W dniu 6.07.2026 o 12:02, Marcin Szycik pisze:
> 
> 
> On 06/07/2026 11:25, Pengpeng Hou wrote:
>> ixgbe_get_pfa_module_tlv() walks E610 PFA TLV records stored in
>> EEPROM.
>>
>> Stop parsing malformed TLVs whose header or declared value length would
>> exceed the PFA boundary.
>>
>> Signed-off-by: Pengpeng Hou <[email protected]>
>> ---
>>  drivers/net/ethernet/intel/ixgbe/ixgbe_e610.c | 6 ++++++
>>  1 file changed, 6 insertions(+)
>>
>> diff --git a/drivers/net/ethernet/intel/ixgbe/ixgbe_e610.c 
>> b/drivers/net/ethernet/intel/ixgbe/ixgbe_e610.c
>> index 4d8ae5b56145..03e88bdf5a43 100644
>> --- a/drivers/net/ethernet/intel/ixgbe/ixgbe_e610.c
>> +++ b/drivers/net/ethernet/intel/ixgbe/ixgbe_e610.c
>> @@ -3895,6 +3895,9 @@ static int ixgbe_get_pfa_module_tlv(struct ixgbe_hw 
>> *hw, u16 *module_tlv,
>>      while (next_tlv < pfa_end_ptr) {
>>              u16 tlv_sub_module_type, tlv_len;
>>  
>> +            if (pfa_end_ptr - next_tlv < 2)
>> +                    break;
> 
> This check could go in the while condition above.
> 
>> +
>>              /* Read TLV type */
>>              err = ixgbe_read_ee_aci_e610(hw, next_tlv,
>>                                           &tlv_sub_module_type);
>> @@ -3917,6 +3920,9 @@ static int ixgbe_get_pfa_module_tlv(struct ixgbe_hw 
>> *hw, u16 *module_tlv,
>>              /* Check next TLV, i.e. current TLV pointer + length + 2 words
>>               * (for current TLV's type and length).
>>               */
>> +            if (tlv_len > pfa_end_ptr - next_tlv - 2)
>> +                    break;
>> +
>>              next_tlv = next_tlv + tlv_len + 2;
> 
> Would be nice to define the magic number (2), since we're reusing it now.

There is a pending patch in review that defines IXGBE_E610_SR_PFA_TLV_HDR_SIZE, 
which fits perfectly here.

> 
>>      }
>>      /* Module does not exist */
> 
> Thanks,
> Marcin

Thanks,
Tomasz

Reply via email to