From: Weimin Xiong <redacted>
Use kcalloc() when calculating the parser table allocation size so an
overflow in the firmware-provided item dimensions is detected before
allocation.
Signed-off-by: Weimin Xiong <redacted>
Reviewed-by: Aleksandr Loktionov <redacted>
Signed-off-by: Tony Nguyen <anthony.l.nguyen@intel.com>
---
drivers/net/ethernet/intel/ice/ice_parser.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/net/ethernet/intel/ice/ice_parser.c b/drivers/net/ethernet/intel/ice/ice_parser.c
index 3ede4c1a5a8a..d239102c52ff 100644
--- a/drivers/net/ethernet/intel/ice/ice_parser.c
+++ b/drivers/net/ethernet/intel/ice/ice_parser.c
@@ -102,7 +102,7 @@ ice_parser_create_table(struct ice_hw *hw, u32 sect_type,
if (!seg)
return ERR_PTR(-EINVAL);
- table = kzalloc(item_size * length, GFP_KERNEL);
+ table = kcalloc(length, item_size, GFP_KERNEL);
if (!table)
return ERR_PTR(-ENOMEM);
--
2.47.1