]> git.ipfire.org Git - thirdparty/kernel/linux.git/commitdiff
drm/log: Fix out-of-bounds read on empty message length
authorShixiong Ou <oushixiong@kylinos.cn>
Wed, 29 Jul 2026 08:45:17 +0000 (16:45 +0800)
committerJocelyn Falempe <jfalempe@redhat.com>
Thu, 13 Aug 2026 13:47:50 +0000 (15:47 +0200)
drm_log_draw_kmsg_record() accesses s[len - 1] to strip the trailing
newline, but len is unsigned int. If len is 0, the subtraction wraps
to UINT_MAX, causing an out-of-bounds read.

Add an early return when len is 0.

Fixes: 25e2c2a3eff5 ("drm/log: Color the timestamp, to improve readability")
Signed-off-by: Shixiong Ou <oushixiong@kylinos.cn>
Reviewed-by: Jocelyn Falempe <jfalempe@redhat.com>
Link: https://patch.msgid.link/20260729084520.688087-1-oushixiong1025@163.com
Signed-off-by: Jocelyn Falempe <jfalempe@redhat.com>
drivers/gpu/drm/clients/drm_log.c

index a3259b8f233337d7768c9d1e539f0887f55634da..f23a92f826c926a2723af3522c6c0e8a11593d8d 100644 (file)
@@ -160,6 +160,9 @@ static void drm_log_draw_kmsg_record(struct drm_log_scanout *scanout,
 {
        u32 prefix_len = 0;
 
+       if (!len)
+               return;
+
        if (len > TS_PREFIX_LEN && s[0] == '[' && s[6] == '.' && s[TS_PREFIX_LEN] == ']')
                prefix_len = TS_PREFIX_LEN + 1;