mirror of
https://github.com/torvalds/linux.git
synced 2026-09-29 12:24:02 +02:00
drm/nouveau/clk: fix list cursor use after loop in nvkm_clk_ustate_update
If list_for_each_entry() exits without hitting a break then "pstate" is
not a valid pstate pointer. Introduce a "found" variable instead.
The check is reachable from userspace: nvkm_clk_ustate_update() takes the
pstate id straight from the 'pstate' debugfs file, so requesting an id
that is not in clk->states - or any id at all when the perf tables are
broken and the list is empty - makes the pstate->pstate != req test
dereference the list head cast to a struct nvkm_pstate, which is an
out-of-bounds read.
Fixes: 7c85652206 ("drm/nouveau/clk: implement power state and engine clock control in core")
Signed-off-by: Dan Carpenter <dan.carpenter@oracle.com>
[Francesco: rebased on drm-misc-next, expanded the commit message]
Signed-off-by: Francesco Magazzu <postadelmaga@gmail.com>
Reviewed-by: Lyude Paul <lyude@redhat.com>
Signed-off-by: Lyude Paul <lyude@redhat.com>
Link: https://patch.msgid.link/20260918131620.405133-2-postadelmaga@gmail.com
This commit is contained in:
parent
fefd9480ec
commit
aff09d9e37
|
|
@ -473,6 +473,7 @@ static int
|
|||
nvkm_clk_ustate_update(struct nvkm_clk *clk, int req)
|
||||
{
|
||||
struct nvkm_pstate *pstate;
|
||||
bool found = false;
|
||||
int i = 0;
|
||||
|
||||
if (!clk->allow_reclock)
|
||||
|
|
@ -480,12 +481,14 @@ nvkm_clk_ustate_update(struct nvkm_clk *clk, int req)
|
|||
|
||||
if (req != -1 && req != -2) {
|
||||
list_for_each_entry(pstate, &clk->states, head) {
|
||||
if (pstate->pstate == req)
|
||||
if (pstate->pstate == req) {
|
||||
found = true;
|
||||
break;
|
||||
}
|
||||
i++;
|
||||
}
|
||||
|
||||
if (pstate->pstate != req)
|
||||
if (!found)
|
||||
return -EINVAL;
|
||||
req = i;
|
||||
}
|
||||
|
|
|
|||
Loading…
Reference in New Issue
Block a user