* [PATCH] net: ncsi: clamp filter table counts in GP response handling
@ 2026-09-28 18:59 Vamsi Krishna Kattamuri
2026-09-28 19:05 ` netdev-bot+sinfo
0 siblings, 1 reply; 2+ messages in thread
From: Vamsi Krishna Kattamuri @ 2026-09-28 18:59 UTC (permalink / raw)
To: netdev, sam
Cc: fercerpav, davem, edumazet, kuba, pabeni, horms, gwshan, joel,
linux-kernel, stable
ncsi_rsp_handler_gp() iterates over the MAC address and VLAN filter
tables using the counts from the Get Parameters response itself,
rsp->mac_cnt and rsp->vlan_cnt. The arrays it writes into, however,
were allocated by the Get Controller Capabilities handler from the
independent rsp->uc_cnt, rsp->mc_cnt, rsp->mixed_cnt and rsp->vlan_cnt
fields.
A malicious or buggy NCSI device can therefore report contradictory
counts in the two responses - for example a GC response advertising
a single unicast address filter followed by a GP response with
mac_cnt = 255. The GP handler then memcpy()s 255 MAC addresses into
the 6-byte kzalloc()ed buffer, a heap out-of-bounds write of roughly
1.5KB of device-controlled data, and the same applies to vlan_cnt
versus the vids[] array.
The loop indices are additionally used as bit numbers for
set_bit()/clear_bit() on the u64 filter bitmaps, so any count larger
than 64 writes out-of-bounds bits into struct ncsi_channel.
Clamp both loops to the number of entries actually allocated for the
channel and to the capacity of the bitmap word, mirroring the
validation the SVF and SMA handlers already apply to their indices.
Fixes: 138635cc27c9 ("net/ncsi: NCSI response packet handler")
Cc: stable@vger.kernel.org
Signed-off-by: Vamsi Krishna Kattamuri <kattamurivamsikrishna17@gmail.com>
---
net/ncsi/ncsi-rsp.c | 7 +++++--
1 file changed, 5 insertions(+), 2 deletions(-)
diff --git a/net/ncsi/ncsi-rsp.c b/net/ncsi/ncsi-rsp.c
index fbd84bc8026a..fa1ed405dfbb 100644
--- a/net/ncsi/ncsi-rsp.c
+++ b/net/ncsi/ncsi-rsp.c
@@ -883,7 +883,9 @@ static int ncsi_rsp_handler_gp(struct ncsi_request *nr)
ncmf = &nc->mac_filter;
spin_lock_irqsave(&nc->lock, flags);
bitmap = &ncmf->bitmap;
- for (i = 0; i < rsp->mac_cnt; i++, pdata += 6) {
+ for (i = 0; i < rsp->mac_cnt &&
+ i < ncmf->n_uc + ncmf->n_mc + ncmf->n_mixed &&
+ i < sizeof(ncmf->bitmap) * 8; i++, pdata += 6) {
if (!(enable & (0x1 << i)))
clear_bit(i, bitmap);
else
@@ -898,7 +900,8 @@ static int ncsi_rsp_handler_gp(struct ncsi_request *nr)
ncvf = &nc->vlan_filter;
bitmap = &ncvf->bitmap;
spin_lock_irqsave(&nc->lock, flags);
- for (i = 0; i < rsp->vlan_cnt; i++, pdata += 2) {
+ for (i = 0; i < rsp->vlan_cnt && i < ncvf->n_vids &&
+ i < sizeof(ncvf->bitmap) * 8; i++, pdata += 2) {
if (!(enable & (0x1 << i)))
clear_bit(i, bitmap);
else
--
2.47.3
^ permalink raw reply [flat|nested] 2+ messages in thread* Re: [PATCH] net: ncsi: clamp filter table counts in GP response handling
2026-09-28 18:59 [PATCH] net: ncsi: clamp filter table counts in GP response handling Vamsi Krishna Kattamuri
@ 2026-09-28 19:05 ` netdev-bot+sinfo
0 siblings, 0 replies; 2+ messages in thread
From: netdev-bot+sinfo @ 2026-09-28 19:05 UTC (permalink / raw)
To: Vamsi Krishna Kattamuri
Cc: netdev, sam, fercerpav, davem, edumazet, kuba, pabeni, horms,
gwshan, joel, linux-kernel, stable
Hi!
This is an automated message. This series looks like a fix, but its
commit messages seem to be missing some information:
- How the issue was discovered, e.g. hit in production, hit during
development, syzbot report, manual code inspection, LLM or static
analysis tool scan.
- Whether the issue was actually triggered, or is only theoretical
(e.g. found by code inspection). If it was triggered please include
the symptoms, like the stack trace or error messages.
Please do not repost the series just to address the above. Instead,
reply to this email with the missing information, so that reviewers
can take it into account. If the series needs another revision for
other reasons, please include the information in the commit messages
then.
The evaluation is done by an LLM so it may be wrong, if you think
that is the case please reply and explain.
^ permalink raw reply [flat|nested] 2+ messages in thread
end of thread, other threads:[~2026-09-28 19:05 UTC | newest]
Thread overview: 2+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-09-28 18:59 [PATCH] net: ncsi: clamp filter table counts in GP response handling Vamsi Krishna Kattamuri
2026-09-28 19:05 ` netdev-bot+sinfo
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®