dri-devel Archive on lore.kernel.org
 help / color / mirror / Atom feed
* [PATCH 5.15 1/2] drm/amdgpu: Use vmemdup_array_user in amdgpu_bo_create_list_entry_array
@ 2026-09-23 14:54 Roman Demidov
  2026-09-23 14:54 ` [PATCH 5.15 2/2] drm/amdgpu: Limit BO list entry count to prevent resource exhaustion Roman Demidov
  2026-09-23 15:07 ` [PATCH 5.15 1/2] drm/amdgpu: Use vmemdup_array_user in amdgpu_bo_create_list_entry_array sashiko-bot
  0 siblings, 2 replies; 4+ messages in thread
From: Roman Demidov @ 2026-09-23 14:54 UTC (permalink / raw)
  To: stable, Greg Kroah-Hartman
  Cc: Roman Demidov, Alex Deucher, Christian König, David Airlie,
	Daniel Vetter, Kees Cook, Andy Shevchenko, Sasha Levin,
	Jani Nikula, amd-gfx, dri-devel, linux-kernel, lvc-project,
	Tvrtko Ursulin, Fang Wang

From: Tvrtko Ursulin <tvrtko.ursulin@igalia.com>

commit c4ac100e9ae252b09986766ad23b1f83ca3a369d upstream.

Replace kvmalloc_array() + copy_from_user() with vmemdup_array_user() on
the fast path.

This shrinks the source code and improves separation between the kernel
and userspace slabs.

Signed-off-by: Tvrtko Ursulin <tvrtko.ursulin@igalia.com>
Signed-off-by: Alex Deucher <alexander.deucher@amd.com>
Signed-off-by: Fang Wang <32840572@qq.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
Stable-dep-of: c833d6c7199c ("drm/amdgpu: Limit BO list entry count to prevent resource exhaustion")
Signed-off-by: Roman Demidov <roman.demidov.nn@gmail.com>
---
Backport fix for CVE-2026-23468

 drivers/gpu/drm/amd/amdgpu/amdgpu_bo_list.c | 41 +++++++++------------
 1 file changed, 17 insertions(+), 24 deletions(-)

diff --git a/drivers/gpu/drm/amd/amdgpu/amdgpu_bo_list.c b/drivers/gpu/drm/amd/amdgpu/amdgpu_bo_list.c
index 9fb8012007e2..22d7b7c504db 100644
--- a/drivers/gpu/drm/amd/amdgpu/amdgpu_bo_list.c
+++ b/drivers/gpu/drm/amd/amdgpu/amdgpu_bo_list.c
@@ -224,43 +224,36 @@ void amdgpu_bo_list_put(struct amdgpu_bo_list *list)
 int amdgpu_bo_create_list_entry_array(struct drm_amdgpu_bo_list_in *in,
 				      struct drm_amdgpu_bo_list_entry **info_param)
 {
-	const void __user *uptr = u64_to_user_ptr(in->bo_info_ptr);
 	const uint32_t info_size = sizeof(struct drm_amdgpu_bo_list_entry);
+	const void __user *uptr = u64_to_user_ptr(in->bo_info_ptr);
+	const uint32_t bo_info_size = in->bo_info_size;
+	const uint32_t bo_number = in->bo_number;
 	struct drm_amdgpu_bo_list_entry *info;
-	int r;
-
-	info = kvmalloc_array(in->bo_number, info_size, GFP_KERNEL);
-	if (!info)
-		return -ENOMEM;
 
 	/* copy the handle array from userspace to a kernel buffer */
-	r = -EFAULT;
-	if (likely(info_size == in->bo_info_size)) {
-		unsigned long bytes = in->bo_number *
-			in->bo_info_size;
-
-		if (copy_from_user(info, uptr, bytes))
-			goto error_free;
-
+	if (likely(info_size == bo_info_size)) {
+		info = vmemdup_array_user(uptr, bo_number, info_size);
+		if (IS_ERR(info))
+			return PTR_ERR(info);
 	} else {
-		unsigned long bytes = min(in->bo_info_size, info_size);
+		const uint32_t bytes = min(bo_info_size, info_size);
 		unsigned i;
 
-		memset(info, 0, in->bo_number * info_size);
-		for (i = 0; i < in->bo_number; ++i) {
-			if (copy_from_user(&info[i], uptr, bytes))
-				goto error_free;
+		info = kvmalloc_array(bo_number, info_size, GFP_KERNEL);
+		if (!info)
+			return -ENOMEM;
 
-			uptr += in->bo_info_size;
+		memset(info, 0, bo_number * info_size);
+		for (i = 0; i < bo_number; ++i, uptr += bo_info_size) {
+			if (copy_from_user(&info[i], uptr, bytes)) {
+				kvfree(info);
+				return -EFAULT;
+			}
 		}
 	}
 
 	*info_param = info;
 	return 0;
-
-error_free:
-	kvfree(info);
-	return r;
 }
 
 int amdgpu_bo_list_ioctl(struct drm_device *dev, void *data,
-- 
2.53.0


^ permalink raw reply related	[flat|nested] 4+ messages in thread

* [PATCH 5.15 2/2] drm/amdgpu: Limit BO list entry count to prevent resource exhaustion
  2026-09-23 14:54 [PATCH 5.15 1/2] drm/amdgpu: Use vmemdup_array_user in amdgpu_bo_create_list_entry_array Roman Demidov
@ 2026-09-23 14:54 ` Roman Demidov
  2026-09-23 15:07 ` [PATCH 5.15 1/2] drm/amdgpu: Use vmemdup_array_user in amdgpu_bo_create_list_entry_array sashiko-bot
  1 sibling, 0 replies; 4+ messages in thread
From: Roman Demidov @ 2026-09-23 14:54 UTC (permalink / raw)
  To: stable, Greg Kroah-Hartman
  Cc: Roman Demidov, Alex Deucher, Christian König, David Airlie,
	Daniel Vetter, Kees Cook, Andy Shevchenko, Sasha Levin,
	Jani Nikula, amd-gfx, dri-devel, linux-kernel, lvc-project,
	Jesse Zhang, Fang Wang

From: "Jesse.Zhang" <Jesse.Zhang@amd.com>

commit 6270b1a5dab94665d7adce3dc78bc9066ed28bdd upstream.

Userspace can pass an arbitrary number of BO list entries via the
bo_number field. Although the previous multiplication overflow check
prevents out-of-bounds allocation, a large number of entries could still
cause excessive memory allocation (up to potentially gigabytes) and
unnecessarily long list processing times.

Introduce a hard limit of 128k entries per BO list, which is more than
sufficient for any realistic use case (e.g., a single list containing all
buffers in a large scene). This prevents memory exhaustion attacks and
ensures predictable performance.

Return -EINVAL if the requested entry count exceeds the limit

Reviewed-by: Christian König <christian.koenig@amd.com>
Suggested-by: Christian König <christian.koenig@amd.com>
Signed-off-by: Jesse Zhang <jesse.zhang@amd.com>
Signed-off-by: Alex Deucher <alexander.deucher@amd.com>
(cherry picked from commit 688b87d39e0aa8135105b40dc167d74b5ada5332)
Cc: stable@vger.kernel.org
Signed-off-by: Fang Wang <32840572@qq.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Roman Demidov <roman.demidov.nn@gmail.com>
---
Backport fix for CVE-2026-23468

 drivers/gpu/drm/amd/amdgpu/amdgpu_bo_list.c | 4 ++++
 1 file changed, 4 insertions(+)

diff --git a/drivers/gpu/drm/amd/amdgpu/amdgpu_bo_list.c b/drivers/gpu/drm/amd/amdgpu/amdgpu_bo_list.c
index 22d7b7c504db..ca0d82be5c9c 100644
--- a/drivers/gpu/drm/amd/amdgpu/amdgpu_bo_list.c
+++ b/drivers/gpu/drm/amd/amdgpu/amdgpu_bo_list.c
@@ -35,6 +35,7 @@
 
 #define AMDGPU_BO_LIST_MAX_PRIORITY	32u
 #define AMDGPU_BO_LIST_NUM_BUCKETS	(AMDGPU_BO_LIST_MAX_PRIORITY + 1)
+#define AMDGPU_BO_LIST_MAX_ENTRIES	(128 * 1024)
 
 static void amdgpu_bo_list_free_rcu(struct rcu_head *rcu)
 {
@@ -230,6 +231,9 @@ int amdgpu_bo_create_list_entry_array(struct drm_amdgpu_bo_list_in *in,
 	const uint32_t bo_number = in->bo_number;
 	struct drm_amdgpu_bo_list_entry *info;
 
+	if (bo_number > AMDGPU_BO_LIST_MAX_ENTRIES)
+		return -EINVAL;
+
 	/* copy the handle array from userspace to a kernel buffer */
 	if (likely(info_size == bo_info_size)) {
 		info = vmemdup_array_user(uptr, bo_number, info_size);
-- 
2.53.0


^ permalink raw reply related	[flat|nested] 4+ messages in thread

* Re: [PATCH 5.15 1/2] drm/amdgpu: Use vmemdup_array_user in amdgpu_bo_create_list_entry_array
  2026-09-23 14:54 [PATCH 5.15 1/2] drm/amdgpu: Use vmemdup_array_user in amdgpu_bo_create_list_entry_array Roman Demidov
  2026-09-23 14:54 ` [PATCH 5.15 2/2] drm/amdgpu: Limit BO list entry count to prevent resource exhaustion Roman Demidov
@ 2026-09-23 15:07 ` sashiko-bot
  2026-09-24  7:07   ` Roman
  1 sibling, 1 reply; 4+ messages in thread
From: sashiko-bot @ 2026-09-23 15:07 UTC (permalink / raw)
  To: Roman Demidov; +Cc: dri-devel

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [Low] build: missing vmemdup_array_user helper
--

commit 4d70c808a81c22c8b9f6c03847fa45f071b2e967
Author: Tvrtko Ursulin <tvrtko.ursulin@igalia.com>

drm/amdgpu: Use vmemdup_array_user in amdgpu_bo_create_list_entry_array

This commit replaces kvmalloc_array() + copy_from_user() with
vmemdup_array_user() on the fast path. This aims to shrink the source code
and improve separation between kernel and userspace slabs.

> diff --git a/drivers/gpu/drm/amd/amdgpu/amdgpu_bo_list.c b/drivers/gpu/drm/amd/amdgpu/amdgpu_bo_list.c
> index 15c45b2a39835..b364f3f5fb918 100644
> --- a/drivers/gpu/drm/amd/amdgpu/amdgpu_bo_list.c
> +++ b/drivers/gpu/drm/amd/amdgpu/amdgpu_bo_list.c
> @@ -223,43 +223,36 @@ void amdgpu_bo_list_put(struct amdgpu_bo_list *list)
>  int amdgpu_bo_create_list_entry_array(struct drm_amdgpu_bo_list_in *in,
>  				      struct drm_amdgpu_bo_list_entry **info_param)
>  {
[ ... ]
>  	/* copy the handle array from userspace to a kernel buffer */
> -	r = -EFAULT;
> -	if (likely(info_size == in->bo_info_size)) {
> -		unsigned long bytes = in->bo_number *
> -			in->bo_info_size;
> -
> -		if (copy_from_user(info, uptr, bytes))
> -			goto error_free;
> -
> +	if (likely(info_size == bo_info_size)) {
> +		info = vmemdup_array_user(uptr, bo_number, info_size);

[Severity: Low]
Does this code call a function vmemdup_array_user() that does not exist in
this kernel tree?

When compiling drivers/gpu/drm/amd/amdgpu/amdgpu_bo_list.c with
CONFIG_DRM_AMDGPU=y or m, this will result in a build failure due to an
implicit function declaration in amdgpu_bo_create_list_entry_array(). If the
compiler allows implicit declarations, it would assume a 32-bit int return
type, which truncates the pointer on 64-bit systems and can lead to an
invalid pointer dereference or use-after-free when IS_ERR(info) or
kvfree(info) is called later.

> +		if (IS_ERR(info))
> +			return PTR_ERR(info);

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260923145453.76114-1-roman.demidov.nn@gmail.com?part=1

^ permalink raw reply	[flat|nested] 4+ messages in thread

* Re: [PATCH 5.15 1/2] drm/amdgpu: Use vmemdup_array_user in amdgpu_bo_create_list_entry_array
  2026-09-23 15:07 ` [PATCH 5.15 1/2] drm/amdgpu: Use vmemdup_array_user in amdgpu_bo_create_list_entry_array sashiko-bot
@ 2026-09-24  7:07   ` Roman
  0 siblings, 0 replies; 4+ messages in thread
From: Roman @ 2026-09-24  7:07 UTC (permalink / raw)
  To: sashiko-reviews; +Cc: dri-devel

[-- Attachment #1: Type: text/plain, Size: 2746 bytes --]

vmemdup_array_user() is already available in 5.15.y via commit 24b17d530c42
(string.h: add array-wrappers for (v)memdup_user()). So there is no
implicit declaration or pointer truncation, and the described build failure
does not apply to the target stable tree.


ср, 23 сент. 2026 г. в 18:07, <sashiko-bot@kernel.org>:

> Thank you for your contribution! Sashiko AI review found 1 potential
> issue(s) to consider:
> - [Low] build: missing vmemdup_array_user helper
> --
>
> commit 4d70c808a81c22c8b9f6c03847fa45f071b2e967
> Author: Tvrtko Ursulin <tvrtko.ursulin@igalia.com>
>
> drm/amdgpu: Use vmemdup_array_user in amdgpu_bo_create_list_entry_array
>
> This commit replaces kvmalloc_array() + copy_from_user() with
> vmemdup_array_user() on the fast path. This aims to shrink the source code
> and improve separation between kernel and userspace slabs.
>
> > diff --git a/drivers/gpu/drm/amd/amdgpu/amdgpu_bo_list.c
> b/drivers/gpu/drm/amd/amdgpu/amdgpu_bo_list.c
> > index 15c45b2a39835..b364f3f5fb918 100644
> > --- a/drivers/gpu/drm/amd/amdgpu/amdgpu_bo_list.c
> > +++ b/drivers/gpu/drm/amd/amdgpu/amdgpu_bo_list.c
> > @@ -223,43 +223,36 @@ void amdgpu_bo_list_put(struct amdgpu_bo_list
> *list)
> >  int amdgpu_bo_create_list_entry_array(struct drm_amdgpu_bo_list_in *in,
> >                                     struct drm_amdgpu_bo_list_entry
> **info_param)
> >  {
> [ ... ]
> >       /* copy the handle array from userspace to a kernel buffer */
> > -     r = -EFAULT;
> > -     if (likely(info_size == in->bo_info_size)) {
> > -             unsigned long bytes = in->bo_number *
> > -                     in->bo_info_size;
> > -
> > -             if (copy_from_user(info, uptr, bytes))
> > -                     goto error_free;
> > -
> > +     if (likely(info_size == bo_info_size)) {
> > +             info = vmemdup_array_user(uptr, bo_number, info_size);
>
> [Severity: Low]
> Does this code call a function vmemdup_array_user() that does not exist in
> this kernel tree?
>
> When compiling drivers/gpu/drm/amd/amdgpu/amdgpu_bo_list.c with
> CONFIG_DRM_AMDGPU=y or m, this will result in a build failure due to an
> implicit function declaration in amdgpu_bo_create_list_entry_array(). If
> the
> compiler allows implicit declarations, it would assume a 32-bit int return
> type, which truncates the pointer on 64-bit systems and can lead to an
> invalid pointer dereference or use-after-free when IS_ERR(info) or
> kvfree(info) is called later.
>
> > +             if (IS_ERR(info))
> > +                     return PTR_ERR(info);
>
> --
> Sashiko AI review ·
> https://sashiko.dev/#/patchset/20260923145453.76114-1-roman.demidov.nn@gmail.com?part=1
>

[-- Attachment #2: Type: text/html, Size: 3825 bytes --]

^ permalink raw reply	[flat|nested] 4+ messages in thread

end of thread, other threads:[~2026-09-24  7:07 UTC | newest]

Thread overview: 4+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-23 14:54 [PATCH 5.15 1/2] drm/amdgpu: Use vmemdup_array_user in amdgpu_bo_create_list_entry_array Roman Demidov
2026-09-23 14:54 ` [PATCH 5.15 2/2] drm/amdgpu: Limit BO list entry count to prevent resource exhaustion Roman Demidov
2026-09-23 15:07 ` [PATCH 5.15 1/2] drm/amdgpu: Use vmemdup_array_user in amdgpu_bo_create_list_entry_array sashiko-bot
2026-09-24  7:07   ` Roman

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox