From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1756987AbdEDTlm (ORCPT ); Thu, 4 May 2017 15:41:42 -0400 Received: from relay1.mentorg.com ([192.94.38.131]:45467 "EHLO relay1.mentorg.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1751375AbdEDTll (ORCPT ); Thu, 4 May 2017 15:41:41 -0400 From: Jim Baxter To: , , Oliver Neukum CC: Subject: [PATCH V1 0/1] net: cdc_ncm: Fix TX zero padding Date: Thu, 4 May 2017 20:41:34 +0100 Message-ID: <1493926895-14556-1-git-send-email-jim_baxter@mentor.com> X-Mailer: git-send-email 1.9.1 MIME-Version: 1.0 Content-Type: text/plain X-Originating-IP: [137.202.0.87] X-ClientProxiedBy: svr-ies-mbx-01.mgc.mentorg.com (139.181.222.1) To SVR-IES-MBX-04.mgc.mentorg.com (139.181.222.4) Sender: linux-kernel-owner@vger.kernel.org List-ID: X-Mailing-List: linux-kernel@vger.kernel.org Analysis -------- The zero padding that is added to NTB's does not zero the memory correctly. This happens because the skb_put called within the memset in the line: memset(skb_put(skb_out, ctx->tx_max - skb_out->len), 0, ctx->tx_max - skb_out->len); causes the value of skb_out->len to be modified during the two uses of it within the above line. This causes non-zeroed data at the end of skb_out. This issue was found when connecting between an ARM Sabre SD Host platform and a test box that was dropping the NDP's due to the non zeroed memory being identified as an error. Solution -------- To resolve this I have cached the value of ctx->tx_max - skb_out->len before the memset operation. Jim Baxter (1): net: cdc_ncm: Fix TX zero padding drivers/net/usb/cdc_ncm.c | 11 +++++++---- 1 file changed, 7 insertions(+), 4 deletions(-) -- 1.9.1