Linux kernel mirror (for testing) git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git
kernel os linux
1
fork

Configure Feed

Select the types of activity you want to include in your feed.

drm/amdgpu: add upper bound check on user inputs in wait ioctl

Huge input values in amdgpu_userq_wait_ioctl can lead to a OOM and
could be exploited.

So check these input value against AMDGPU_USERQ_MAX_HANDLES
which is big enough value for genuine use cases and could
potentially avoid OOM.

v2: squash in Srini's fix

Signed-off-by: Sunil Khatri <sunil.khatri@amd.com>
Reviewed-by: Christian König <christian.koenig@amd.com>
Signed-off-by: Alex Deucher <alexander.deucher@amd.com>
(cherry picked from commit fcec012c664247531aed3e662f4280ff804d1476)
Cc: stable@vger.kernel.org

authored by

Sunil Khatri and committed by
Alex Deucher
64ac7c09 ea78f8c6

+5
+5
drivers/gpu/drm/amd/amdgpu/amdgpu_userq_fence.c
··· 671 671 if (!amdgpu_userq_enabled(dev)) 672 672 return -ENOTSUPP; 673 673 674 + if (wait_info->num_syncobj_handles > AMDGPU_USERQ_MAX_HANDLES || 675 + wait_info->num_bo_write_handles > AMDGPU_USERQ_MAX_HANDLES || 676 + wait_info->num_bo_read_handles > AMDGPU_USERQ_MAX_HANDLES) 677 + return -EINVAL; 678 + 674 679 num_read_bo_handles = wait_info->num_bo_read_handles; 675 680 bo_handles_read = memdup_user(u64_to_user_ptr(wait_info->bo_read_handles), 676 681 size_mul(sizeof(u32), num_read_bo_handles));