]> git.ipfire.org Git - thirdparty/linux.git/commit
drm/vmwgfx: validate DRAW_PRIMITIVES header size before division
authorZack Rusin <zack.rusin@broadcom.com>
Tue, 5 May 2026 22:22:27 +0000 (18:22 -0400)
committerZack Rusin <zack.rusin@broadcom.com>
Mon, 27 Jul 2026 15:29:24 +0000 (11:29 -0400)
commit85891d174707d8bddcec7a888fb4e1d17def34f3
treec7e61ab1c16768ce0d3b5bc6a13e94c2c4588322
parentf739416dc555fa205a785e5135d73fa39b26f35d
drm/vmwgfx: validate DRAW_PRIMITIVES header size before division

vmw_cmd_draw() computes

maxnum = (header->size - sizeof(cmd->body)) / sizeof(*decl);

where header->size is u32 and is taken straight from the user-supplied
command stream.  When header->size is less than sizeof(cmd->body) the
unsigned subtraction wraps to nearly 4 GiB, producing a huge maxnum.
Any user-controlled cmd->body.numVertexDecls then passes the bound and
the loop dereferences decl[i] far past the end of the kernel command
bounce buffer, producing an out-of-bounds read of kernel memory.

Reject undersized headers up front.

Fixes: 7a73ba7469cb ("drm/vmwgfx: Use TTM handles instead of SIDs as user-space surface handles.")
Cc: stable@vger.kernel.org
Assisted-by: Claude:claude-opus-4.7
Signed-off-by: Zack Rusin <zack.rusin@broadcom.com>
Reviewed-by: Ian Forbes <ian.forbes@broadcom.com>
Link: https://patch.msgid.link/20260505222728.519626-7-zack.rusin@broadcom.com
drivers/gpu/drm/vmwgfx/vmwgfx_execbuf.c