linux/drivers/video/fbdev/kyro
Danila Chernetsov 7b5c7bc55e fbdev: kyro: Validate overlay viewport coordinates
The overlay viewport end coordinates are computed from the viewport
origin and dimensions using 32-bit unsigned arithmetic. Large input
values can cause these calculations to wrap around before the resulting
coordinates are passed to SetOverlayViewPort().

SetOverlayViewPort() packs the viewport coordinates into 16-bit
register fields. The X coordinates are additionally adjusted by +2
and +1 before being written. Validate the coordinate calculations
for 32-bit wraparound and ensure that the adjusted coordinates fit
within their 16-bit register fields before calling
SetOverlayViewPort().

Found by Linux Verification Center (linuxtesting.org) with SVACE.

Fixes: 1da177e4c3 ("Linux-2.6.12-rc2")
Signed-off-by: Danila Chernetsov <listdansp@mail.ru>
Signed-off-by: Helge Deller <deller@gmx.de>
2026-08-10 08:13:25 +02:00
..
fbdev.c fbdev: kyro: Validate overlay viewport coordinates 2026-08-10 08:13:25 +02:00
Makefile
STG4000InitDevice.c fbdev: kyro: make some const read-only arrays static and reduce type size 2023-07-20 07:52:54 +02:00
STG4000Interface.h
STG4000OverlayDevice.c video: fbdev: kyrofb: remove set but not used variable 'ulScaleRight' 2020-03-02 16:32:11 +01:00
STG4000Ramdac.c
STG4000Reg.h
STG4000VTG.c