Re: [Intel-wired-lan] [PATCH] ixgbe: validate E610 PFA TLV bounds
From: Marcin Szycik
Date: Mon Jul 06 2026 - 06:32:10 EST
On 06/07/2026 11:25, Pengpeng Hou wrote:
> ixgbe_get_pfa_module_tlv() walks E610 PFA TLV records stored in
> EEPROM.
>
> Stop parsing malformed TLVs whose header or declared value length would
> exceed the PFA boundary.
>
> Signed-off-by: Pengpeng Hou <pengpeng@xxxxxxxxxxx>
> ---
> drivers/net/ethernet/intel/ixgbe/ixgbe_e610.c | 6 ++++++
> 1 file changed, 6 insertions(+)
>
> diff --git a/drivers/net/ethernet/intel/ixgbe/ixgbe_e610.c b/drivers/net/ethernet/intel/ixgbe/ixgbe_e610.c
> index 4d8ae5b56145..03e88bdf5a43 100644
> --- a/drivers/net/ethernet/intel/ixgbe/ixgbe_e610.c
> +++ b/drivers/net/ethernet/intel/ixgbe/ixgbe_e610.c
> @@ -3895,6 +3895,9 @@ static int ixgbe_get_pfa_module_tlv(struct ixgbe_hw *hw, u16 *module_tlv,
> while (next_tlv < pfa_end_ptr) {
> u16 tlv_sub_module_type, tlv_len;
>
> + if (pfa_end_ptr - next_tlv < 2)
> + break;
This check could go in the while condition above.
> +
> /* Read TLV type */
> err = ixgbe_read_ee_aci_e610(hw, next_tlv,
> &tlv_sub_module_type);
> @@ -3917,6 +3920,9 @@ static int ixgbe_get_pfa_module_tlv(struct ixgbe_hw *hw, u16 *module_tlv,
> /* Check next TLV, i.e. current TLV pointer + length + 2 words
> * (for current TLV's type and length).
> */
> + if (tlv_len > pfa_end_ptr - next_tlv - 2)
> + break;
> +
> next_tlv = next_tlv + tlv_len + 2;
Would be nice to define the magic number (2), since we're reusing it now.
> }
> /* Module does not exist */
Thanks,
Marcin