From dbc641ecf1cbd41a649e7ac6ea7175562ef599b2 Mon Sep 17 00:00:00 2001 From: Dan Carpenter Date: Fri, 7 Feb 2025 12:16:19 +0300 Subject: [PATCH] RDMA/bnxt_re: Fix buffer overflow in debugfs code Add some bounds checking to prevent memory corruption in bnxt_re_cc_config_set(). This is debugfs code so the bug can only be triggered by root. Fixes: 656dff55da19 ("RDMA/bnxt_re: Congestion control settings using debugfs hook") Signed-off-by: Dan Carpenter Link: https://patch.msgid.link/a6b081ab-55fe-4d0c-8f69-c5e5a59e9141@stanley.mountain Acked-by: Selvin Xavier Signed-off-by: Leon Romanovsky --- drivers/infiniband/hw/bnxt_re/debugfs.c | 3 +++ 1 file changed, 3 insertions(+) diff --git a/drivers/infiniband/hw/bnxt_re/debugfs.c b/drivers/infiniband/hw/bnxt_re/debugfs.c index f4dd2fb51867d..d7354e7753fe3 100644 --- a/drivers/infiniband/hw/bnxt_re/debugfs.c +++ b/drivers/infiniband/hw/bnxt_re/debugfs.c @@ -285,6 +285,9 @@ static ssize_t bnxt_re_cc_config_set(struct file *filp, const char __user *buffe u32 val; int rc; + if (count >= sizeof(buf)) + return -EINVAL; + if (copy_from_user(buf, buffer, count)) return -EFAULT; -- 2.47.2