From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from relay.smtp-ext.broadcom.com (relay.smtp-ext.broadcom.com [192.19.144.205]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id A500943F0BB; Thu, 8 Oct 2026 21:07:34 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=192.19.144.205 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1791493657; cv=none; b=TSF0VokSQjDZedyvMAnPiE2Lk2qhPicrmwGavWkTypTxW3s2cS7TbdzYYS68H8H1NFkl1+HCwDZ6jPPFzXDTpSNR1LsHwtfDoc3gu94Mm6hLDyMCZjVHN3xQwlWF1agu4Pr76YSxoNw/GDL6AE05bLbSQNX+JTP9wuGRu0q0YXs= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1791493657; c=relaxed/simple; bh=gIKbUDJZEVTa9ybRdg4BYuW1Zqqjkz+OubBavqSUHkw=; h=From:To:Cc:Subject:Date:Message-Id:In-Reply-To:References: MIME-Version; b=NsaeJRcGNUpzyp/SN9YZzyQhkvSTMW79qSeKGtsYKnxn/yjxdbUhCPHvyuuRgsKbaOOs/XBXtsZprQRxSUu3RnhPufB22q2PPhnGmC8Vz9V9P4h+6M34bJenkyOlWlvyrN86156FVzSJ0oz8L1SEx4WWMpewgaoPB8zzDfExi9c= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=broadcom.com; spf=fail smtp.mailfrom=broadcom.com; dkim=pass (1024-bit key) header.d=broadcom.com header.i=@broadcom.com header.b=bZuc3y09; arc=none smtp.client-ip=192.19.144.205 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=broadcom.com Authentication-Results: smtp.subspace.kernel.org; spf=fail smtp.mailfrom=broadcom.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=broadcom.com header.i=@broadcom.com header.b="bZuc3y09" Received: from mail-lvn-it-01.broadcom.com (mail-lvn-it-01.lvn.broadcom.net [10.36.132.253]) by relay.smtp-ext.broadcom.com (Postfix) with ESMTP id 960E8C0000F9; Thu, 8 Oct 2026 14:07:27 -0700 (PDT) DKIM-Filter: OpenDKIM Filter v2.11.0 relay.smtp-ext.broadcom.com 960E8C0000F9 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=broadcom.com; s=dkimrelay; t=1791493647; bh=gIKbUDJZEVTa9ybRdg4BYuW1Zqqjkz+OubBavqSUHkw=; h=From:To:Cc:Subject:Date:In-Reply-To:References:From; b=bZuc3y09wYaOwP9OQ7Q5xARm/MC1TWH+jZdPzG42bi68bgj5SLSnCnJrsd/2jGVwT qb+WLHkPIICGjBAutRHmqooXa5y+3YQPszyUBAHRuKoz3g5YZWUJwdzcqqThcbM5DD olXqctD3+3AWmEZa9ttms6ba8DD+kkn/KQwJCSIs= Received: from stbirv-lnx-1.igp.broadcom.net (stbirv-lnx-1.igp.broadcom.net [10.67.48.32]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (2048 bits) server-digest SHA256) (No client certificate requested) by mail-lvn-it-01.broadcom.com (Postfix) with ESMTPSA id 3CC51A83; Thu, 8 Oct 2026 14:07:27 -0700 (PDT) From: Florian Fainelli To: netdev@vger.kernel.org Cc: Florian Fainelli , Doug Berger , Broadcom internal kernel review list , Andrew Lunn , "David S. Miller" , Eric Dumazet , Jakub Kicinski , Paolo Abeni , Zak Kemble , Simon Horman , Ryo Takakura , linux-kernel@vger.kernel.org (open list), Nicolai Buchwitz Subject: [PATCH net v2 3/6] net: bcmasp: validate minimum RX packet size in bcmasp_rx_poll() Date: Thu, 8 Oct 2026 14:06:18 -0700 Message-Id: <20261008210621.1374785-4-florian.fainelli@broadcom.com> X-Mailer: git-send-email 2.34.1 In-Reply-To: <20261008210621.1374785-1-florian.fainelli@broadcom.com> References: <20261008210621.1374785-1-florian.fainelli@broadcom.com> Precedence: bulk X-Mailing-List: netdev@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit In bcmasp_rx_poll(), the driver removes a 2-byte alignment pad and optionally strips the ETH_FCS_LEN CRC from received packets before passing them to eth_type_trans(). If the hardware reports a descriptor size smaller than the sum of the 2-byte pad, the Ethernet header (ETH_HLEN), and optional CRC (ETH_FCS_LEN), subtracting the pad and CRC lengths underflows u32 len. This adds ~4 GiB to rx_bytes statistics, while the undersized frame reaches eth_type_trans(), which reads past skb->len into stale buffer data. Check that desc->size is at least (2 + ETH_HLEN + (crc_fwd ? ETH_FCS_LEN : 0)) before proceeding to process the descriptor. Fixes: 490cb412007d ("net: bcmasp: Add support for ASP2.0 Ethernet controller") Assisted-by: LLM Signed-off-by: Florian Fainelli --- drivers/net/ethernet/broadcom/asp2/bcmasp_intf.c | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/drivers/net/ethernet/broadcom/asp2/bcmasp_intf.c b/drivers/net/ethernet/broadcom/asp2/bcmasp_intf.c index 9ad5a982542f..d679c796c8c2 100644 --- a/drivers/net/ethernet/broadcom/asp2/bcmasp_intf.c +++ b/drivers/net/ethernet/broadcom/asp2/bcmasp_intf.c @@ -523,6 +523,12 @@ static int bcmasp_rx_poll(struct napi_struct *napi, int budget) DMA_FROM_DEVICE); len = desc->size; + if (unlikely(len < 2 + ETH_HLEN + (intf->crc_fwd ? ETH_FCS_LEN : 0))) { + u64_stats_update_begin(&stats->syncp); + u64_stats_inc(&stats->rx_dropped); + u64_stats_update_end(&stats->syncp); + goto next; + } /* Allocate a page pool page as the SKB data area so the * kernel can recycle it efficiently after the packet is -- 2.34.1