mirror of
https://github.com/torvalds/linux.git
synced 2026-07-27 17:47:41 +02:00
drm/amdkfd: Add bounds check for AMDKFD_IOC_WAIT_EVENTS
The kfd_wait_on_events ioctl passes a user-supplied num_events parameter directly to alloc_event_waiters() which calls kcalloc() without validation. This allows unprivileged users with /dev/kfd access to trigger large kernel memory allocations, potentially causing memory exhaustion and denial of service via the OOM killer. Add a check to reject num_events values exceeding KFD_SIGNAL_EVENT_LIMIT (4096), which is the maximum number of events a single process can create. Signed-off-by: Sunday Clement <Sunday.Clement@amd.com> Reviewed-by: Harish Kasiviswanathan <Harish.Kasiviswanathan@amd.com> Signed-off-by: Alex Deucher <alexander.deucher@amd.com>
This commit is contained in:
parent
59720bfd8c
commit
39eb6da7ac
|
|
@ -800,6 +800,8 @@ static struct kfd_event_waiter *alloc_event_waiters(uint32_t num_events)
|
|||
struct kfd_event_waiter *event_waiters;
|
||||
uint32_t i;
|
||||
|
||||
if (num_events > KFD_SIGNAL_EVENT_LIMIT)
|
||||
return NULL;
|
||||
event_waiters = kzalloc_objs(struct kfd_event_waiter, num_events);
|
||||
if (!event_waiters)
|
||||
return NULL;
|
||||
|
|
|
|||
Loading…
Reference in New Issue
Block a user