From: Greg Kroah-Hartman Date: Wed, 29 Jul 2026 11:19:28 +0000 (+0200) Subject: 6.18-stable patches X-Git-Tag: v6.1.179~55 X-Git-Url: http://git.ipfire.org/gitweb/?a=commitdiff_plain;h=0eb60252fcb494292911fafbd9d1bae1f884e513;p=thirdparty%2Fkernel%2Fstable-queue.git 6.18-stable patches added patches: drm-amd-display-detect_link_and_local_sink-dp-alt-mode-timeout-path-leaks-prev_sink-reference.patch drm-amd-display-handle-struct-drm_plane_state.ignore_damage_clips.patch drm-amdgpu-sdma5.0-replace-bug_on-with-warn_on.patch drm-amdgpu-sdma5.2-replace-bug_on-with-warn_on.patch drm-amdgpu-sdma6.0-replace-bug_on-with-warn_on.patch drm-amdgpu-sdma7.0-replace-bug_on-with-warn_on.patch drm-i915-hdcp-check-streams-bounds-before-overflow.patch drm-i915-hdcp-require-monotonically-increasing-seq_num_v.patch drm-virtio-bound-edid-block-reads-to-the-response-buffer.patch --- diff --git a/queue-6.18/drm-amd-display-detect_link_and_local_sink-dp-alt-mode-timeout-path-leaks-prev_sink-reference.patch b/queue-6.18/drm-amd-display-detect_link_and_local_sink-dp-alt-mode-timeout-path-leaks-prev_sink-reference.patch new file mode 100644 index 0000000000..0111528bb6 --- /dev/null +++ b/queue-6.18/drm-amd-display-detect_link_and_local_sink-dp-alt-mode-timeout-path-leaks-prev_sink-reference.patch @@ -0,0 +1,43 @@ +From a6e14b976be48eebd8769cb5b883a6af7fc5ade1 Mon Sep 17 00:00:00 2001 +From: WenTao Liang +Date: Fri, 26 Jun 2026 20:45:55 +0800 +Subject: drm/amd/display: detect_link_and_local_sink: DP alt mode timeout path leaks prev_sink reference + +From: WenTao Liang + +commit a6e14b976be48eebd8769cb5b883a6af7fc5ade1 upstream. + +prev_sink is unconditionally retained via dc_sink_retain at function + entry, but the DP alt mode timeout path inside SIGNAL_TYPE_DISPLAY_PORT + returns false without releasing prev_sink. All other return paths in the + function correctly call dc_sink_release(prev_sink), making this the only + missing cleanup. + +Fixes: 54618888d1ea ("drm/amd/display: break down dc_link.c") +Signed-off-by: WenTao Liang +Reviewed-by: Mario Limonciello (AMD) +Link: https://patch.msgid.link/20260626124555.36910-1-vulab@iscas.ac.cn +Signed-off-by: Mario Limonciello +Signed-off-by: Alex Deucher +(cherry picked from commit 45510cf662dcf46b5d8926d454f338809f107b9d) +Cc: stable@vger.kernel.org +Signed-off-by: Greg Kroah-Hartman +--- + drivers/gpu/drm/amd/display/dc/link/link_detection.c | 5 ++++- + 1 file changed, 4 insertions(+), 1 deletion(-) + +--- a/drivers/gpu/drm/amd/display/dc/link/link_detection.c ++++ b/drivers/gpu/drm/amd/display/dc/link/link_detection.c +@@ -979,8 +979,11 @@ static bool detect_link_and_local_sink(s + link->link_enc->features.flags.bits.DP_IS_USB_C == 1) { + + /* if alt mode times out, return false */ +- if (!wait_for_entering_dp_alt_mode(link)) ++ if (!wait_for_entering_dp_alt_mode(link)) { ++ if (prev_sink) ++ dc_sink_release(prev_sink); + return false; ++ } + } + + if (!detect_dp(link, &sink_caps, reason)) { diff --git a/queue-6.18/drm-amd-display-handle-struct-drm_plane_state.ignore_damage_clips.patch b/queue-6.18/drm-amd-display-handle-struct-drm_plane_state.ignore_damage_clips.patch new file mode 100644 index 0000000000..3a3b9f74e8 --- /dev/null +++ b/queue-6.18/drm-amd-display-handle-struct-drm_plane_state.ignore_damage_clips.patch @@ -0,0 +1,64 @@ +From ac11060c6d4959e2d4ceada037d2e1e1bfcf6645 Mon Sep 17 00:00:00 2001 +From: Thomas Zimmermann +Date: Wed, 10 Jun 2026 17:18:17 +0200 +Subject: drm/amd/display: Handle struct drm_plane_state.ignore_damage_clips + +From: Thomas Zimmermann + +commit ac11060c6d4959e2d4ceada037d2e1e1bfcf6645 upstream. + +The mode-setting pipeline can disabled damage clippings for a commit +by setting ignore_damage_clips in struct drm_plane_state. The commit +will then do a full display update. + +Test the flag in DCN code and do a full update in DCN code if it has +been set. + +Commit 35ed38d58257 ("drm: Allow drivers to indicate the damage helpers +to ignore damage clips") introduced ignore_damage_clips to selectively +ignore damage clipping in certain framebuffer changes. This driver does +not do that, but DRM's damage iterator will soon rely on the flag. +Therefore supporting it here as well make sense for consistency. + +Signed-off-by: Thomas Zimmermann +Fixes: 35ed38d58257 ("drm: Allow drivers to indicate the damage helpers to ignore damage clips") +Cc: Javier Martinez Canillas +Cc: Thomas Zimmermann +Cc: Zack Rusin +Cc: dri-devel@lists.freedesktop.org +Reviewed-by: Javier Martinez Canillas +Reviewed-by: Harry Wentland +Signed-off-by: Alex Deucher +(cherry picked from commit a24019f6480fad5c077b5956eed942c8960323d6) +Cc: # v6.8+ +Signed-off-by: Greg Kroah-Hartman +--- + drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm.c | 10 ++++++---- + 1 file changed, 6 insertions(+), 4 deletions(-) + +--- a/drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm.c ++++ b/drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm.c +@@ -6240,8 +6240,8 @@ static void fill_dc_dirty_rects(struct d + { + struct dm_crtc_state *dm_crtc_state = to_dm_crtc_state(crtc_state); + struct rect *dirty_rects = flip_addrs->dirty_rects; +- u32 num_clips; +- struct drm_mode_rect *clips; ++ u32 num_clips = 0; ++ struct drm_mode_rect *clips = NULL; + bool bb_changed; + bool fb_changed; + u32 i = 0; +@@ -6257,8 +6257,10 @@ static void fill_dc_dirty_rects(struct d + if (new_plane_state->rotation != DRM_MODE_ROTATE_0) + goto ffu; + +- num_clips = drm_plane_get_damage_clips_count(new_plane_state); +- clips = drm_plane_get_damage_clips(new_plane_state); ++ if (!new_plane_state->ignore_damage_clips) { ++ num_clips = drm_plane_get_damage_clips_count(new_plane_state); ++ clips = drm_plane_get_damage_clips(new_plane_state); ++ } + + if (num_clips && (!amdgpu_damage_clips || (amdgpu_damage_clips < 0 && + is_psr_su))) diff --git a/queue-6.18/drm-amdgpu-sdma5.0-replace-bug_on-with-warn_on.patch b/queue-6.18/drm-amdgpu-sdma5.0-replace-bug_on-with-warn_on.patch new file mode 100644 index 0000000000..85be55787e --- /dev/null +++ b/queue-6.18/drm-amdgpu-sdma5.0-replace-bug_on-with-warn_on.patch @@ -0,0 +1,40 @@ +From 9e98ed3113943257ad6e5c1e6beddbdb482a70ad Mon Sep 17 00:00:00 2001 +From: Alex Deucher +Date: Mon, 15 Jun 2026 18:26:28 -0400 +Subject: drm/amdgpu/sdma5.0: replace BUG_ON() with WARN_ON() + +From: Alex Deucher + +commit 9e98ed3113943257ad6e5c1e6beddbdb482a70ad upstream. + +There's no need to crash the kernel for these cases. + +Reviewed-by: Vitaly Prosyak +Signed-off-by: Alex Deucher +(cherry picked from commit 8d144a0eb09537055841af48c9e7c2d4cd48e84d) +Cc: stable@vger.kernel.org +Signed-off-by: Greg Kroah-Hartman +--- + drivers/gpu/drm/amd/amdgpu/sdma_v5_0.c | 4 ++-- + 1 file changed, 2 insertions(+), 2 deletions(-) + +--- a/drivers/gpu/drm/amd/amdgpu/sdma_v5_0.c ++++ b/drivers/gpu/drm/amd/amdgpu/sdma_v5_0.c +@@ -528,7 +528,7 @@ static void sdma_v5_0_ring_emit_fence(st + amdgpu_ring_write(ring, SDMA_PKT_HEADER_OP(SDMA_OP_FENCE) | + SDMA_PKT_FENCE_HEADER_MTYPE(0x3)); /* Ucached(UC) */ + /* zero in first two bits */ +- BUG_ON(addr & 0x3); ++ WARN_ON(addr & 0x3); + amdgpu_ring_write(ring, lower_32_bits(addr)); + amdgpu_ring_write(ring, upper_32_bits(addr)); + amdgpu_ring_write(ring, lower_32_bits(seq)); +@@ -539,7 +539,7 @@ static void sdma_v5_0_ring_emit_fence(st + amdgpu_ring_write(ring, SDMA_PKT_HEADER_OP(SDMA_OP_FENCE) | + SDMA_PKT_FENCE_HEADER_MTYPE(0x3)); + /* zero in first two bits */ +- BUG_ON(addr & 0x3); ++ WARN_ON(addr & 0x3); + amdgpu_ring_write(ring, lower_32_bits(addr)); + amdgpu_ring_write(ring, upper_32_bits(addr)); + amdgpu_ring_write(ring, upper_32_bits(seq)); diff --git a/queue-6.18/drm-amdgpu-sdma5.2-replace-bug_on-with-warn_on.patch b/queue-6.18/drm-amdgpu-sdma5.2-replace-bug_on-with-warn_on.patch new file mode 100644 index 0000000000..b5623e6d8c --- /dev/null +++ b/queue-6.18/drm-amdgpu-sdma5.2-replace-bug_on-with-warn_on.patch @@ -0,0 +1,40 @@ +From b9dd618a635d39fbb211454b6e8837b2a7f10fb0 Mon Sep 17 00:00:00 2001 +From: Alex Deucher +Date: Mon, 15 Jun 2026 18:27:15 -0400 +Subject: drm/amdgpu/sdma5.2: replace BUG_ON() with WARN_ON() + +From: Alex Deucher + +commit b9dd618a635d39fbb211454b6e8837b2a7f10fb0 upstream. + +There's no need to crash the kernel for these cases. + +Reviewed-by: Vitaly Prosyak +Signed-off-by: Alex Deucher +(cherry picked from commit ae658afc7f47f6147371ec42cc6b1a793dfdb5af) +Cc: stable@vger.kernel.org +Signed-off-by: Greg Kroah-Hartman +--- + drivers/gpu/drm/amd/amdgpu/sdma_v5_2.c | 4 ++-- + 1 file changed, 2 insertions(+), 2 deletions(-) + +--- a/drivers/gpu/drm/amd/amdgpu/sdma_v5_2.c ++++ b/drivers/gpu/drm/amd/amdgpu/sdma_v5_2.c +@@ -378,7 +378,7 @@ static void sdma_v5_2_ring_emit_fence(st + amdgpu_ring_write(ring, SDMA_PKT_HEADER_OP(SDMA_OP_FENCE) | + SDMA_PKT_FENCE_HEADER_MTYPE(0x3)); /* Ucached(UC) */ + /* zero in first two bits */ +- BUG_ON(addr & 0x3); ++ WARN_ON(addr & 0x3); + amdgpu_ring_write(ring, lower_32_bits(addr)); + amdgpu_ring_write(ring, upper_32_bits(addr)); + amdgpu_ring_write(ring, lower_32_bits(seq)); +@@ -389,7 +389,7 @@ static void sdma_v5_2_ring_emit_fence(st + amdgpu_ring_write(ring, SDMA_PKT_HEADER_OP(SDMA_OP_FENCE) | + SDMA_PKT_FENCE_HEADER_MTYPE(0x3)); + /* zero in first two bits */ +- BUG_ON(addr & 0x3); ++ WARN_ON(addr & 0x3); + amdgpu_ring_write(ring, lower_32_bits(addr)); + amdgpu_ring_write(ring, upper_32_bits(addr)); + amdgpu_ring_write(ring, upper_32_bits(seq)); diff --git a/queue-6.18/drm-amdgpu-sdma6.0-replace-bug_on-with-warn_on.patch b/queue-6.18/drm-amdgpu-sdma6.0-replace-bug_on-with-warn_on.patch new file mode 100644 index 0000000000..e360fb4f34 --- /dev/null +++ b/queue-6.18/drm-amdgpu-sdma6.0-replace-bug_on-with-warn_on.patch @@ -0,0 +1,40 @@ +From ec42c96c322e5cc48099ab5e67b5cbe236cb1949 Mon Sep 17 00:00:00 2001 +From: Alex Deucher +Date: Mon, 15 Jun 2026 18:27:54 -0400 +Subject: drm/amdgpu/sdma6.0: replace BUG_ON() with WARN_ON() + +From: Alex Deucher + +commit ec42c96c322e5cc48099ab5e67b5cbe236cb1949 upstream. + +There's no need to crash the kernel for these cases. + +Reviewed-by: Vitaly Prosyak +Signed-off-by: Alex Deucher +(cherry picked from commit c17a508a7d652da3728f8bbc481bfffe96d65a87) +Cc: stable@vger.kernel.org +Signed-off-by: Greg Kroah-Hartman +--- + drivers/gpu/drm/amd/amdgpu/sdma_v6_0.c | 4 ++-- + 1 file changed, 2 insertions(+), 2 deletions(-) + +--- a/drivers/gpu/drm/amd/amdgpu/sdma_v6_0.c ++++ b/drivers/gpu/drm/amd/amdgpu/sdma_v6_0.c +@@ -360,7 +360,7 @@ static void sdma_v6_0_ring_emit_fence(st + amdgpu_ring_write(ring, SDMA_PKT_COPY_LINEAR_HEADER_OP(SDMA_OP_FENCE) | + SDMA_PKT_FENCE_HEADER_MTYPE(0x3)); /* Ucached(UC) */ + /* zero in first two bits */ +- BUG_ON(addr & 0x3); ++ WARN_ON(addr & 0x3); + amdgpu_ring_write(ring, lower_32_bits(addr)); + amdgpu_ring_write(ring, upper_32_bits(addr)); + amdgpu_ring_write(ring, lower_32_bits(seq)); +@@ -371,7 +371,7 @@ static void sdma_v6_0_ring_emit_fence(st + amdgpu_ring_write(ring, SDMA_PKT_COPY_LINEAR_HEADER_OP(SDMA_OP_FENCE) | + SDMA_PKT_FENCE_HEADER_MTYPE(0x3)); + /* zero in first two bits */ +- BUG_ON(addr & 0x3); ++ WARN_ON(addr & 0x3); + amdgpu_ring_write(ring, lower_32_bits(addr)); + amdgpu_ring_write(ring, upper_32_bits(addr)); + amdgpu_ring_write(ring, upper_32_bits(seq)); diff --git a/queue-6.18/drm-amdgpu-sdma7.0-replace-bug_on-with-warn_on.patch b/queue-6.18/drm-amdgpu-sdma7.0-replace-bug_on-with-warn_on.patch new file mode 100644 index 0000000000..8ec0980244 --- /dev/null +++ b/queue-6.18/drm-amdgpu-sdma7.0-replace-bug_on-with-warn_on.patch @@ -0,0 +1,40 @@ +From e80e28f398f5d9f6e361ffb56382d2e74fc87556 Mon Sep 17 00:00:00 2001 +From: Alex Deucher +Date: Mon, 15 Jun 2026 18:28:29 -0400 +Subject: drm/amdgpu/sdma7.0: replace BUG_ON() with WARN_ON() + +From: Alex Deucher + +commit e80e28f398f5d9f6e361ffb56382d2e74fc87556 upstream. + +There's no need to crash the kernel for these cases. + +Reviewed-by: Vitaly Prosyak +Signed-off-by: Alex Deucher +(cherry picked from commit 9723a8bed3aa251a26bee4583bac9d8fb064dd44) +Cc: stable@vger.kernel.org +Signed-off-by: Greg Kroah-Hartman +--- + drivers/gpu/drm/amd/amdgpu/sdma_v7_0.c | 4 ++-- + 1 file changed, 2 insertions(+), 2 deletions(-) + +--- a/drivers/gpu/drm/amd/amdgpu/sdma_v7_0.c ++++ b/drivers/gpu/drm/amd/amdgpu/sdma_v7_0.c +@@ -364,7 +364,7 @@ static void sdma_v7_0_ring_emit_fence(st + amdgpu_ring_write(ring, SDMA_PKT_COPY_LINEAR_HEADER_OP(SDMA_OP_FENCE) | + SDMA_PKT_FENCE_HEADER_MTYPE(0x3)); /* Ucached(UC) */ + /* zero in first two bits */ +- BUG_ON(addr & 0x3); ++ WARN_ON(addr & 0x3); + amdgpu_ring_write(ring, lower_32_bits(addr)); + amdgpu_ring_write(ring, upper_32_bits(addr)); + amdgpu_ring_write(ring, lower_32_bits(seq)); +@@ -375,7 +375,7 @@ static void sdma_v7_0_ring_emit_fence(st + amdgpu_ring_write(ring, SDMA_PKT_COPY_LINEAR_HEADER_OP(SDMA_OP_FENCE) | + SDMA_PKT_FENCE_HEADER_MTYPE(0x3)); + /* zero in first two bits */ +- BUG_ON(addr & 0x3); ++ WARN_ON(addr & 0x3); + amdgpu_ring_write(ring, lower_32_bits(addr)); + amdgpu_ring_write(ring, upper_32_bits(addr)); + amdgpu_ring_write(ring, upper_32_bits(seq)); diff --git a/queue-6.18/drm-i915-hdcp-check-streams-bounds-before-overflow.patch b/queue-6.18/drm-i915-hdcp-check-streams-bounds-before-overflow.patch new file mode 100644 index 0000000000..466cd7322c --- /dev/null +++ b/queue-6.18/drm-i915-hdcp-check-streams-bounds-before-overflow.patch @@ -0,0 +1,55 @@ +From bbb15a6b042d02e5508a02b4847e02d2579ee7bc Mon Sep 17 00:00:00 2001 +From: Jani Nikula +Date: Thu, 25 Jun 2026 20:03:04 +0300 +Subject: drm/i915/hdcp: check streams[] bounds before overflow + +From: Jani Nikula + +commit bbb15a6b042d02e5508a02b4847e02d2579ee7bc upstream. + +The data->streams[] overflow check is done after the buffer overflow has +already happened. Move the overflow check before the write. + +Side note, emitting a warning splat with a backtrace might be overkill +here, but prefer not changing the behaviour other than not doing the +overrun. + +Discovered using AI-assisted static analysis confirmed by Intel Product +Security. + +Reported-by: Martin Hodo +Fixes: e03187e12cae ("drm/i915/hdcp: MST streams support in hdcp port_data") +Cc: stable@vger.kernel.org # v5.12+ +Cc: Anshuman Gupta +Cc: Suraj Kandpal +Reviewed-by: Suraj Kandpal +Link: https://patch.msgid.link/20260625170304.1104723-1-jani.nikula@intel.com +Signed-off-by: Jani Nikula +(cherry picked from commit 9284ab3b6e776c315883ac2611283d263c9460fd) +Signed-off-by: Joonas Lahtinen +Signed-off-by: Greg Kroah-Hartman +--- + drivers/gpu/drm/i915/display/intel_hdcp.c | 5 ++++- + 1 file changed, 4 insertions(+), 1 deletion(-) + +--- a/drivers/gpu/drm/i915/display/intel_hdcp.c ++++ b/drivers/gpu/drm/i915/display/intel_hdcp.c +@@ -140,6 +140,9 @@ intel_hdcp_required_content_stream(struc + if (conn_dig_port != dig_port) + continue; + ++ if (drm_WARN_ON(display->drm, data->k >= INTEL_NUM_PIPES(display))) ++ return -EINVAL; ++ + data->streams[data->k].stream_id = + intel_conn_to_vcpi(state, connector); + data->k++; +@@ -150,7 +153,7 @@ intel_hdcp_required_content_stream(struc + } + drm_connector_list_iter_end(&conn_iter); + +- if (drm_WARN_ON(display->drm, data->k > INTEL_NUM_PIPES(display) || data->k == 0)) ++ if (drm_WARN_ON(display->drm, !data->k)) + return -EINVAL; + + /* diff --git a/queue-6.18/drm-i915-hdcp-require-monotonically-increasing-seq_num_v.patch b/queue-6.18/drm-i915-hdcp-require-monotonically-increasing-seq_num_v.patch new file mode 100644 index 0000000000..66e34c592a --- /dev/null +++ b/queue-6.18/drm-i915-hdcp-require-monotonically-increasing-seq_num_v.patch @@ -0,0 +1,50 @@ +From db9e64c983dcb07ff256bd455f258c44aa530ff8 Mon Sep 17 00:00:00 2001 +From: Jani Nikula +Date: Thu, 25 Jun 2026 13:44:07 +0300 +Subject: drm/i915/hdcp: require monotonically increasing seq_num_v + +From: Jani Nikula + +commit db9e64c983dcb07ff256bd455f258c44aa530ff8 upstream. + +The HDCP 2.2 specification requires the seq_num_v to be monotonically +increasing, and repeated seq_num_v needs to be treated as an integrity +failure. Make it so. + +For the first message, seq_num_v must be zero, and is already +checked. We can only check for less-than-or-equal for the subsequent +messages, where hdcp2_encrypted is true. + +Discovered using AI-assisted static analysis confirmed by Intel Product +Security. + +Reported-by: Martin Hodo +Fixes: d849178e2c9e ("drm/i915: Implement HDCP2.2 repeater authentication") +Cc: stable@vger.kernel.org # v5.2+ +Cc: Suraj Kandpal +Reviewed-by: Suraj Kandpal +Link: https://patch.msgid.link/20260625104407.1025614-1-jani.nikula@intel.com +Signed-off-by: Jani Nikula +(cherry picked from commit 58a224375c81179b52558c53d8857b93196d2687) +Signed-off-by: Joonas Lahtinen +Signed-off-by: Greg Kroah-Hartman +--- + drivers/gpu/drm/i915/display/intel_hdcp.c | 7 ++++--- + 1 file changed, 4 insertions(+), 3 deletions(-) + +--- a/drivers/gpu/drm/i915/display/intel_hdcp.c ++++ b/drivers/gpu/drm/i915/display/intel_hdcp.c +@@ -1794,9 +1794,10 @@ int hdcp2_authenticate_repeater_topology + return -EINVAL; + } + +- if (seq_num_v < hdcp->seq_num_v) { +- /* Roll over of the seq_num_v from repeater. Reauthenticate. */ +- drm_dbg_kms(display->drm, "Seq_num_v roll over.\n"); ++ if (hdcp->hdcp2_encrypted && seq_num_v <= hdcp->seq_num_v) { ++ /* Reauthenticate on Seq_num_v repeat or rollover */ ++ drm_dbg_kms(display->drm, "Seq_num_v %s\n", ++ seq_num_v == hdcp->seq_num_v ? "repeat" : "rollover"); + return -EINVAL; + } + diff --git a/queue-6.18/drm-virtio-bound-edid-block-reads-to-the-response-buffer.patch b/queue-6.18/drm-virtio-bound-edid-block-reads-to-the-response-buffer.patch new file mode 100644 index 0000000000..2bca7db7bd --- /dev/null +++ b/queue-6.18/drm-virtio-bound-edid-block-reads-to-the-response-buffer.patch @@ -0,0 +1,42 @@ +From 4e1a53892ba7f8a3e1da6bfc53c83ae7c812dccd Mon Sep 17 00:00:00 2001 +From: Bryam Vargas +Date: Sat, 20 Jun 2026 21:43:34 -0500 +Subject: drm/virtio: bound EDID block reads to the response buffer + +From: Bryam Vargas + +commit 4e1a53892ba7f8a3e1da6bfc53c83ae7c812dccd upstream. + +virtio_get_edid_block() validates the read offset only against the +device-supplied resp->size field, never against the fixed-size resp->edid +array. The EDID block index is driven by the device-supplied extension +count, so a malicious virtio-gpu backend can advertise a large size +together with a high block count and read far past the array into adjacent +kernel memory, which is then surfaced in the parsed EDID (an out-of-bounds +read / info leak). + +Also reject any read whose end exceeds the size of the edid array. +Conforming EDID responses stay within the array and are unaffected. + +Fixes: b4b01b4995fb ("drm/virtio: add edid support") +Cc: stable@vger.kernel.org +Signed-off-by: Bryam Vargas +Signed-off-by: Dmitry Osipenko +Link: https://patch.msgid.link/20260620-b4-disp-22bba7bf-v1-1-b95924cee742@proton.me +Signed-off-by: Greg Kroah-Hartman +--- + drivers/gpu/drm/virtio/virtgpu_vq.c | 3 ++- + 1 file changed, 2 insertions(+), 1 deletion(-) + +--- a/drivers/gpu/drm/virtio/virtgpu_vq.c ++++ b/drivers/gpu/drm/virtio/virtgpu_vq.c +@@ -893,7 +893,8 @@ static int virtio_get_edid_block(void *d + struct virtio_gpu_resp_edid *resp = data; + size_t start = block * EDID_LENGTH; + +- if (start + len > le32_to_cpu(resp->size)) ++ if (start + len > le32_to_cpu(resp->size) || ++ start + len > sizeof(resp->edid)) + return -EINVAL; + memcpy(buf, resp->edid + start, len); + return 0; diff --git a/queue-6.18/series b/queue-6.18/series index fa455e8f2f..433e049aa1 100644 --- a/queue-6.18/series +++ b/queue-6.18/series @@ -362,3 +362,12 @@ drm-amdkfd-use-kvcalloc-to-allocate-arrays.patch drm-amdkfd-check-bounds-in-allocate_event_notification_slot.patch drm-amdkfd-check-bounds-on-criu-restore-queue-type-and-mqd-size.patch drm-amdkfd-fix-32-bit-overflow-in-cwsr-total-size-calculation.patch +drm-amd-display-handle-struct-drm_plane_state.ignore_damage_clips.patch +drm-amd-display-detect_link_and_local_sink-dp-alt-mode-timeout-path-leaks-prev_sink-reference.patch +drm-virtio-bound-edid-block-reads-to-the-response-buffer.patch +drm-i915-hdcp-require-monotonically-increasing-seq_num_v.patch +drm-i915-hdcp-check-streams-bounds-before-overflow.patch +drm-amdgpu-sdma7.0-replace-bug_on-with-warn_on.patch +drm-amdgpu-sdma6.0-replace-bug_on-with-warn_on.patch +drm-amdgpu-sdma5.2-replace-bug_on-with-warn_on.patch +drm-amdgpu-sdma5.0-replace-bug_on-with-warn_on.patch