Page MenuHomeFreeBSD

if_bnxt: avoid FTQM/STQM pg_info alias on reset
AcceptedPublic

Authored by sumit.saxena_broadcom.com on Aug 3 2026, 1:04 PM.
Tags
None
Referenced Files
Unknown Object (File)
Thu, Sep 3, 10:50 PM
Unknown Object (File)
Thu, Sep 3, 5:29 AM
Unknown Object (File)
Wed, Sep 2, 8:47 PM
Unknown Object (File)
Tue, Sep 1, 9:47 PM
Unknown Object (File)
Wed, Aug 26, 5:28 PM
Unknown Object (File)
Wed, Aug 26, 2:02 PM
Unknown Object (File)
Wed, Aug 26, 7:17 AM
Unknown Object (File)
Tue, Aug 25, 4:39 PM
Subscribers
None

Details

Summary

Copying the STQM backing-store context to seed FTQM's also copied
STQM's pg_info pointer verbatim. On cold load STQM's pg_info is still
NULL so this is harmless, but on a firmware reset STQM's pg_info is
already non-NULL, making FTQM alias STQM's backing-store pages. The
allocator then skips FTQM since it looks already allocated, and FTQM
is later indexed as its own array, reading out of bounds into STQM's
buffer and dereferencing a bogus DMA address.

Clear ctxm->pg_info after the memcpy so FTQM always gets its own
backing store.

Diff Detail

Lint
Lint Skipped
Unit
Tests Skipped