mirror of
https://github.com/torvalds/linux.git
synced 2026-07-27 09:36:22 +02:00
drm/sysfb: Avoid truncating maximum stride
Passing a maximum as 64-bit type to drm_sysfb_get_validated_int0() can truncate the value to 32 bits. Use drm_sysfb_get_validated_size0(), which uses 64-bit arithmetics. Then test the returned stride against the limits of int to avoid truncations in the returned value. A valid stride is in the range of [1, INT_MAX] inclusive. Signed-off-by: Thomas Zimmermann <tzimmermann@suse.de> Reported-by: Sashiko <sashiko-bot@kernel.org> Closes: https://lore.kernel.org/dri-devel/20260617114016.5A5991F000E9@smtp.kernel.org/ Fixes:32ae90c66f("drm/sysfb: Add efidrm for EFI displays") Fixes:a84eb6abe2("drm/sysfb: Add vesadrm for VESA displays") Cc: Thomas Zimmermann <tzimmermann@suse.de> Cc: Javier Martinez Canillas <javierm@redhat.com> Cc: dri-devel@lists.freedesktop.org Cc: <stable@vger.kernel.org> # v6.16+ Reviewed-by: Javier Martinez Canillas <javierm@redhat.com> Link: https://patch.msgid.link/20260618084327.46567-5-tzimmermann@suse.de
This commit is contained in:
parent
7bab0f09d7
commit
9206b22fb9
|
|
@ -57,11 +57,17 @@ int drm_sysfb_get_stride_si(struct drm_device *dev, const struct screen_info *si
|
|||
unsigned int width, unsigned int height, u64 size)
|
||||
{
|
||||
u64 lfb_linelength = si->lfb_linelength;
|
||||
s64 stride;
|
||||
|
||||
if (!lfb_linelength)
|
||||
lfb_linelength = drm_format_info_min_pitch(format, 0, width);
|
||||
|
||||
return drm_sysfb_get_validated_int0(dev, "stride", lfb_linelength, div64_u64(size, height));
|
||||
stride = drm_sysfb_get_validated_size0(dev, "stride", lfb_linelength,
|
||||
div64_u64(size, height));
|
||||
if (stride < INT_MIN || stride > INT_MAX)
|
||||
return -EINVAL;
|
||||
|
||||
return (int)stride; /* stride or negative errno code */
|
||||
}
|
||||
EXPORT_SYMBOL(drm_sysfb_get_stride_si);
|
||||
|
||||
|
|
|
|||
Loading…
Reference in New Issue
Block a user