net: txgbe: fix heap overflow when reading module EEPROM

txgbe_read_eeprom_hostif() always copies round_up(length, 4) bytes
into the caller buffer, which ethtool allocates with exactly 'length'
bytes. A non-4-aligned length therefore causes an out-of-bounds write.
Copy only the remaining bytes on the final dword instead.

Signed-off-by: Chenguang Zhao <zhaochenguang@kylinos.cn>
Reviewed-by: Jiawen Wu <jiawenwu@trustnetic.com>
Reviewed-by: Jacob Keller <jacob.e.keller@intel.com>
Fixes: 9b97b6b563 ("net: txgbe: support getting module EEPROM by page")
Link: https://patch.msgid.link/20260713085111.1481884-1-chenguang.zhao@linux.dev
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
This commit is contained in:
Chenguang Zhao 2026-07-13 16:51:11 +08:00 committed by Jakub Kicinski
parent 043c1f6d84
commit 6a905a71fd

View File

@ -96,11 +96,13 @@ int txgbe_read_eeprom_hostif(struct wx *wx,
dword_len = round_up(length, 4) >> 2;
for (i = 0; i < dword_len; i++) {
u32 copy_len = min_t(u32, 4, length - i * 4);
value = rd32a(wx, WX_FW2SW_MBOX, i + offset);
le32_to_cpus(&value);
memcpy(data, &value, 4);
data += 4;
memcpy(data, &value, copy_len);
data += copy_len;
}
return 0;