From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-wm1-f41.google.com (mail-wm1-f41.google.com [209.85.128.41]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 6BBED356A28 for ; Tue, 27 Jan 2026 19:40:23 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.128.41 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1769542824; cv=none; b=TF6CpqGsjIxYAJgYAlBpaQMv9q9qkonySlr3X3ePgUnbfP95TPp/JvjFKt7SgaJioZO9mmO+KVyYPpIawpvdkpSpiC70cRP1AZ3vz6WQTrkLy6CdgwI7WyCacXpJyc+moeWDYAoPC2ChMHflR+fCTAkqqwEH/kpZ2Kdzydm+tl0= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1769542824; c=relaxed/simple; bh=zvk5je7zKiUla10UlKAmaAQo+KOtZIQ20YbfxH9bHi8=; h=Date:From:To:Cc:Subject:Message-ID:References:MIME-Version: Content-Type:Content-Disposition:In-Reply-To; b=SSi5sCE7iU5ljlk1MiNGTD3cRog9xSibqu2LU0rLThtpelJopxAc318TtFrJDvi1Rw3XJf1O9Mpp9H/rZU95jKmn231F1O+i2I4ui5AotUgQFqBEKJQRlCPECd96ASJkYytwf3hgrjXPvuTrfy3yrgI2o3CMvzo0r0yoV7sJ2ps= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=YJVu4Q5x; arc=none smtp.client-ip=209.85.128.41 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="YJVu4Q5x" Received: by mail-wm1-f41.google.com with SMTP id 5b1f17b1804b1-47edffe5540so69913325e9.0 for ; Tue, 27 Jan 2026 11:40:23 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20230601; t=1769542821; x=1770147621; darn=vger.kernel.org; h=in-reply-to:content-disposition:mime-version:references:message-id :subject:cc:to:from:date:from:to:cc:subject:date:message-id:reply-to; bh=b52qO2yFLp3y0SMOMTd2WsGkQfNWU95x2F2WxKXZb6k=; b=YJVu4Q5xKjWbwJ9tW8DWkmMSED/uWDpbt/6I3mzGa5mOytt4zfd2u1sZoX8Axfmvwn q3pneoh4YYMe+g91KhEWwpY/i8uxPhLJtalvr9IEJqFqBpy3NPR+vbvKy9RRgvQgRrwo m3iamg4MfVrXQKOuZrb4VLS2oysST+ElxKpy8yLsiqB3uXmXCcdKl5+a79D7OsfC7Wen QLWP8OHnfMX8cc3AZordzuSnqT9gNXPTBlq4u5zy3ZoW1QF71eGHPIwxJmbmavIlT0/h VSdXx1JwnBTD+n+dlxPRDH57E/jfrugS1P6ugYQ0GuCVqOodGmcbC+MvsnrTjLR88Iv1 Sxjw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1769542821; x=1770147621; h=in-reply-to:content-disposition:mime-version:references:message-id :subject:cc:to:from:date:x-gm-gg:x-gm-message-state:from:to:cc :subject:date:message-id:reply-to; bh=b52qO2yFLp3y0SMOMTd2WsGkQfNWU95x2F2WxKXZb6k=; b=l9NEsGcuW+yNVua5pfKN7GiYkMbpgkBUDEVpKmL/j6mBrQ8W8hG0EGgewu4HUo5pfF nD803hNksqRCkb3LjpNgQY3nHeLcewUfc3MLhCouQFSomN1lREtcIXOrerK607nB1u+f 1CYVvaKxbeYTVxcAK3qDomqPX4VFo6n4APA4UmKstqrJk2/MBR18eTHuUxyWHfwsVjA3 d6sjXI1hU/t0y7zZOMclgyJJgQPY8EVA97kGaUHSR4i9IepdOOHIsUIlG8Rzk4aAXAYT rW5amShmSYJuo3QlToEETKpTDVlYVJcfoLneN7hkK5LRDAAd7cVl5qjWgTfjkG4ygLk7 oVKA== X-Forwarded-Encrypted: i=1; AJvYcCVh5UJf0YIlBCYcUAqHFLr3hVmNN47QWX+mXpw00N+/O00nNHL/7af9tb8CKKEqroLBp0I5OeDk1UZXVN0=@vger.kernel.org X-Gm-Message-State: AOJu0Yxdd3wZE4NDI7EW9pJHqeye78JoIoLDq9woaqHjvc2m59PtXphp x69CrhMHUREWARfYK2L/21hdCnY5aQ7KWdW6AM6yPIocBdHWD9aIXJaI X-Gm-Gg: AZuq6aKcjymI+IoesbiNBM91zOC8Fqhjr3KQ3WDyYmhX48gcEzYDR0dmPDF6Df1P7JI ZawJexLiXFR02BO84rh7e5wjWVk2rzSsdM33UxgB/LNShOWL3xOAbydd+sePF4JiE/1abVA3jnS dY+yDlgkwadMHTGMsSCBhDaYvxTFvo3hjgJMCdZvbltUqKFfLKCO7wK1dlU4E6T0UY7zLE7qPaV l7LLNdro7PPmJvN+7C/C9MG//5a6u3Q2J92GDKcB4GDpQfNvYmCKmwQocZN2doAAJOachvhZGJ/ DaoWUYG5hnAh3ukSKVzhzKAU8oa59ucWb4+pHuKqkQ6qIsBKLqfiWmoWWRvyOJ7oKzYFfVaiTvc OB5nLvg1PmGbbAoMnAFrEGpqFVyXZ7jhZ74cjEJFyG3kt1QHdxrmYE7NH5Qk9EONZPXxG1Ibwqz fTpB/Tpk4lkcVC4Q0i267B7LTzgFVgfdAhq+DbTGw= X-Received: by 2002:a05:600c:350b:b0:47a:935f:61a0 with SMTP id 5b1f17b1804b1-48069b9a017mr35915635e9.0.1769542821228; Tue, 27 Jan 2026 11:40:21 -0800 (PST) Received: from osama ([41.37.41.91]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-435e10ee562sm1088358f8f.18.2026.01.27.11.40.19 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 27 Jan 2026 11:40:20 -0800 (PST) Date: Tue, 27 Jan 2026 20:40:15 +0100 From: Osama Abdelkader To: Helge Deller Cc: Simona Vetter , Thomas Zimmermann , Lee Jones , "Daniel Thompson (RISCstar)" , Murad Masimov , Quanmin Yan , Yongzhen Zhang , linux-fbdev@vger.kernel.org, dri-devel@lists.freedesktop.org, linux-kernel@vger.kernel.org, syzbot+55e03490a0175b8dd81d@syzkaller.appspotmail.com Subject: Re: [PATCH v2] fbdev: avoid out-of-bounds read in fb_pad_unaligned_buffer() Message-ID: References: <20260124164633.20444-1-osama.abdelkader@gmail.com> <889fd11b-80ea-4c23-b47f-4e6b17536b0f@gmx.de> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <889fd11b-80ea-4c23-b47f-4e6b17536b0f@gmx.de> On Tue, Jan 27, 2026 at 06:57:32PM +0100, Helge Deller wrote: > On 1/24/26 17:46, Osama Abdelkader wrote: > > fb_pad_unaligned_buffer() unconditionally reads and advances the source > > pointer for the final byte of each row, even when no bits from that byte > > are actually consumed. > > > > When shift_high >= mod, the remaining bits do not cross a byte boundary, > > but the code still accesses the next source byte. This can lead to > > out-of-bounds reads under malformed geometry, as reported by syzbot. > > > > Fix this by only accessing and consuming the final source byte when it > > contributes bits (shift_high < mod). > > > > This fixes the KASAN slab-out-of-bounds read reported by syzkaller: > > https://syzkaller.appspot.com/bug?extid=55e03490a0175b8dd81d > > > > Reported-by: syzbot+55e03490a0175b8dd81d@syzkaller.appspotmail.com > > Closes: https://syzkaller.appspot.com/bug?extid=55e03490a0175b8dd81d > > Signed-off-by: Osama Abdelkader > > --- > > v2: address the real issue (shift_high >= mod) condition. > > --- > > drivers/video/fbdev/core/fbmem.c | 15 +++++++++------ > > 1 file changed, 9 insertions(+), 6 deletions(-) > > > > diff --git a/drivers/video/fbdev/core/fbmem.c b/drivers/video/fbdev/core/fbmem.c > > index eff757ebbed1..d125c3db37a1 100644 > > --- a/drivers/video/fbdev/core/fbmem.c > > +++ b/drivers/video/fbdev/core/fbmem.c > > @@ -100,7 +100,7 @@ EXPORT_SYMBOL(fb_pad_aligned_buffer); > > void fb_pad_unaligned_buffer(u8 *dst, u32 d_pitch, u8 *src, u32 idx, u32 height, > > u32 shift_high, u32 shift_low, u32 mod) > > { > > - u8 mask = (u8) (0xfff << shift_high), tmp; > > + u8 mask = (u8) (0xff << shift_high), tmp; > > This part is correct, but shouldn't be part of this patch. I just sent a seperate patch for that, and going to remove it in next version of this one. > > > > int i, j; > > for (i = height; i--; ) { > > @@ -113,15 +113,18 @@ void fb_pad_unaligned_buffer(u8 *dst, u32 d_pitch, u8 *src, u32 idx, u32 height, > > dst[j+1] = tmp; > > src++; > > } > > - tmp = dst[idx]; > > - tmp &= mask; > > - tmp |= *src >> shift_low; > > - dst[idx] = tmp; > > + > > + /* Only consume another source byte if it contributes bits */ > > if (shift_high < mod) { > > + tmp = dst[idx]; > > + tmp &= mask; > > + tmp |= *src >> shift_low; > > + dst[idx] = tmp; > > tmp = *src << shift_high; > > dst[idx+1] = tmp; > > + src++; > > } > > - src++; > > Above you moved the src pointer inside the if(), so every line > processed may miss a ptr increment. This means the source would need to > be different too, but it hasn't changed, as it's still used from > bit_putcs_unaligned() which prints a char from the character fonts. > > So, I believe this part at least is wrong. > Did you test it? > I couldn't find syzbot's ReproC, so I did minimal one, I will re-test it and write you. > Helge BR, Osama