[PATCH] net/bnxt: fix ctx_dma_arr allocation size
Stephen Hemminger
stephen at networkplumber.org
Tue Sep 15 16:34:59 CEST 2026
On Tue, 15 Sep 2026 08:56:06 +0000
Evgeny Sokolov <Evgeny.Sokolov at infotecs.ru> wrote:
> From: Sokolov Evgeny <Evgeny.Sokolov at infotecs.ru>
>
> ctx_dma_arr stores rte_iova_t entries, but the allocation size was
> calculated using sizeof(rte_iova_t *) instead of sizeof(rte_iova_t).
>
> Use the correct element size when allocating the array to match the
> actual data type stored in ctx_dma_arr.
>
> Fixes: 4371b402c7b ("net/bnxt: fix array overflow")
> Cc: stable at dpdk.org
>
> Signed-off-by: Sokolov Evgeny <Evgeny.Sokolov at infotecs.ru>
> ---
> drivers/net/bnxt/bnxt_ethdev.c | 2 +-
> 1 file changed, 1 insertion(+), 1 deletion(-)
>
> diff --git a/drivers/net/bnxt/bnxt_ethdev.c b/drivers/net/bnxt/bnxt_ethdev.c
> index a2429561b9..2754725566 100644
> --- a/drivers/net/bnxt/bnxt_ethdev.c
> +++ b/drivers/net/bnxt/bnxt_ethdev.c
> @@ -5054,7 +5054,7 @@ static int bnxt_alloc_ctx_mem_blk(struct bnxt *bp,
>
> snprintf(name, RTE_MEMZONE_NAMESIZE, "bnxt_ctx_dma_arr%s_%x_%d",
> suffix, idx, bp->eth_dev->data->port_id);
> - ctx_pg->ctx_dma_arr = rte_zmalloc(name, sizeof(rte_iova_t *) * rmem->nr_pages, 0);
> + ctx_pg->ctx_dma_arr = rte_zmalloc(name, sizeof(rte_iova_t) * rmem->nr_pages, 0);
> if (ctx_pg->ctx_dma_arr == NULL)
> return -ENOMEM;
>
Maybe use rte_calloc() instead but fine as is.
Acked-by: Stephen Hemminger <stephen at networkplumber.org>
More information about the stable
mailing list