[PATCH] net/bnxt: prevent overflow in alarm timeout calculation

Evgeny Sokolov Evgeny.Sokolov at infotecs.ru
Tue Sep 15 10:55:02 CEST 2026


From: Sokolov Evgeny <Evgeny.Sokolov at infotecs.ru>

The alarm timeout is calculated by multiplying wait_msec by
US_PER_MS before passing the value to rte_eal_alarm_set().

Since wait_msec is a uint32_t, the multiplication may overflow
when performed using 32-bit arithmetic for large timeout values.

Cast wait_msec to uint64_t to ensure the multiplication is
performed in 64-bit arithmetic.

Signed-off-by: Sokolov Evgeny <Evgeny.Sokolov at infotecs.ru>
Cc: stable at dpdk.org
---
 drivers/net/bnxt/bnxt_ethdev.c | 6 +++---
 1 file changed, 3 insertions(+), 3 deletions(-)

diff --git a/drivers/net/bnxt/bnxt_ethdev.c b/drivers/net/bnxt/bnxt_ethdev.c
index a2429561b9..16a65f9770 100644
--- a/drivers/net/bnxt/bnxt_ethdev.c
+++ b/drivers/net/bnxt/bnxt_ethdev.c
@@ -4855,7 +4855,7 @@ static void bnxt_check_fw_health(void *arg)
 
 	info->last_reset_counter = val;
 
-	rte_eal_alarm_set(US_PER_MS * info->driver_polling_freq,
+	rte_eal_alarm_set(US_PER_MS * (uint64_t)info->driver_polling_freq,
 			  bnxt_check_fw_health, (void *)bp);
 
 	return;
@@ -4877,7 +4877,7 @@ static void bnxt_check_fw_health(void *arg)
 	else
 		wait_msec = info->normal_func_wait_period;
 
-	rte_eal_alarm_set(US_PER_MS * wait_msec,
+	rte_eal_alarm_set(US_PER_MS * (uint64_t)wait_msec,
 			  bnxt_fw_reset_cb, (void *)bp);
 }
 
@@ -4895,7 +4895,7 @@ void bnxt_schedule_fw_health_check(struct bnxt *bp)
 
 	polling_freq = bp->recovery_info->driver_polling_freq;
 
-	rte_eal_alarm_set(US_PER_MS * polling_freq,
+	rte_eal_alarm_set(US_PER_MS * (uint64_t)polling_freq,
 			  bnxt_check_fw_health, (void *)bp);
 	bp->flags |= BNXT_FLAG_FW_HEALTH_CHECK_SCHEDULED;
 
-- 
2.30.2



More information about the stable mailing list