mirror of
https://github.com/torvalds/linux.git
synced 2026-09-13 15:40:03 +02:00
drm/rockchip: analogix_dp: fix unchecked bound endpoint name length
rockchip_dp_drm_encoder_enable() uses sprintf() to format a device tree
path into a 32-byte stack buffer. Device tree paths are not limited to
this size, so a sufficiently long path can overflow the buffer.
Use snprintf() with the destination size to truncate the generated name
and keep the writes within bounds.
Fixes: 729f8eefdc ("drm/rockchip: analogix_dp: Add support for RK3588")
Cc: stable@vger.kernel.org
Signed-off-by: Yudi Yang <2000jedi@gmail.com>
Signed-off-by: Heiko Stuebner <heiko@sntech.de>
Link: https://patch.msgid.link/20260901195511.2761251-1-2000jedi@gmail.com
This commit is contained in:
parent
d3609b5408
commit
bc69439d98
|
|
@ -241,10 +241,11 @@ static void rockchip_dp_drm_encoder_enable(struct drm_encoder *encoder,
|
|||
of_graph_get_remote_port(endpoint.local_node);
|
||||
|
||||
of_property_read_u32(remote_port, "reg", &port_id);
|
||||
sprintf(name, "%s vp%d", remote_port_parent->full_name, port_id);
|
||||
snprintf(name, sizeof(name), "%s vp%d",
|
||||
remote_port_parent->full_name, port_id);
|
||||
} else {
|
||||
sprintf(name, "%s %s",
|
||||
remote_port_parent->full_name, endpoint.id ? "vopl" : "vopb");
|
||||
snprintf(name, sizeof(name), "%s %s",
|
||||
remote_port_parent->full_name, endpoint.id ? "vopl" : "vopb");
|
||||
}
|
||||
|
||||
DRM_DEV_DEBUG(dp->dev, "vop %s output to dp\n", (ret) ? "LIT" : "BIG");
|
||||
|
|
|
|||
Loading…
Reference in New Issue
Block a user