Skip to content

Commit 64ac7c0

Browse files
amd-sukhatrialexdeucher
authored andcommitted
drm/amdgpu: add upper bound check on user inputs in wait ioctl
Huge input values in amdgpu_userq_wait_ioctl can lead to a OOM and could be exploited. So check these input value against AMDGPU_USERQ_MAX_HANDLES which is big enough value for genuine use cases and could potentially avoid OOM. v2: squash in Srini's fix Signed-off-by: Sunil Khatri <sunil.khatri@amd.com> Reviewed-by: Christian König <christian.koenig@amd.com> Signed-off-by: Alex Deucher <alexander.deucher@amd.com> (cherry picked from commit fcec012) Cc: stable@vger.kernel.org
1 parent ea78f8c commit 64ac7c0

1 file changed

Lines changed: 5 additions & 0 deletions

File tree

drivers/gpu/drm/amd/amdgpu/amdgpu_userq_fence.c

Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -671,6 +671,11 @@ int amdgpu_userq_wait_ioctl(struct drm_device *dev, void *data,
671671
if (!amdgpu_userq_enabled(dev))
672672
return -ENOTSUPP;
673673

674+
if (wait_info->num_syncobj_handles > AMDGPU_USERQ_MAX_HANDLES ||
675+
wait_info->num_bo_write_handles > AMDGPU_USERQ_MAX_HANDLES ||
676+
wait_info->num_bo_read_handles > AMDGPU_USERQ_MAX_HANDLES)
677+
return -EINVAL;
678+
674679
num_read_bo_handles = wait_info->num_bo_read_handles;
675680
bo_handles_read = memdup_user(u64_to_user_ptr(wait_info->bo_read_handles),
676681
size_mul(sizeof(u32), num_read_bo_handles));

0 commit comments

Comments
 (0)