Commit 64ac7c09 authored by Sunil Khatri's avatar Sunil Khatri Committed by Alex Deucher
Browse files

drm/amdgpu: add upper bound check on user inputs in wait ioctl



Huge input values in amdgpu_userq_wait_ioctl can lead to a OOM and
could be exploited.

So check these input value against AMDGPU_USERQ_MAX_HANDLES
which is big enough value for genuine use cases and could
potentially avoid OOM.

v2: squash in Srini's fix

Signed-off-by: default avatarSunil Khatri <sunil.khatri@amd.com>
Reviewed-by: default avatarChristian König <christian.koenig@amd.com>
Signed-off-by: default avatarAlex Deucher <alexander.deucher@amd.com>
(cherry picked from commit fcec012c)
Cc: stable@vger.kernel.org
parent ea78f8c6
Loading
Loading
Loading
Loading
+5 −0
Original line number Diff line number Diff line
@@ -671,6 +671,11 @@ int amdgpu_userq_wait_ioctl(struct drm_device *dev, void *data,
	if (!amdgpu_userq_enabled(dev))
		return -ENOTSUPP;

	if (wait_info->num_syncobj_handles > AMDGPU_USERQ_MAX_HANDLES ||
	    wait_info->num_bo_write_handles > AMDGPU_USERQ_MAX_HANDLES ||
	    wait_info->num_bo_read_handles > AMDGPU_USERQ_MAX_HANDLES)
		return -EINVAL;

	num_read_bo_handles = wait_info->num_bo_read_handles;
	bo_handles_read = memdup_user(u64_to_user_ptr(wait_info->bo_read_handles),
				      size_mul(sizeof(u32), num_read_bo_handles));