From: "Christian König" <christian.koenig@amd.com>
To: hackyzh002 <hackyzh002@gmail.com>, alexander.deucher@amd.com
Cc: Xinhui.Pan@amd.com, airlied@gmail.com, daniel@ffwll.ch,
sumit.semwal@linaro.org, amd-gfx@lists.freedesktop.org,
dri-devel@lists.freedesktop.org, linux-kernel@vger.kernel.org,
linux-media@vger.kernel.org, linaro-mm-sig@lists.linaro.org
Subject: Re: [PATCH 1/2] drm/radeon: Fix integer overflow in radeon_cs_parser_init
Date: Wed, 19 Apr 2023 10:37:34 +0200 [thread overview]
Message-ID: <e3005eb6-e37f-bbb1-446b-15b2bc02b69f@amd.com> (raw)
In-Reply-To: <20230419042407.69001-1-hackyzh002@gmail.com>
Am 19.04.23 um 06:24 schrieb hackyzh002:
> The type of size is unsigned, if size is 0x40000000, there will be an
> integer overflow, size will be zero after size *= sizeof(uint32_t),
> will cause uninitialized memory to be referenced later
Well good catch, but this is actually harmless.
Userspace can control the memory which is referenced here anyway and
since the size would be zero when copying anything back to userspace
this is also not an information leak.
>
> Signed-off-by: hackyzh002 <hackyzh002@gmail.com>
> ---
> drivers/gpu/drm/radeon/radeon_cs.c | 4 ++--
> 1 file changed, 2 insertions(+), 2 deletions(-)
>
> diff --git a/drivers/gpu/drm/radeon/radeon_cs.c b/drivers/gpu/drm/radeon/radeon_cs.c
> index 46a27ebf4..472c29050 100644
> --- a/drivers/gpu/drm/radeon/radeon_cs.c
> +++ b/drivers/gpu/drm/radeon/radeon_cs.c
> @@ -270,7 +270,7 @@ int radeon_cs_parser_init(struct radeon_cs_parser *p, void *data)
> {
> struct drm_radeon_cs *cs = data;
> uint64_t *chunk_array_ptr;
> - unsigned size, i;
> + u64 size, i;
Please use size_t for size only and not "i".
> u32 ring = RADEON_CS_RING_GFX;
> s32 priority = 0;
>
> @@ -347,7 +347,7 @@ int radeon_cs_parser_init(struct radeon_cs_parser *p, void *data)
> continue;
> }
>
> - p->chunks[i].kdata = kvmalloc_array(size, sizeof(uint32_t), GFP_KERNEL);
> + p->chunks[i].kdata = kvcalloc(size, sizeof(uint32_t), GFP_KERNEL);
Please drop that chunk.
Regards,
Christian.
> size *= sizeof(uint32_t);
> if (p->chunks[i].kdata == NULL) {
> return -ENOMEM;
prev parent reply other threads:[~2023-04-19 8:37 UTC|newest]
Thread overview: 2+ messages / expand[flat|nested] mbox.gz Atom feed top
2023-04-19 4:24 hackyzh002
2023-04-19 8:37 ` Christian König [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=e3005eb6-e37f-bbb1-446b-15b2bc02b69f@amd.com \
--to=christian.koenig@amd.com \
--cc=Xinhui.Pan@amd.com \
--cc=airlied@gmail.com \
--cc=alexander.deucher@amd.com \
--cc=amd-gfx@lists.freedesktop.org \
--cc=daniel@ffwll.ch \
--cc=dri-devel@lists.freedesktop.org \
--cc=hackyzh002@gmail.com \
--cc=linaro-mm-sig@lists.linaro.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-media@vger.kernel.org \
--cc=sumit.semwal@linaro.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
Powered by JetHome