mirror of
https://github.com/torvalds/linux.git
synced 2026-09-24 06:24:02 +02:00
drm/amdgpu: bounds check atom indirect io method
Bound indirect io method execution by the BIOS size to avoid out-of-bounds reads. Signed-off-by: Lijo Lazar <lijo.lazar@amd.com> Reviewed-by: Hawking Zhang <Hawking.Zhang@amd.com> Signed-off-by: Alex Deucher <alexander.deucher@amd.com>
This commit is contained in:
parent
1e453f7e77
commit
0b2becfc28
|
|
@ -114,8 +114,10 @@ static uint32_t atom_iio_execute(struct atom_context *ctx, int base,
|
|||
uint32_t index, uint32_t data)
|
||||
{
|
||||
uint32_t temp = 0xCDCDCDCD;
|
||||
int start = base;
|
||||
|
||||
while (1)
|
||||
/* IIO opcodes read up to base+3; keep within the BIOS image */
|
||||
while (base + 3 < ctx->bios_size)
|
||||
switch (CU8(base)) {
|
||||
case ATOM_IIO_NOP:
|
||||
base++;
|
||||
|
|
@ -180,6 +182,9 @@ static uint32_t atom_iio_execute(struct atom_context *ctx, int base,
|
|||
pr_info("Unknown IIO opcode\n");
|
||||
return 0;
|
||||
}
|
||||
|
||||
pr_info("IIO method starting at offset %d runs past BIOS image\n", start);
|
||||
return 0;
|
||||
}
|
||||
|
||||
static uint32_t atom_get_src_int(atom_exec_context *ctx, uint8_t attr,
|
||||
|
|
|
|||
Loading…
Reference in New Issue
Block a user