[PATCH net] net: ethernet: ti: am65-cpsw-nuss: Fix port_id extraction from SRC TAG

Chintan Vankar c-vankar at ti.com
Sun Aug 9 13:27:08 PDT 2026



On 07/08/26 16:47, Siddharth Vadapalli wrote:
> On the packet reception path, the ID of the MAC Port on which the packet
> was received, is embedded in the RX DMA Descriptor's metadata. The ID is
> extracted using the helper function cppi5_desc_get_tags_ids() which fills
> in the 16-bit Source Tag into the 'port_id' variable. However, it is only
> the lower 8-bits of the 16-bit Source Tag that represent the MAC Port ID,
> while the upper 8-bits are Hardware-Reserved and carry an arbitrary value.
> With the existing logic, sporadic kernel crash is observed due to the
> subsequent driver code accessing out-of-bound memory because of an invalid
> port_id.
> 
> Hence, fix the port_id extraction logic to use only the lower 8-bits of the
> Source Tag as the MAC Port ID.
> 
> Fixes: 93a76530316a ("net: ethernet: ti: introduce am65x/j721e gigabit eth subsystem driver")
> Signed-off-by: Siddharth Vadapalli <s-vadapalli at ti.com>
> ---
> 
> Hello,
> 
> This patch is based on commit
> f9a2394a2348 Merge tag 'mm-hotfixes-stable-2026-08-06-18-44' of git://git.kernel.org/pub/scm/linux/kernel/git/akpm/mm
> of Mainline Linux.
> 
> I have observed it in practice that the RESERVED field contains non-zero
> value (such as 0xFF on one instance) causing port_id to be set to an
> invalid value (such as 0xFF01 in that instance) resulting in the subsequent
> driver code accessing out-of-bound / incorrect memory and corrupting it and
> causing a kernel crash. To summarize, this patch is fixing a real issue and
> not a hypothetical one.
> 
> Regards,
> Siddharth.
> 
>   drivers/net/ethernet/ti/am65-cpsw-nuss.c | 2 ++
>   1 file changed, 2 insertions(+)
> 
> diff --git a/drivers/net/ethernet/ti/am65-cpsw-nuss.c b/drivers/net/ethernet/ti/am65-cpsw-nuss.c
> index 434a31080855..6330540979d7 100644
> --- a/drivers/net/ethernet/ti/am65-cpsw-nuss.c
> +++ b/drivers/net/ethernet/ti/am65-cpsw-nuss.c
> @@ -1310,6 +1310,8 @@ static int am65_cpsw_nuss_rx_packets(struct am65_cpsw_rx_flow *flow,
>   	k3_udma_glue_rx_cppi5_to_dma_addr(rx_chn->rx_chn, &buf_dma);
>   	pkt_len = cppi5_hdesc_get_pktlen(desc_rx);
>   	cppi5_desc_get_tags_ids(&desc_rx->hdr, &port_id, NULL);
> +	/* Port ID is contained in the lower 8-bits of the 16-bit Source Tag */
> +	port_id &= 0xFF;
>   	dev_dbg(dev, "%s rx port_id:%d\n", __func__, port_id);
>   	port = am65_common_get_port(common, port_id);
>   	ndev = port->ndev;


Reviewed-by: Chintan Vankar <c-vankar at ti.com>

Regards,
Chintan.



More information about the linux-arm-kernel mailing list