Donate to e Foundation | Murena handsets with /e/OS | Own a part of Murena! Learn more

Commit 9be5b16d authored by Kasin Li's avatar Kasin Li
Browse files

drm/msm: Fix potential buffer overflow issue



In function submit_create, if nr_cmds or nr_bos is assigned with
negative value, the allocated buffer may be small than intended.
Using this buffer will lead to buffer overflow issue.

Change-Id: I0b61cccffd836e2dd3c859446470af4b6451b9ed
Signed-off-by: default avatarKasin Li <donglil@codeaurora.org>
parent e68546c8
Loading
Loading
Loading
Loading
+5 −2
Original line number Diff line number Diff line
@@ -34,12 +34,15 @@ static inline void __user *to_user_ptr(u64 address)
}

static struct msm_gem_submit *submit_create(struct drm_device *dev,
		struct msm_gpu *gpu, int nr_cmds, int nr_bos)
		struct msm_gpu *gpu, uint32_t nr_cmds, uint32_t nr_bos)
{
	struct msm_gem_submit *submit;
	int sz = sizeof(*submit) + (nr_bos * sizeof(submit->bos[0])) +
	uint64_t sz = sizeof(*submit) + (nr_bos * sizeof(submit->bos[0])) +
		(nr_cmds * sizeof(submit->cmd[0]));

	if (sz > SIZE_MAX)
		return NULL;

	submit = kmalloc(sz, GFP_TEMPORARY | __GFP_NOWARN | __GFP_NORETRY);
	if (submit) {
		submit->dev = dev;