mirror of
https://github.com/torvalds/linux.git
synced 2026-09-22 04:34:03 +02:00
drm/i915/hdcp: check streams[] bounds before overflow
The data->streams[] overflow check is done after the buffer overflow has
already happened. Move the overflow check before the write.
Side note, emitting a warning splat with a backtrace might be overkill
here, but prefer not changing the behaviour other than not doing the
overrun.
Discovered using AI-assisted static analysis confirmed by Intel Product
Security.
Reported-by: Martin Hodo <martin.hodo@intel.com>
Fixes: e03187e12c ("drm/i915/hdcp: MST streams support in hdcp port_data")
Cc: stable@vger.kernel.org # v5.12+
Cc: Anshuman Gupta <anshuman.gupta@intel.com>
Cc: Suraj Kandpal <suraj.kandpal@intel.com>
Reviewed-by: Suraj Kandpal <suraj.kandpal@intel.com>
Link: https://patch.msgid.link/20260625170304.1104723-1-jani.nikula@intel.com
Signed-off-by: Jani Nikula <jani.nikula@intel.com>
This commit is contained in:
parent
4dfcc789a1
commit
9284ab3b6e
|
|
@ -145,6 +145,9 @@ intel_hdcp_required_content_stream(struct intel_atomic_state *state,
|
|||
if (!new_conn_state || !new_conn_state->crtc)
|
||||
continue;
|
||||
|
||||
if (drm_WARN_ON(display->drm, data->k >= INTEL_NUM_PIPES(display)))
|
||||
return -EINVAL;
|
||||
|
||||
data->streams[data->k].stream_id =
|
||||
intel_conn_to_vcpi(state, connector);
|
||||
data->k++;
|
||||
|
|
@ -155,7 +158,7 @@ intel_hdcp_required_content_stream(struct intel_atomic_state *state,
|
|||
}
|
||||
drm_connector_list_iter_end(&conn_iter);
|
||||
|
||||
if (drm_WARN_ON(display->drm, data->k > INTEL_NUM_PIPES(display) || data->k == 0))
|
||||
if (drm_WARN_ON(display->drm, !data->k))
|
||||
return -EINVAL;
|
||||
|
||||
/*
|
||||
|
|
|
|||
Loading…
Reference in New Issue
Block a user