mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
* [PATCH] drm: nv04: Add check to avoid out of bounds access
@ 2024-03-31  6:45 Mikhail Kobuk
  2024-04-05 15:53 ` Danilo Krummrich
  0 siblings, 1 reply; 6+ messages in thread
From: Mikhail Kobuk @ 2024-03-31  6:45 UTC (permalink / raw)
  To: Karol Herbst
  Cc: Mikhail Kobuk, Lyude Paul, Danilo Krummrich, David Airlie,
	Daniel Vetter, Ben Skeggs, Francisco Jerez, dri-devel, nouveau,
	linux-kernel, lvc-project, Fedor Pchelkin, Alexey Khoroshilov

Output Resource (dcb->or) value is not guaranteed to be non-zero (i.e.
in drivers/gpu/drm/nouveau/nouveau_bios.c, in 'fabricate_dcb_encoder_table()'
'dcb->or' is assigned value '0' in call to 'fabricate_dcb_output()').

Add check to validate 'dcb->or' before it's used.

Found by Linux Verification Center (linuxtesting.org) with SVACE.

Fixes: 2e5702aff395 ("drm/nouveau: fabricate DCB encoder table for iMac G4")
Signed-off-by: Mikhail Kobuk <m.kobuk@ispras.ru>
---
 drivers/gpu/drm/nouveau/dispnv04/dac.c | 4 ++--
 1 file changed, 2 insertions(+), 2 deletions(-)

diff --git a/drivers/gpu/drm/nouveau/dispnv04/dac.c b/drivers/gpu/drm/nouveau/dispnv04/dac.c
index d6b8e0cce2ac..0c8d4fc95ff3 100644
--- a/drivers/gpu/drm/nouveau/dispnv04/dac.c
+++ b/drivers/gpu/drm/nouveau/dispnv04/dac.c
@@ -428,7 +428,7 @@ void nv04_dac_update_dacclk(struct drm_encoder *encoder, bool enable)
 	struct drm_device *dev = encoder->dev;
 	struct dcb_output *dcb = nouveau_encoder(encoder)->dcb;
 
-	if (nv_gf4_disp_arch(dev)) {
+	if (nv_gf4_disp_arch(dev) && ffs(dcb->or)) {
 		uint32_t *dac_users = &nv04_display(dev)->dac_users[ffs(dcb->or) - 1];
 		int dacclk_off = NV_PRAMDAC_DACCLK + nv04_dac_output_offset(encoder);
 		uint32_t dacclk = NVReadRAMDAC(dev, 0, dacclk_off);
@@ -453,7 +453,7 @@ bool nv04_dac_in_use(struct drm_encoder *encoder)
 	struct drm_device *dev = encoder->dev;
 	struct dcb_output *dcb = nouveau_encoder(encoder)->dcb;
 
-	return nv_gf4_disp_arch(encoder->dev) &&
+	return nv_gf4_disp_arch(encoder->dev) && ffs(dcb->or) &&
 		(nv04_display(dev)->dac_users[ffs(dcb->or) - 1] & ~(1 << dcb->index));
 }
 
-- 
2.44.0


^ permalink raw reply	[flat|nested] 6+ messages in thread

end of thread, other threads:[~2024-04-10 16:24 UTC | newest]

Thread overview: 6+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2024-03-31  6:45 [PATCH] drm: nv04: Add check to avoid out of bounds access Mikhail Kobuk
2024-04-05 15:53 ` Danilo Krummrich
2024-04-05 20:05   ` Lyude Paul
2024-04-08 13:23     ` Danilo Krummrich
2024-04-10 15:39       ` Mikhail Kobuk
2024-04-10 16:24         ` Danilo Krummrich

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®