From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from us-smtp-delivery-124.mimecast.com (us-smtp-delivery-124.mimecast.com [170.10.133.124]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 6488E3DEFFE for ; Tue, 18 Aug 2026 19:10:36 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=170.10.133.124 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787080237; cv=none; b=k7xunQn6UQS/pRUoRjxB+cP0S46H9KLqAPFb61OuPqtXlNlC+E2j7PCJqLHZ/KsT86VLEOovtBaAYeMQ6f0jmgfwD/4XiWnenq7919UH55lcg4nRBylyMi8VbxXZjJVpKRU0Bxj78sLLN8gL5unSzQbnyx1yMMvM86UM9O/IEsg= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787080237; c=relaxed/simple; bh=DAdsEC0Uuf+qib7V+KURez0DyL7Z6gLPhSiAW/SJ1NY=; h=Message-ID:Subject:From:To:Cc:Date:In-Reply-To:References: Content-Type:MIME-Version; b=IJnJVlPtSWR4CLtacg45iL7DQenHaBXq9E3xnZcQt942AfF4IyP/OhvfjgZ8Rfwee/EeMAwIEff6jv3IRadVRty4iWYYcmfGRloLWQU8PnaHnyIhE0dcor+zKEHyXY/NkP+ls1ypjrQn+MgVW5KNgMIE65Tyjm4Kp89Z8lk9UMU= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com; spf=pass smtp.mailfrom=redhat.com; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b=SIOwfCXx; dkim=pass (2048-bit key) header.d=redhat.com header.i=@redhat.com header.b=qWPDAbDO; arc=none smtp.client-ip=170.10.133.124 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=redhat.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b="SIOwfCXx"; dkim=pass (2048-bit key) header.d=redhat.com header.i=@redhat.com header.b="qWPDAbDO" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1787080235; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=9kbwhzYfa9+JR+FXCNWXDj5upifP6ZSYoTxSiBsZODs=; b=SIOwfCXxvMNMlzyuM0Q1In188bqGanZCz9GDhqB026wcnuazROc86U8PuE42JkW4SyVBf0 JnH+J8iZZvT3tfoApqZ+E5xLuHh45Aqq7m1NjeMYefLYwAUmOtGBQJT2q1h1qpK00E/SjM wKp53SKfDJ2Ea0fZcGjGmzGb+nQqwpM= Received: from mail-qt1-f197.google.com (mail-qt1-f197.google.com [209.85.160.197]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-446-Yyhm3W5YOXS3zqVii8oonQ-1; Tue, 18 Aug 2026 15:10:33 -0400 X-MC-Unique: Yyhm3W5YOXS3zqVii8oonQ-1 X-Mimecast-MFC-AGG-ID: Yyhm3W5YOXS3zqVii8oonQ_1787080233 Received: by mail-qt1-f197.google.com with SMTP id d75a77b69052e-52ce3c7cb2eso2486561cf.3 for ; Tue, 18 Aug 2026 12:10:33 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=google; t=1787080233; x=1787685033; darn=vger.kernel.org; h=mime-version:user-agent:content-transfer-encoding:content-type :references:in-reply-to:date:cc:to:from:subject:message-id:from:to :cc:subject:date:message-id:reply-to:content-type; bh=9kbwhzYfa9+JR+FXCNWXDj5upifP6ZSYoTxSiBsZODs=; b=qWPDAbDOBTTgvEkbT4qQp3HLVzr1DRDhoJIEhW1d6mTqQz1bx09U1/AdbxyT8U2cEc fgFxRz2OKjJTUJx8nfyBbihU7mdxG/I3LThg/XLZ8/bG6qx1wzDBYErOf5ohGkVmPQEI m6phxtxBe6STQLwj/M5CiDt7JhRP1eT95AOyHaofwj9WOaa6ox+/SHEE3gsOfFirHzkv WR7tQpDa8L7bewdsSoNv0jCPcZwcuNqZGVxBJOhh+A+7FQCtL9kbzKfdLtvtrAN+X6ad O2Uya3u9Hdyhg3IzFtNzhaHuu5+NMR6G10vMQT8yoHopIKvn1L7KJinQoWwITbyttQEl jBqQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1787080233; x=1787685033; h=mime-version:user-agent:content-transfer-encoding:content-type :references:in-reply-to:date:cc:to:from:subject:message-id:x-gm-gg :x-gm-message-state:from:to:cc:subject:date:message-id:reply-to :content-type; bh=9kbwhzYfa9+JR+FXCNWXDj5upifP6ZSYoTxSiBsZODs=; b=HzntRFYrjGfI3CE2eKkYKDgDc943nBlUkKaA0llR80rvRj20CD3hN3WlL088iod/v7 B18P31a8P90qsSN4kjTcB2ul4uqaPVC1LJY9eIOppO21U1vnGHMo8FQ6CnEq6jxFeItn j27zmfctCOg/dLRrrXPmjNSEm7V1vjK5rAOUgCL+n8uaL75G9WYGzRExOaEguP2PfAqD VVhUksiDVGprOM/nA+hrKqjdVurpJLsCFXgXvRZy+r0QfyZtP0vV7j1eQ9RiT6SYQPqT NHngQfsRXTmg/g0h+vVjPLGeftH/+EPV6Lnb/rhYePK3iyvOemT97L4QX+5bQK/CIbrI 00gA== X-Forwarded-Encrypted: i=1; AHgh+RoSpRSjQzDKyLNIKbLNxxkx5mW17sJgKSFo0awbw1rf2HH07PsrQztuDHA3t6EiPDPbtZKc35puFax9ZO0=@vger.kernel.org X-Gm-Message-State: AOJu0Yw96aE6CWnGd5oG2f2fvBBFSPzqwH+YTgTHDxu/UdJkihWxy/k7 SvqRN+G9T8FLluA0jk9NJliO6o3XZciwEHspB83eyR7sg/7JzcuXPNLu15y6ylIUEwxva5Jwu3v sPPIlZrR/hjn2MZjQ4qB32CYusCpnwmd6Jexax/H0RA8fXM5TA9UQR6VjomI4OB5Qfz4VUVcL+g == X-Gm-Gg: AR+sD12DYCagrNi/XhBX9gPce30LU4wrYhV3D29Ov8LjyFQOcoO6Vdvsc83Gk2M2pwQ ZQim5CtEaHf3EU0jbhUFVaPJamFeuef+mb1BpoC7xkUNMljlokyGO+8a+D2exI6LWtZ6EFOCbKN KcXdg1kYsamM0hLKh5Q4/OV8ym0q5pfk/usyfUa5e/vykYF48R7gUP0NF9Xy5mK8VoqzzekAtPn dlDmeqYYfR0OezL1claK+MFRsOtdvJZJmUoQEeLdwbWJbDq9fyeHbe6C3GUNdiK8ir9XMoY+3tG kn4ZiXjKusijb8/ExUAx/E7RmX2DFH0uctr42QuGAlbFli9vJjORcShcO8xhehGUJ8T6YbkM X-Received: by 2002:ac8:5749:0:b0:52b:4e1f:941d with SMTP id d75a77b69052e-52dd30d0802mr3569001cf.6.1787080233318; Tue, 18 Aug 2026 12:10:33 -0700 (PDT) X-Received: by 2002:ac8:5749:0:b0:52b:4e1f:941d with SMTP id d75a77b69052e-52dd30d0802mr3568331cf.6.1787080232870; Tue, 18 Aug 2026 12:10:32 -0700 (PDT) Received: from [192.168.8.4] ([100.0.180.93]) by smtp.gmail.com with ESMTPSA id d75a77b69052e-52db623bfb0sm44781051cf.24.2026.08.18.12.10.30 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 18 Aug 2026 12:10:31 -0700 (PDT) Message-ID: <7ba5804dccefb1fde985f19242f6bad94aaefcc8.camel@redhat.com> Subject: Re: [PATCH] drm/nouveau: reject zero-size notifier object allocation From: lyude@redhat.com To: Zhenhao Wan , Danilo Krummrich , Maarten Lankhorst , Maxime Ripard , Thomas Zimmermann , David Airlie , Simona Vetter , Ben Skeggs Cc: dri-devel@lists.freedesktop.org, nouveau@lists.freedesktop.org, linux-kernel@vger.kernel.org, Yuhao Jiang , stable@vger.kernel.org Date: Tue, 18 Aug 2026 15:10:30 -0400 In-Reply-To: <20260813-nouveau-abi16-notifierobj-zero-size-v1-1-20dee38077cb@gmail.com> References: <20260813-nouveau-abi16-notifierobj-zero-size-v1-1-20dee38077cb@gmail.com> Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: quoted-printable User-Agent: Evolution 3.58.3 (3.58.3-1.fc43) Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Reviewed-by: Lyude Paul Will push to drm-misc-fixes in a moment On Thu, 2026-08-13 at 21:14 +0800, Zhenhao Wan wrote: > nouveau_abi16_ioctl_notifierobj_alloc() passes the userspace- > controlled > info->size to nvkm_mm_head() as both size_max and size_min without a > lower > bound.=C2=A0 A zero size satisfies the allocator's "e - s < size_min" gat= e > (size_min =3D=3D 0 makes the unsigned comparison inert) and yields a > zero-length node, after which >=20 > args.limit =3D ntfy->node->offset + ntfy->node->length - 1; >=20 > underflows (offset 0, length 0 -> 0xffffffff) into an oversized ~4 > GiB DMA > window.=C2=A0 The dma object constructor only rejects start > limit, so > the > validly ordered [base, base + 0xffffffff] range passes and is > programmed > into the GPU DMA context.=C2=A0 The ioctl is DRM_RENDER_ALLOW, so any > render > node client can trigger this on pre-Fermi hardware. >=20 > Reject a zero-size request before allocating anything. >=20 > Fixes: ebb945a94bba ("drm/nouveau: port all engines to new engine > module format") > Reported-by: Yuhao Jiang > Assisted-by: Claude:claude-opus-5 > Cc: stable@vger.kernel.org > Signed-off-by: Zhenhao Wan > --- > =C2=A0drivers/gpu/drm/nouveau/nouveau_abi16.c | 4 ++++ > =C2=A01 file changed, 4 insertions(+) >=20 > diff --git a/drivers/gpu/drm/nouveau/nouveau_abi16.c > b/drivers/gpu/drm/nouveau/nouveau_abi16.c > index 291203121f0c..8d139bbb2934 100644 > --- a/drivers/gpu/drm/nouveau/nouveau_abi16.c > +++ b/drivers/gpu/drm/nouveau/nouveau_abi16.c > @@ -660,6 +660,10 @@ > nouveau_abi16_ioctl_notifierobj_alloc(ABI16_IOCTL_ARGS) > =C2=A0 if (unlikely(device->info.family >=3D > NV_DEVICE_INFO_V0_FERMI)) > =C2=A0 return nouveau_abi16_put(abi16, -EINVAL); > =C2=A0 > + /* zero size yields a zero-length node, underflowing > args.limit */ > + if (unlikely(!info->size)) > + return nouveau_abi16_put(abi16, -EINVAL); > + > =C2=A0 chan =3D nouveau_abi16_chan(abi16, info->channel); > =C2=A0 if (!chan) > =C2=A0 return nouveau_abi16_put(abi16, -ENOENT); >=20 > --- > base-commit: db2ddb87143519e20a95aa36c60b36107b736a58 > change-id: 20260813-nouveau-abi16-notifierobj-zero-size-5d3888d36b57 >=20 > Best regards, > --=C2=A0=20 > Zhenhao Wan