When processing asynchronous event notifications from controller firmware,
the driver trusted the firmware-reported event data length without verifying
whether it fit within the physical reply buffer frame. If an event reported a
length exceeding the reply frame size, copying the payload into bottom-half
event queues or saving diagnostic log data caused memory reads beyond the
reply buffer boundaries.
In addition, when saving log data into the driver's circular logging buffer,
the copy size was bounded against the total slot size rather than the payload
capacity, failing to account for the entry header and causing writes to
overflow into adjacent buffer slots.
Clamp all event data copy lengths to the maximum capacity of the reply
buffer frame, and account for entry header overhead when saving log data to
prevent buffer overflows.