[PATCH v2] RDMA/mlx5: Fix destination index when resizing a CQ
From: lirongqing
Date: Tue Sep 29 2026 - 21:07:03 EST
From: Li RongQing <lirongqing@xxxxxxxxx>
copy_resize_cqes() uses the absolute consumer index to copy pending
CQEs into the resized CQ buffer. The destination slot must wrap at
resize_buf->nent, but the code applies a bitwise AND with nent itself.
CQ sizes are rounded up to a power of two, so nent has only one bit
set. Masking with nent therefore produces either zero or nent instead
of an index in the range [0, nent). When it produces nent,
mlx5_frag_buf_get_wqe() accesses one entry beyond the resized CQ buffer
and the following memcpy() can corrupt memory.
Use modulo nent to calculate the destination slot and keep it within
the resized CQ.
Fixes: bde51583f49b ("IB/mlx5: Add support for resize CQ")
Signed-off-by: Li RongQing <lirongqing@xxxxxxxxx>
---
Diff with v1: replace & with %
drivers/infiniband/hw/mlx5/cq.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/infiniband/hw/mlx5/cq.c b/drivers/infiniband/hw/mlx5/cq.c
index dc457fa..fc4ee1c 100644
--- a/drivers/infiniband/hw/mlx5/cq.c
+++ b/drivers/infiniband/hw/mlx5/cq.c
@@ -1319,7 +1319,7 @@ static int copy_resize_cqes(struct mlx5_ib_cq *cq)
while (get_cqe_opcode(scqe64) != MLX5_CQE_RESIZE_CQ) {
dcqe = mlx5_frag_buf_get_wqe(&cq->resize_buf->fbc,
- (i + 1) & cq->resize_buf->nent);
+ (i + 1) % cq->resize_buf->nent);
dcqe64 = dsize == 64 ? dcqe : dcqe + 64;
sw_own = sw_ownership_bit(i + 1, cq->resize_buf->nent);
memcpy(dcqe, scqe, dsize);
--
2.9.4