From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-oi1-f200.google.com (mail-oi1-f200.google.com [209.85.167.200]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 6D31E331EC0 for ; Mon, 10 Aug 2026 04:35:50 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.167.200 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786336551; cv=none; b=E0xy87itm5CIF68qi2G7vluzrjJY6GTsZb4uux2eeO7tgPfibsoWCfTlvCGp51ku3kHkkxxhLzqv0GUAaLIHWKM5eLfSH/Ld6vE4rohAqoXFSAVp20st52F8IGdwDpuIe9XIk7wPjOthQHbXatwf1pgB97Ty1Mv0LuIIwyOKY7k= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786336551; c=relaxed/simple; bh=Dzx2Yl7ovm9zPLZ/Y4dqzsn8LUcHU+tqQ1+LE0TMnq4=; h=MIME-Version:Date:In-Reply-To:Message-ID:Subject:From:To: Content-Type; b=Sc8PEN8M7kwp07nygV+qxd0oMRo3W2hDpNpNQOOJcl4MDZDDZlnDXBQD/zMv+z2jVI2wr1Qw9aiRuXZHX66uU5CKrR+o9WRPmPH91av2IRo3snGxlynKt0QAiR3bLWVls+vj1M1VaQH2tY69ROimqnAgSWC4NF3yUGsZZ5+rYIw= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=fail (p=none dis=none) header.from=syzkaller.appspotmail.com; spf=pass smtp.mailfrom=M3KW2WVRGUFZ5GODRSRYTGD7.apphosting.bounces.google.com; arc=none smtp.client-ip=209.85.167.200 Authentication-Results: smtp.subspace.kernel.org; dmarc=fail (p=none dis=none) header.from=syzkaller.appspotmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=M3KW2WVRGUFZ5GODRSRYTGD7.apphosting.bounces.google.com Received: by mail-oi1-f200.google.com with SMTP id 5614622812f47-4ad778bacbeso1961772b6e.1 for ; Sun, 09 Aug 2026 21:35:50 -0700 (PDT) X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1786336549; x=1786941349; h=content-type:to:from:subject:message-id:in-reply-to:date :mime-version:x-gm-message-state:from:to:cc:subject:date:message-id :reply-to:content-type; bh=9VV5d8kn0cK2dTyY402PqgD/Ww7ntU85N5Od+/wYC6g=; b=ND/4kWx3pa+8Z8xqg0yHUI+cFRp+Aiin2cPJ9rn5kq3STco0QBjVeTzC1yudCo+3v/ FLoiWOE2tTipMSNCcHvo3EltGz7ZLFlaYkEcXH5Ha00lx70juhJSsMm7GPwSdzHTog0R ErpGl1JErUETdGXQ9jWD30f4DQ1O5bNjHpIjuCjpgQ0FpEQpxSt4vChOCAHydPR/KvEz mTGD2uFOexGpvmy0UV2B5H82uDo9zebJIoR+w5Jyy5Sm0gXYPzWfnXHmI1FutvqrmHAP mcCk4WNV4h118j12q5wG30wvjsSXQmY90X8Jc++AG4Yw6VzIkjnPCx30Z1bz5Kv++EQu MiKQ== X-Gm-Message-State: AOJu0YyQZzga0DHWA2n7nwqVLsIi2rMZg2briXsWu4Upc8ISj0DMOna4 OBsgpFhBTIzE6K5RI1NeZjnknGt4+lO9iRvLsAgt90p0WfR6Pgg9mtXURoraiDXVCEOHqc0SiGj XCb3YOvBuwwb/p9dPDaMMmT/7pmivh9jtJwrGV4FWQE/ne3bjWMAud1SRoMc= Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 X-Received: by 2002:a05:6808:1512:b0:496:e0:a47b with SMTP id 5614622812f47-4b1aba7f07cmr9133723b6e.20.1786336549445; Sun, 09 Aug 2026 21:35:49 -0700 (PDT) Date: Sun, 09 Aug 2026 21:35:49 -0700 In-Reply-To: <6a74aa04.01d0871a.3a0d52.0025.GAE@google.com> X-Google-Appengine-App-Id: s~syzkaller X-Google-Appengine-App-Id-Alias: syzkaller Message-ID: <6a795525.b50370da.49fe0.004c.GAE@google.com> Subject: Forwarded: [PATCH net] e100: fix shift-out-of-bounds in e100_eeprom_load() From: syzbot To: linux-kernel@vger.kernel.org, syzkaller-bugs@googlegroups.com Content-Type: text/plain; charset="UTF-8" For archival purposes, forwarding an incoming command email to linux-kernel@vger.kernel.org, syzkaller-bugs@googlegroups.com. *** Subject: [PATCH net] e100: fix shift-out-of-bounds in e100_eeprom_load() Author: malathi.a2000@gmail.com #syz test: git://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git f9a2394a23482bfd330911e9c8295b71724feacd e100_eeprom_load() and e100_eeprom_save() start with an address length of 8 and call e100_eeprom_read() to auto-detect the real EEPROM address length. e100_eeprom_read() adjusts the length with *addr_len -= (i - 16); based on when the EEPROM drives a dummy zero onto EEDO. A malfunctioning or emulated device that drives EEDO low too early makes (i - 16) exceed the current length, underflowing the u16 addr_len to a large value such as 65529. That value is then used as a shift count: nic->eeprom_wc = 1 << addr_len; which is undefined behaviour and additionally overflows the fixed-size nic->eeprom[256] cache. UBSAN: shift-out-of-bounds in drivers/net/ethernet/intel/e100.c:768:21 shift exponent 65529 is too large for 32-bit type 'int' The EEPROM cache holds at most 256 words, so a valid address length is never larger than 8. Reject larger values before using addr_len. Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2") Reported-by: syzbot+e0abb1d45ac291ebebeb@syzkaller.appspotmail.com Closes: https://syzkaller.appspot.com/bug?extid=e0abb1d45ac291ebebeb Signed-off-by: Malathi --- drivers/net/ethernet/intel/e100.c | 10 ++++++++++ 1 file changed, 10 insertions(+) diff --git a/drivers/net/ethernet/intel/e100.c b/drivers/net/ethernet/intel/e100.c index 29960762e64a..a236273f5e65 100644 --- a/drivers/net/ethernet/intel/e100.c +++ b/drivers/net/ethernet/intel/e100.c @@ -765,6 +765,11 @@ static int e100_eeprom_load(struct nic *nic) /* Try reading with an 8-bit addr len to discover actual addr len */ e100_eeprom_read(nic, &addr_len, 0); + if (addr_len > 8) { + netif_err(nic, probe, nic->netdev, + "invalid EEPROM address length %u\n", addr_len); + return -EINVAL; + } nic->eeprom_wc = 1 << addr_len; for (addr = 0; addr < nic->eeprom_wc; addr++) { @@ -791,6 +796,11 @@ static int e100_eeprom_save(struct nic *nic, u16 start, u16 count) /* Try reading with an 8-bit addr len to discover actual addr len */ e100_eeprom_read(nic, &addr_len, 0); + if (addr_len > 8) { + netif_err(nic, probe, nic->netdev, + "invalid EEPROM address length %u\n", addr_len); + return -EINVAL; + } nic->eeprom_wc = 1 << addr_len; if (start + count >= nic->eeprom_wc) -- 2.43.0