]> git.ipfire.org Git - thirdparty/linux.git/commitdiff
ethtool: cmis: validate fw->size against start_cmd_payload_size
authorJakub Kicinski <kuba@kernel.org>
Fri, 22 May 2026 23:13:12 +0000 (16:13 -0700)
committerJakub Kicinski <kuba@kernel.org>
Tue, 26 May 2026 15:19:33 +0000 (08:19 -0700)
cmis_fw_update_start_download() copies start_cmd_payload_size bytes
from the firmware blob into the CDB LPL vendor_data[] payload without
validating that the FW has enough data.

Since the start_cmd_payload_size can only be ~120B an image too short
is most likely corrupted, so reject it.

Fixes: c4f78134d45c ("ethtool: cmis_fw_update: add a layer for supporting firmware update using CDB")
Reviewed-by: Maxime Chevallier <maxime.chevallier@bootlin.com>
Reviewed-by: Danielle Ratson <danieller@nvidia.com>
Link: https://patch.msgid.link/20260522231312.1710836-10-kuba@kernel.org
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
net/ethtool/cmis_fw_update.c

index 16190c97e1f78c66844a243b4f95c98d71b36fb3..291d04d2776a5cfd66e684a6cf47ffe2917ede6e 100644 (file)
@@ -130,6 +130,14 @@ cmis_fw_update_start_download(struct ethtool_cmis_cdb *cdb,
        u8 lpl_len;
        int err;
 
+       if (fw_update->fw->size < vendor_data_size) {
+               ethnl_module_fw_flash_ntf_err(fw_update->dev,
+                                             &fw_update->ntf_params,
+                                             "Firmware image too small for module's start payload",
+                                             NULL);
+               return -EINVAL;
+       }
+
        pl.image_size = cpu_to_be32(fw_update->fw->size);
        memcpy(pl.vendor_data, fw_update->fw->data, vendor_data_size);