net: mana: Validate the packet length reported by the NIC

[ Upstream commit 2e2a83b499 ]

Validate the packet length reported in the RX CQE before passing it
to skb processing. The CQE is supplied by the NIC device and should
not be blindly trusted.

Cc: stable@vger.kernel.org
Reviewed-by: Haiyang Zhang <haiyangz@microsoft.com>
Signed-off-by: Dexuan Cui <decui@microsoft.com>
Fixes: ca9c54d2d6 ("net: mana: Add a driver for Microsoft Azure Network Adapter (MANA)")
Link: https://patch.msgid.link/20260702041237.617719-2-decui@microsoft.com
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
This commit is contained in:
Dexuan Cui
2026-08-03 11:15:39 +02:00
committed by Greg Kroah-Hartman
parent 3cfaac77b3
commit 2e276b14b6
@@ -1739,6 +1739,19 @@ static void mana_process_rx_cqe(struct mana_rxq *rxq, struct mana_cq *cq,
rxbuf_oob = &rxq->rx_oobs[curr];
WARN_ON_ONCE(rxbuf_oob->wqe_inf.wqe_size_in_bu != 1);
if (unlikely(pktlen > rxq->datasize)) {
/* Increase it even if mana_rx_skb() isn't called. */
rxq->rx_cq.work_done++;
++ndev->stats.rx_dropped;
netdev_warn_once(ndev,
"Dropped oversized RX packet: len=%u, datasize=%u\n",
pktlen, rxq->datasize);
/* Reuse the RX buffer since rxbuf_oob is unchanged. */
goto drop;
}
mana_refill_rx_oob(dev, rxq, rxbuf_oob, &old_buf, &old_fp);
/* Unsuccessful refill will have old_buf == NULL.