Page MenuHomeFreeBSD

if_bnxt: avoid FTQM/STQM pg_info alias on reset
ClosedPublic

Authored by sumit.saxena_broadcom.com on Aug 3 2026, 1:04 PM.
Tags
None
Referenced Files
Unknown Object (File)
Wed, Oct 7, 1:51 PM
Unknown Object (File)
Mon, Oct 5, 1:13 PM
Unknown Object (File)
Sun, Oct 4, 9:03 AM
Unknown Object (File)
Wed, Sep 30, 12:03 PM
Unknown Object (File)
Sat, Sep 26, 6:12 PM
Unknown Object (File)
Wed, Sep 23, 6:16 PM
Unknown Object (File)
Tue, Sep 22, 8:15 PM
Unknown Object (File)
Sep 3 2026, 10:50 PM
Subscribers

Details

Summary

Copying the STQM backing-store context to seed FTQM's also copied
STQM's pg_info pointer verbatim. On cold load STQM's pg_info is still
NULL so this is harmless, but on a firmware reset STQM's pg_info is
already non-NULL, making FTQM alias STQM's backing-store pages. The
allocator then skips FTQM since it looks already allocated, and FTQM
is later indexed as its own array, reading out of bounds into STQM's
buffer and dereferencing a bogus DMA address.

Clear ctxm->pg_info after the memcpy so FTQM always gets its own
backing store.

Diff Detail

Repository
rG FreeBSD src repository
Lint
Lint Not Applicable
Unit
Tests Not Applicable