Re: [Intel-wired-lan] [PATCH] ixgbe: validate E610 PFA TLV bounds
From: Tomasz Lichwala
Date: Mon Jul 06 2026 - 09:16:16 EST
W dniu 6.07.2026 o 12:02, Marcin Szycik pisze:
>
>
> On 06/07/2026 11:25, Pengpeng Hou wrote:
>> ixgbe_get_pfa_module_tlv() walks E610 PFA TLV records stored in
>> EEPROM.
>>
>> Stop parsing malformed TLVs whose header or declared value length would
>> exceed the PFA boundary.
>>
>> Signed-off-by: Pengpeng Hou <pengpeng@xxxxxxxxxxx>
>> ---
>> drivers/net/ethernet/intel/ixgbe/ixgbe_e610.c | 6 ++++++
>> 1 file changed, 6 insertions(+)
>>
>> diff --git a/drivers/net/ethernet/intel/ixgbe/ixgbe_e610.c b/drivers/net/ethernet/intel/ixgbe/ixgbe_e610.c
>> index 4d8ae5b56145..03e88bdf5a43 100644
>> --- a/drivers/net/ethernet/intel/ixgbe/ixgbe_e610.c
>> +++ b/drivers/net/ethernet/intel/ixgbe/ixgbe_e610.c
>> @@ -3895,6 +3895,9 @@ static int ixgbe_get_pfa_module_tlv(struct ixgbe_hw *hw, u16 *module_tlv,
>> while (next_tlv < pfa_end_ptr) {
>> u16 tlv_sub_module_type, tlv_len;
>>
>> + if (pfa_end_ptr - next_tlv < 2)
>> + break;
>
> This check could go in the while condition above.
>
>> +
>> /* Read TLV type */
>> err = ixgbe_read_ee_aci_e610(hw, next_tlv,
>> &tlv_sub_module_type);
>> @@ -3917,6 +3920,9 @@ static int ixgbe_get_pfa_module_tlv(struct ixgbe_hw *hw, u16 *module_tlv,
>> /* Check next TLV, i.e. current TLV pointer + length + 2 words
>> * (for current TLV's type and length).
>> */
>> + if (tlv_len > pfa_end_ptr - next_tlv - 2)
>> + break;
>> +
>> next_tlv = next_tlv + tlv_len + 2;
>
> Would be nice to define the magic number (2), since we're reusing it now.
There is a pending patch in review that defines IXGBE_E610_SR_PFA_TLV_HDR_SIZE, which fits perfectly here.
>
>> }
>> /* Module does not exist */
>
> Thanks,
> Marcin
Thanks,
Tomasz