From: Aldo Ariel Panzardo <qwe.aldo@gmail.com>
To: airlied@redhat.com, kraxel@redhat.com
Cc: dri-devel@lists.freedesktop.org, stable@vger.kernel.org,
Aldo Ariel Panzardo <qwe.aldo@gmail.com>
Subject: [PATCH v2 2/4] drm/qxl: reject command sizes that exceed the release slot
Date: Sun, 13 Sep 2026 19:29:58 -0300 [thread overview]
Message-ID: <20260913223000.695299-3-qwe.aldo@gmail.com> (raw)
In-Reply-To: <20260913223000.695299-1-qwe.aldo@gmail.com>
qxl_alloc_release_reserved() receives a requested size from its callers
but never validates it against the actual sub-allocation slot size.
Drawable releases use 256-byte slots (RELEASE_SIZE), yet
qxl_process_single_command() allows command_size up to
PAGE_SIZE - sizeof(union qxl_release_info), approximately 4088 bytes.
The command payload is then copied from userspace via
copy_from_user_inatomic_nontemporal() into the 256-byte slot, causing a
heap buffer overflow that corrupts adjacent release slots in the same
page and can overwrite the neighbouring release_info headers.
Add a check in qxl_alloc_release_reserved() to reject allocations where
the requested size exceeds the slot size for the given release type.
Fixes: f64122c1f6ad ("drm: add qxl driver.")
Cc: stable@vger.kernel.org
Signed-off-by: Aldo Ariel Panzardo <qwe.aldo@gmail.com>
---
drivers/gpu/drm/qxl/qxl_release.c | 3 +++
1 file changed, 3 insertions(+)
diff --git a/drivers/gpu/drm/qxl/qxl_release.c b/drivers/gpu/drm/qxl/qxl_release.c
index 06979d0e8..049ad167f 100644
--- a/drivers/gpu/drm/qxl/qxl_release.c
+++ b/drivers/gpu/drm/qxl/qxl_release.c
@@ -312,6 +312,9 @@ int qxl_alloc_release_reserved(struct qxl_device *qdev, unsigned long size,
return -EINVAL;
}
+ if (size > release_size_per_bo[cur_idx])
+ return -EINVAL;
+
idr_ret = qxl_release_alloc(qdev, type, release);
if (idr_ret < 0) {
if (rbo)
--
2.43.0
next prev parent reply other threads:[~2026-09-13 22:30 UTC|newest]
Thread overview: 9+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-13 22:29 [PATCH v2 0/4] drm/qxl: fix multiple missing bounds checks in execbuffer relocations Aldo Ariel Panzardo
2026-09-13 22:29 ` [PATCH v2 1/4] drm/qxl: validate relocation dst_offset against destination BO Aldo Ariel Panzardo
2026-09-13 22:44 ` sashiko-bot
2026-09-13 22:29 ` Aldo Ariel Panzardo [this message]
2026-09-13 22:45 ` [PATCH v2 2/4] drm/qxl: reject command sizes that exceed the release slot sashiko-bot
2026-09-13 22:29 ` [PATCH v2 3/4] drm/qxl: reject relocations whose writes cross a page boundary Aldo Ariel Panzardo
2026-09-13 22:45 ` sashiko-bot
2026-09-13 22:30 ` [PATCH v2 4/4] drm/qxl: validate relocation src_offset and fix type truncation Aldo Ariel Panzardo
2026-09-13 22:46 ` sashiko-bot
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260913223000.695299-3-qwe.aldo@gmail.com \
--to=qwe.aldo@gmail.com \
--cc=airlied@redhat.com \
--cc=dri-devel@lists.freedesktop.org \
--cc=kraxel@redhat.com \
--cc=stable@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.