[PATCH net-next v2] net: phy: air_en8811h: refuse a firmware blob that is not a multiple of 4
From: Aleksei Sviridkin
Date: Thu Sep 03 2026 - 08:40:31 EST
The download loop streams the blob into the MCU as 32-bit words and
reads the last word past the end of a blob whose size is not a multiple
of four. The shipped blobs happen to be aligned, so the overread never
showed; a truncated or foreign file would carry up to three bytes of
whatever follows it into the MCU. Reject it before the first write
instead.
Fixes: 71e79430117d ("net: phy: air_en8811h: Add the Airoha EN8811H PHY driver")
Assisted-by: LLM
Reviewed-by: Andrew Lunn <andrew@xxxxxxx>
Signed-off-by: Aleksei Sviridkin <f@xxxxxx>
---
Found by review rather than by a failure: the loop reads a 32-bit word
per iteration, so a blob whose size is not a multiple of four overreads
by up to three bytes. Both blobs the EN8811H ships with are aligned
(16384 and 131072 bytes), which is why nothing has tripped over it.
Exercised on an MT7981B board with an EN8811H behind an MT7531 switch,
with the DM blob truncated by one byte in the image:
firmware size 16383 is not a multiple of 4
airoha-en8811h-mcu mdio-bus:0d: firmware download keeps failing: -EINVAL
The blob is refused before the first write to the MCU, the driver
retries and gives up with a warning, and the port comes up without a
PHY rather than with a chip programmed from three bytes of whatever
followed the file. With the shipped blobs the same board loads
firmware 25062302 and the port links at 1 Gbps. The board runs the
loop in the library that the pending late-PHY series moves it into, so
the message carries the bus device there; the guard and the loop are
the ones in this patch.
v2: target net-next: no shipped blob trips the check, so not a stable
candidate (Andrew Lunn); carries his Reviewed-by.
https://lore.kernel.org/netdev/20260902080525.2211446-1-f@xxxxxx/
drivers/net/phy/air_en8811h.c | 6 ++++++
1 file changed, 6 insertions(+)
diff --git a/drivers/net/phy/air_en8811h.c b/drivers/net/phy/air_en8811h.c
index 0eeb7b9a4e26..34d2727e8222 100644
--- a/drivers/net/phy/air_en8811h.c
+++ b/drivers/net/phy/air_en8811h.c
@@ -312,6 +312,12 @@ static int air_write_buf(struct phy_device *phydev, u32 address,
int saved_page;
int ret = 0;
+ if (fw->size % 4) {
+ phydev_err(phydev, "firmware size %zu is not a multiple of 4\n",
+ fw->size);
+ return -EINVAL;
+ }
+
saved_page = phy_select_page(phydev, AIR_PHY_PAGE_EXTENDED_4);
if (saved_page >= 0) {
--
2.53.0