* [PATCH 5.15 1/2] drm/amdgpu: Use vmemdup_array_user in amdgpu_bo_create_list_entry_array
@ 2026-09-23 14:54 Roman Demidov
2026-09-23 14:54 ` [PATCH 5.15 2/2] drm/amdgpu: Limit BO list entry count to prevent resource exhaustion Roman Demidov
2026-09-23 15:07 ` [PATCH 5.15 1/2] drm/amdgpu: Use vmemdup_array_user in amdgpu_bo_create_list_entry_array sashiko-bot
0 siblings, 2 replies; 4+ messages in thread
From: Roman Demidov @ 2026-09-23 14:54 UTC (permalink / raw)
To: stable, Greg Kroah-Hartman
Cc: Roman Demidov, Alex Deucher, Christian König, David Airlie,
Daniel Vetter, Kees Cook, Andy Shevchenko, Sasha Levin,
Jani Nikula, amd-gfx, dri-devel, linux-kernel, lvc-project,
Tvrtko Ursulin, Fang Wang
From: Tvrtko Ursulin <tvrtko.ursulin@igalia.com>
commit c4ac100e9ae252b09986766ad23b1f83ca3a369d upstream.
Replace kvmalloc_array() + copy_from_user() with vmemdup_array_user() on
the fast path.
This shrinks the source code and improves separation between the kernel
and userspace slabs.
Signed-off-by: Tvrtko Ursulin <tvrtko.ursulin@igalia.com>
Signed-off-by: Alex Deucher <alexander.deucher@amd.com>
Signed-off-by: Fang Wang <32840572@qq.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
Stable-dep-of: c833d6c7199c ("drm/amdgpu: Limit BO list entry count to prevent resource exhaustion")
Signed-off-by: Roman Demidov <roman.demidov.nn@gmail.com>
---
Backport fix for CVE-2026-23468
drivers/gpu/drm/amd/amdgpu/amdgpu_bo_list.c | 41 +++++++++------------
1 file changed, 17 insertions(+), 24 deletions(-)
diff --git a/drivers/gpu/drm/amd/amdgpu/amdgpu_bo_list.c b/drivers/gpu/drm/amd/amdgpu/amdgpu_bo_list.c
index 9fb8012007e2..22d7b7c504db 100644
--- a/drivers/gpu/drm/amd/amdgpu/amdgpu_bo_list.c
+++ b/drivers/gpu/drm/amd/amdgpu/amdgpu_bo_list.c
@@ -224,43 +224,36 @@ void amdgpu_bo_list_put(struct amdgpu_bo_list *list)
int amdgpu_bo_create_list_entry_array(struct drm_amdgpu_bo_list_in *in,
struct drm_amdgpu_bo_list_entry **info_param)
{
- const void __user *uptr = u64_to_user_ptr(in->bo_info_ptr);
const uint32_t info_size = sizeof(struct drm_amdgpu_bo_list_entry);
+ const void __user *uptr = u64_to_user_ptr(in->bo_info_ptr);
+ const uint32_t bo_info_size = in->bo_info_size;
+ const uint32_t bo_number = in->bo_number;
struct drm_amdgpu_bo_list_entry *info;
- int r;
-
- info = kvmalloc_array(in->bo_number, info_size, GFP_KERNEL);
- if (!info)
- return -ENOMEM;
/* copy the handle array from userspace to a kernel buffer */
- r = -EFAULT;
- if (likely(info_size == in->bo_info_size)) {
- unsigned long bytes = in->bo_number *
- in->bo_info_size;
-
- if (copy_from_user(info, uptr, bytes))
- goto error_free;
-
+ if (likely(info_size == bo_info_size)) {
+ info = vmemdup_array_user(uptr, bo_number, info_size);
+ if (IS_ERR(info))
+ return PTR_ERR(info);
} else {
- unsigned long bytes = min(in->bo_info_size, info_size);
+ const uint32_t bytes = min(bo_info_size, info_size);
unsigned i;
- memset(info, 0, in->bo_number * info_size);
- for (i = 0; i < in->bo_number; ++i) {
- if (copy_from_user(&info[i], uptr, bytes))
- goto error_free;
+ info = kvmalloc_array(bo_number, info_size, GFP_KERNEL);
+ if (!info)
+ return -ENOMEM;
- uptr += in->bo_info_size;
+ memset(info, 0, bo_number * info_size);
+ for (i = 0; i < bo_number; ++i, uptr += bo_info_size) {
+ if (copy_from_user(&info[i], uptr, bytes)) {
+ kvfree(info);
+ return -EFAULT;
+ }
}
}
*info_param = info;
return 0;
-
-error_free:
- kvfree(info);
- return r;
}
int amdgpu_bo_list_ioctl(struct drm_device *dev, void *data,
--
2.53.0
^ permalink raw reply related [flat|nested] 4+ messages in thread
* [PATCH 5.15 2/2] drm/amdgpu: Limit BO list entry count to prevent resource exhaustion
2026-09-23 14:54 [PATCH 5.15 1/2] drm/amdgpu: Use vmemdup_array_user in amdgpu_bo_create_list_entry_array Roman Demidov
@ 2026-09-23 14:54 ` Roman Demidov
2026-09-23 15:07 ` [PATCH 5.15 1/2] drm/amdgpu: Use vmemdup_array_user in amdgpu_bo_create_list_entry_array sashiko-bot
1 sibling, 0 replies; 4+ messages in thread
From: Roman Demidov @ 2026-09-23 14:54 UTC (permalink / raw)
To: stable, Greg Kroah-Hartman
Cc: Roman Demidov, Alex Deucher, Christian König, David Airlie,
Daniel Vetter, Kees Cook, Andy Shevchenko, Sasha Levin,
Jani Nikula, amd-gfx, dri-devel, linux-kernel, lvc-project,
Jesse Zhang, Fang Wang
From: "Jesse.Zhang" <Jesse.Zhang@amd.com>
commit 6270b1a5dab94665d7adce3dc78bc9066ed28bdd upstream.
Userspace can pass an arbitrary number of BO list entries via the
bo_number field. Although the previous multiplication overflow check
prevents out-of-bounds allocation, a large number of entries could still
cause excessive memory allocation (up to potentially gigabytes) and
unnecessarily long list processing times.
Introduce a hard limit of 128k entries per BO list, which is more than
sufficient for any realistic use case (e.g., a single list containing all
buffers in a large scene). This prevents memory exhaustion attacks and
ensures predictable performance.
Return -EINVAL if the requested entry count exceeds the limit
Reviewed-by: Christian König <christian.koenig@amd.com>
Suggested-by: Christian König <christian.koenig@amd.com>
Signed-off-by: Jesse Zhang <jesse.zhang@amd.com>
Signed-off-by: Alex Deucher <alexander.deucher@amd.com>
(cherry picked from commit 688b87d39e0aa8135105b40dc167d74b5ada5332)
Cc: stable@vger.kernel.org
Signed-off-by: Fang Wang <32840572@qq.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Roman Demidov <roman.demidov.nn@gmail.com>
---
Backport fix for CVE-2026-23468
drivers/gpu/drm/amd/amdgpu/amdgpu_bo_list.c | 4 ++++
1 file changed, 4 insertions(+)
diff --git a/drivers/gpu/drm/amd/amdgpu/amdgpu_bo_list.c b/drivers/gpu/drm/amd/amdgpu/amdgpu_bo_list.c
index 22d7b7c504db..ca0d82be5c9c 100644
--- a/drivers/gpu/drm/amd/amdgpu/amdgpu_bo_list.c
+++ b/drivers/gpu/drm/amd/amdgpu/amdgpu_bo_list.c
@@ -35,6 +35,7 @@
#define AMDGPU_BO_LIST_MAX_PRIORITY 32u
#define AMDGPU_BO_LIST_NUM_BUCKETS (AMDGPU_BO_LIST_MAX_PRIORITY + 1)
+#define AMDGPU_BO_LIST_MAX_ENTRIES (128 * 1024)
static void amdgpu_bo_list_free_rcu(struct rcu_head *rcu)
{
@@ -230,6 +231,9 @@ int amdgpu_bo_create_list_entry_array(struct drm_amdgpu_bo_list_in *in,
const uint32_t bo_number = in->bo_number;
struct drm_amdgpu_bo_list_entry *info;
+ if (bo_number > AMDGPU_BO_LIST_MAX_ENTRIES)
+ return -EINVAL;
+
/* copy the handle array from userspace to a kernel buffer */
if (likely(info_size == bo_info_size)) {
info = vmemdup_array_user(uptr, bo_number, info_size);
--
2.53.0
^ permalink raw reply related [flat|nested] 4+ messages in thread
* Re: [PATCH 5.15 1/2] drm/amdgpu: Use vmemdup_array_user in amdgpu_bo_create_list_entry_array
2026-09-23 14:54 [PATCH 5.15 1/2] drm/amdgpu: Use vmemdup_array_user in amdgpu_bo_create_list_entry_array Roman Demidov
2026-09-23 14:54 ` [PATCH 5.15 2/2] drm/amdgpu: Limit BO list entry count to prevent resource exhaustion Roman Demidov
@ 2026-09-23 15:07 ` sashiko-bot
2026-09-24 7:07 ` Roman
1 sibling, 1 reply; 4+ messages in thread
From: sashiko-bot @ 2026-09-23 15:07 UTC (permalink / raw)
To: Roman Demidov; +Cc: dri-devel
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [Low] build: missing vmemdup_array_user helper
--
commit 4d70c808a81c22c8b9f6c03847fa45f071b2e967
Author: Tvrtko Ursulin <tvrtko.ursulin@igalia.com>
drm/amdgpu: Use vmemdup_array_user in amdgpu_bo_create_list_entry_array
This commit replaces kvmalloc_array() + copy_from_user() with
vmemdup_array_user() on the fast path. This aims to shrink the source code
and improve separation between kernel and userspace slabs.
> diff --git a/drivers/gpu/drm/amd/amdgpu/amdgpu_bo_list.c b/drivers/gpu/drm/amd/amdgpu/amdgpu_bo_list.c
> index 15c45b2a39835..b364f3f5fb918 100644
> --- a/drivers/gpu/drm/amd/amdgpu/amdgpu_bo_list.c
> +++ b/drivers/gpu/drm/amd/amdgpu/amdgpu_bo_list.c
> @@ -223,43 +223,36 @@ void amdgpu_bo_list_put(struct amdgpu_bo_list *list)
> int amdgpu_bo_create_list_entry_array(struct drm_amdgpu_bo_list_in *in,
> struct drm_amdgpu_bo_list_entry **info_param)
> {
[ ... ]
> /* copy the handle array from userspace to a kernel buffer */
> - r = -EFAULT;
> - if (likely(info_size == in->bo_info_size)) {
> - unsigned long bytes = in->bo_number *
> - in->bo_info_size;
> -
> - if (copy_from_user(info, uptr, bytes))
> - goto error_free;
> -
> + if (likely(info_size == bo_info_size)) {
> + info = vmemdup_array_user(uptr, bo_number, info_size);
[Severity: Low]
Does this code call a function vmemdup_array_user() that does not exist in
this kernel tree?
When compiling drivers/gpu/drm/amd/amdgpu/amdgpu_bo_list.c with
CONFIG_DRM_AMDGPU=y or m, this will result in a build failure due to an
implicit function declaration in amdgpu_bo_create_list_entry_array(). If the
compiler allows implicit declarations, it would assume a 32-bit int return
type, which truncates the pointer on 64-bit systems and can lead to an
invalid pointer dereference or use-after-free when IS_ERR(info) or
kvfree(info) is called later.
> + if (IS_ERR(info))
> + return PTR_ERR(info);
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260923145453.76114-1-roman.demidov.nn@gmail.com?part=1
^ permalink raw reply [flat|nested] 4+ messages in thread
* Re: [PATCH 5.15 1/2] drm/amdgpu: Use vmemdup_array_user in amdgpu_bo_create_list_entry_array
2026-09-23 15:07 ` [PATCH 5.15 1/2] drm/amdgpu: Use vmemdup_array_user in amdgpu_bo_create_list_entry_array sashiko-bot
@ 2026-09-24 7:07 ` Roman
0 siblings, 0 replies; 4+ messages in thread
From: Roman @ 2026-09-24 7:07 UTC (permalink / raw)
To: sashiko-reviews; +Cc: dri-devel
[-- Attachment #1: Type: text/plain, Size: 2746 bytes --]
vmemdup_array_user() is already available in 5.15.y via commit 24b17d530c42
(string.h: add array-wrappers for (v)memdup_user()). So there is no
implicit declaration or pointer truncation, and the described build failure
does not apply to the target stable tree.
ср, 23 сент. 2026 г. в 18:07, <sashiko-bot@kernel.org>:
> Thank you for your contribution! Sashiko AI review found 1 potential
> issue(s) to consider:
> - [Low] build: missing vmemdup_array_user helper
> --
>
> commit 4d70c808a81c22c8b9f6c03847fa45f071b2e967
> Author: Tvrtko Ursulin <tvrtko.ursulin@igalia.com>
>
> drm/amdgpu: Use vmemdup_array_user in amdgpu_bo_create_list_entry_array
>
> This commit replaces kvmalloc_array() + copy_from_user() with
> vmemdup_array_user() on the fast path. This aims to shrink the source code
> and improve separation between kernel and userspace slabs.
>
> > diff --git a/drivers/gpu/drm/amd/amdgpu/amdgpu_bo_list.c
> b/drivers/gpu/drm/amd/amdgpu/amdgpu_bo_list.c
> > index 15c45b2a39835..b364f3f5fb918 100644
> > --- a/drivers/gpu/drm/amd/amdgpu/amdgpu_bo_list.c
> > +++ b/drivers/gpu/drm/amd/amdgpu/amdgpu_bo_list.c
> > @@ -223,43 +223,36 @@ void amdgpu_bo_list_put(struct amdgpu_bo_list
> *list)
> > int amdgpu_bo_create_list_entry_array(struct drm_amdgpu_bo_list_in *in,
> > struct drm_amdgpu_bo_list_entry
> **info_param)
> > {
> [ ... ]
> > /* copy the handle array from userspace to a kernel buffer */
> > - r = -EFAULT;
> > - if (likely(info_size == in->bo_info_size)) {
> > - unsigned long bytes = in->bo_number *
> > - in->bo_info_size;
> > -
> > - if (copy_from_user(info, uptr, bytes))
> > - goto error_free;
> > -
> > + if (likely(info_size == bo_info_size)) {
> > + info = vmemdup_array_user(uptr, bo_number, info_size);
>
> [Severity: Low]
> Does this code call a function vmemdup_array_user() that does not exist in
> this kernel tree?
>
> When compiling drivers/gpu/drm/amd/amdgpu/amdgpu_bo_list.c with
> CONFIG_DRM_AMDGPU=y or m, this will result in a build failure due to an
> implicit function declaration in amdgpu_bo_create_list_entry_array(). If
> the
> compiler allows implicit declarations, it would assume a 32-bit int return
> type, which truncates the pointer on 64-bit systems and can lead to an
> invalid pointer dereference or use-after-free when IS_ERR(info) or
> kvfree(info) is called later.
>
> > + if (IS_ERR(info))
> > + return PTR_ERR(info);
>
> --
> Sashiko AI review ·
> https://sashiko.dev/#/patchset/20260923145453.76114-1-roman.demidov.nn@gmail.com?part=1
>
[-- Attachment #2: Type: text/html, Size: 3825 bytes --]
^ permalink raw reply [flat|nested] 4+ messages in thread
end of thread, other threads:[~2026-09-24 7:07 UTC | newest]
Thread overview: 4+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-23 14:54 [PATCH 5.15 1/2] drm/amdgpu: Use vmemdup_array_user in amdgpu_bo_create_list_entry_array Roman Demidov
2026-09-23 14:54 ` [PATCH 5.15 2/2] drm/amdgpu: Limit BO list entry count to prevent resource exhaustion Roman Demidov
2026-09-23 15:07 ` [PATCH 5.15 1/2] drm/amdgpu: Use vmemdup_array_user in amdgpu_bo_create_list_entry_array sashiko-bot
2026-09-24 7:07 ` Roman
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox