Donate to e Foundation | Murena handsets with /e/OS | Own a part of Murena! Learn more

Commit 4a630fad authored by Kasin Li's avatar Kasin Li Committed by Rob Clark
Browse files

drm/msm: Fix potential buffer overflow issue



In function submit_create, if nr_cmds or nr_bos is assigned with
negative value, the allocated buffer may be small than intended.
Using this buffer will lead to buffer overflow issue.

Signed-off-by: default avatarKasin Li <donglil@codeaurora.org>
Signed-off-by: default avatarJordan Crouse <jcrouse@codeaurora.org>
Signed-off-by: default avatarRob Clark <robdclark@gmail.com>
parent 51c9fbe6
Loading
Loading
Loading
Loading
+6 −3
Original line number Diff line number Diff line
@@ -31,11 +31,14 @@
#define BO_PINNED   0x2000

static struct msm_gem_submit *submit_create(struct drm_device *dev,
		struct msm_gpu *gpu, int nr_bos, int nr_cmds)
		struct msm_gpu *gpu, uint32_t nr_bos, uint32_t nr_cmds)
{
	struct msm_gem_submit *submit;
	int sz = sizeof(*submit) + (nr_bos * sizeof(submit->bos[0])) +
			(nr_cmds * sizeof(*submit->cmd));
	uint64_t sz = sizeof(*submit) + (nr_bos * sizeof(submit->bos[0])) +
		(nr_cmds * sizeof(submit->cmd[0]));

	if (sz > SIZE_MAX)
		return NULL;

	submit = kmalloc(sz, GFP_TEMPORARY | __GFP_NOWARN | __GFP_NORETRY);
	if (!submit)