Thread (20 messages) flat view 20 messages, 5 authors, 2025-09-16

Re: [PATCH net 1/3] net: stmmac: replace memcpy with strscpy in ethtool

From: Andrew Lunn <andrew@lunn.ch>
Date: 2025-09-04 19:18:30
Also in: lkml

On Thu, Sep 04, 2025 at 08:53:03PM +0200, Sebastian Basierski wrote:
On 9/1/2025 9:59 PM, Jakub Kicinski wrote:
quoted
On Thu, 28 Aug 2025 12:02:35 +0200 Konrad Leszczynski wrote:
quoted
Fix kernel exception by replacing memcpy with strscpy when used with
safety feature strings in ethtool logic.

[  +0.000023] BUG: KASAN: global-out-of-bounds in stmmac_get_strings+0x17d/0x520 [stmmac]
[  +0.000115] Read of size 32 at addr ffffffffc0cfab20 by task ethtool/2571
If you hit this with upstream code please mention which string
is not padded. If this can't happen with upstream platforms --
there is no upstream bug. BTW ethtool_puts() is a better choice.
Hi Jakub,
Sorry for late answer to your review.
I double checked and made sure this bug reproduces on upstream platform.
Bug seems to appear on first string - i will add this information to commit
message.
By first string, do you mean "Application Transmit Interface Parity
Check Error"?

I think it also would be better to change dwmac5_error_desc, so that
it uses char stat_string[ETH_GSTRING_LEN] __nonstring; like
stmmac_stats.

     Andrew
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help