mirror of
https://github.com/torvalds/linux.git
synced 2026-09-27 19:42:03 +02:00
drm/panthor: reject firmware sections with oversized data
In panthor_fw_load_section_entry(), the data size to copy is calculated
without validating it against the allocated section_size:
section->data.size = hdr.data.end - hdr.data.start;
If a crafted firmware sets data.size larger than the allocated memory,
this could cause a heap buffer overflow in panthor_fw_init_section_mem()
memcpy(section->mem->kmap, section->data.buf, section->data.size);
Additionally, if the section->data.size exceeds the BO size, could this
memset underflow the size calculation, leading to a massive out-of-bounds
zeroing of kernel memory?
memset(section->mem->kmap + section->data.size, 0,
panthor_kernel_bo_size(section->mem) - section->data.size);
Reject section entries whose initial data is larger than the section size.
Fixes: 2718d91816 ("drm/panthor: Add the FW logical block")
Cc: stable@vger.kernel.org
Signed-off-by: Osama Abdelkader <osama.abdelkader@gmail.com>
Reviewed-by: Steven Price <steven.price@arm.com>
Reviewed-by: Boris Brezillon <boris.brezillon@collabora.com>
Link: https://patch.msgid.link/20260716143939.21903-1-osama.abdelkader@gmail.com
Signed-off-by: Steven Price <steven.price@arm.com>
This commit is contained in:
parent
112badb724
commit
a3caaa0680
|
|
@ -545,6 +545,7 @@ static int panthor_fw_load_section_entry(struct panthor_device *ptdev,
|
|||
struct panthor_fw_binary_section_entry_hdr hdr;
|
||||
struct panthor_fw_section *section;
|
||||
u32 section_size;
|
||||
u32 data_size;
|
||||
u32 name_len;
|
||||
int ret;
|
||||
|
||||
|
|
@ -595,6 +596,13 @@ static int panthor_fw_load_section_entry(struct panthor_device *ptdev,
|
|||
return -EINVAL;
|
||||
}
|
||||
|
||||
section_size = hdr.va.end - hdr.va.start;
|
||||
data_size = hdr.data.end - hdr.data.start;
|
||||
if (data_size > section_size) {
|
||||
drm_err(&ptdev->base, "Firmware corrupted, section data exceeds section size\n");
|
||||
return -EINVAL;
|
||||
}
|
||||
|
||||
name_len = iter->size - iter->offset;
|
||||
|
||||
section = drmm_kzalloc(&ptdev->base, sizeof(*section), GFP_KERNEL);
|
||||
|
|
@ -603,7 +611,7 @@ static int panthor_fw_load_section_entry(struct panthor_device *ptdev,
|
|||
|
||||
list_add_tail(§ion->node, &ptdev->fw->sections);
|
||||
section->flags = hdr.flags;
|
||||
section->data.size = hdr.data.end - hdr.data.start;
|
||||
section->data.size = data_size;
|
||||
|
||||
if (section->data.size > 0) {
|
||||
void *data = drmm_kmalloc(&ptdev->base, section->data.size, GFP_KERNEL);
|
||||
|
|
@ -626,7 +634,6 @@ static int panthor_fw_load_section_entry(struct panthor_device *ptdev,
|
|||
section->name = name;
|
||||
}
|
||||
|
||||
section_size = hdr.va.end - hdr.va.start;
|
||||
if (section_size) {
|
||||
u32 cache_mode = hdr.flags & CSF_FW_BINARY_IFACE_ENTRY_CACHE_MODE_MASK;
|
||||
struct panthor_gem_object *bo;
|
||||
|
|
|
|||
Loading…
Reference in New Issue
Block a user