When the controller notifies the driver of SAS or PCIe topology changes,
the firmware event notification includes a payload length and an entry
count indicating the number of PHY or port descriptors attached to the
event. Previously, the top-half event handlers iterated over the entry
count without verifying whether the payload buffer was actually large
enough to contain all reported entries. A malformed event with an entry
count exceeding the buffer length would result in reading memory beyond
the event descriptor.
Validate that the reported event length covers the base topology header
and compute the maximum number of entries that fit within the payload.
If the entry count exceeds the available buffer, reject the event and
skip scheduling deferred bottom-half processing.