivers/net/ethernet/intel/e100.c
+++ b/drivers/net/ethernet/intel/e100.c
@@ -765,6 +765,11 @@ static int e100_eeprom_load(struct nic *nic)
/* Try reading with an 8-bit addr len to discover actual addr len */
e100_eeprom_read(nic, &addr_len, 0);
+ if (addr_len > 8) {
+ netif_err(nic, probe, nic->netdev,
+ "invalid EEPROM address length %u\n", addr_len);
+ return -EINVAL;
+ }
nic->eeprom_wc = 1 << addr_len;
for (addr = 0; addr < nic->eeprom_wc; addr++) {
@@ -791,6 +796,11 @@ static int e100_eeprom_save(struct nic *nic, u16 start, u16 count)
/* Try reading with an 8-bit addr len to discover actual addr len */
e100_eeprom_read(nic, &addr_len, 0);
+ if (addr_len > 8) {
+ netif_err(nic, probe, nic->netdev,
+ "invalid EEPROM address length %u\n", addr_len);
+ return -EINVAL;
+ }
nic->eeprom_wc = 1 << addr_len;
if (start + count >= nic->eeprom_wc)
--
2.43.0
prev parent reply other threads:[~2026-08-10 4:35 UTC|newest]
Thread overview: 3+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-06 15:36 [syzbot] [intel-wired-lan?] UBSAN: shift-out-of-bounds in e100_eeprom_load syzbot
2026-08-07 13:46 ` Forwarded: [PATCH] e100: prevent shift out-of-bounds " syzbot
2026-08-10 4:35 ` syzbot [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=6a795525.b50370da.49fe0.004c.GAE@google.com \
--to=syzbot+e0abb1d45ac291ebebeb@syzkaller.appspotmail.com \
--cc=linux-kernel@vger.kernel.org \
--cc=syzkaller-bugs@googlegroups.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox