mirror of
https://github.com/torvalds/linux.git
synced 2026-07-27 09:36:22 +02:00
net: txgbe: fix heap overflow when reading module EEPROM
txgbe_read_eeprom_hostif() always copies round_up(length, 4) bytes
into the caller buffer, which ethtool allocates with exactly 'length'
bytes. A non-4-aligned length therefore causes an out-of-bounds write.
Copy only the remaining bytes on the final dword instead.
Signed-off-by: Chenguang Zhao <zhaochenguang@kylinos.cn>
Reviewed-by: Jiawen Wu <jiawenwu@trustnetic.com>
Reviewed-by: Jacob Keller <jacob.e.keller@intel.com>
Fixes: 9b97b6b563 ("net: txgbe: support getting module EEPROM by page")
Link: https://patch.msgid.link/20260713085111.1481884-1-chenguang.zhao@linux.dev
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
This commit is contained in:
parent
043c1f6d84
commit
6a905a71fd
|
|
@ -96,11 +96,13 @@ int txgbe_read_eeprom_hostif(struct wx *wx,
|
|||
dword_len = round_up(length, 4) >> 2;
|
||||
|
||||
for (i = 0; i < dword_len; i++) {
|
||||
u32 copy_len = min_t(u32, 4, length - i * 4);
|
||||
|
||||
value = rd32a(wx, WX_FW2SW_MBOX, i + offset);
|
||||
le32_to_cpus(&value);
|
||||
|
||||
memcpy(data, &value, 4);
|
||||
data += 4;
|
||||
memcpy(data, &value, copy_len);
|
||||
data += copy_len;
|
||||
}
|
||||
|
||||
return 0;
|
||||
|
|
|
|||
Loading…
Reference in New Issue
Block a user