Linux kernel -stable discussions
 help / color / mirror / Atom feed
* [PATCH] drm/amd/display: Check link_index before accessing dc->links[]
@ 2025-01-23 12:08 Shubham Pushpkar
  2025-01-23 12:10 ` kernel test robot
  2025-01-23 14:10 ` Greg KH
  0 siblings, 2 replies; 3+ messages in thread
From: Shubham Pushpkar @ 2025-01-23 12:08 UTC (permalink / raw)
  To: stable
  Cc: linux-kernel, deeratho, Harry Wentland, Tom Chung, Daniel Wheeler,
	Shubham Pushpkar

From: Alex Hung <alex.hung@amd.com>

commit 8aa2864044b9d13e95fe224f32e808afbf79ecdf ("drm/amd/display:
Check link_index before accessing dc->links[]")

[WHY & HOW]
dc->links[] has max size of MAX_LINKS and NULL is return when trying to
access with out-of-bound index.

This fixes 3 OVERRUN and 1 RESOURCE_LEAK issues reported by Coverity.

Fixes: CVE-2024-46813
Reviewed-by: Harry Wentland <harry.wentland@amd.com>
Acked-by: Tom Chung <chiahsuan.chung@amd.com>
Signed-off-by: Alex Hung <alex.hung@amd.com>
Tested-by: Daniel Wheeler <daniel.wheeler@amd.com>
Signed-off-by: Alex Deucher <alexander.deucher@amd.com>
(cherry picked from commit 8aa2864044b9d13e95fe224f32e808afbf79ecdf)
Signed-off-by: Shubham Pushpkar <spushpka@cisco.com>
---
 drivers/gpu/drm/amd/display/dc/core/dc_link_exports.c | 3 +++
 1 file changed, 3 insertions(+)

diff --git a/drivers/gpu/drm/amd/display/dc/core/dc_link_exports.c b/drivers/gpu/drm/amd/display/dc/core/dc_link_exports.c
index f365773d5714..b5639e88c581 100644
--- a/drivers/gpu/drm/amd/display/dc/core/dc_link_exports.c
+++ b/drivers/gpu/drm/amd/display/dc/core/dc_link_exports.c
@@ -37,6 +37,9 @@
 #include "dce/dce_i2c.h"
 struct dc_link *dc_get_link_at_index(struct dc *dc, uint32_t link_index)
 {
+	if (link_index >= MAX_LINKS)
+		return NULL;
+
 	return dc->links[link_index];
 }
 
-- 
2.35.6


^ permalink raw reply related	[flat|nested] 3+ messages in thread

* Re: [PATCH] drm/amd/display: Check link_index before accessing dc->links[]
  2025-01-23 12:08 [PATCH] drm/amd/display: Check link_index before accessing dc->links[] Shubham Pushpkar
@ 2025-01-23 12:10 ` kernel test robot
  2025-01-23 14:10 ` Greg KH
  1 sibling, 0 replies; 3+ messages in thread
From: kernel test robot @ 2025-01-23 12:10 UTC (permalink / raw)
  To: Shubham Pushpkar; +Cc: stable, oe-kbuild-all

Hi,

Thanks for your patch.

FYI: kernel test robot notices the stable kernel rule is not satisfied.

The check is based on https://www.kernel.org/doc/html/latest/process/stable-kernel-rules.html#option-1

Rule: add the tag "Cc: stable@vger.kernel.org" in the sign-off area to have the patch automatically included in the stable tree.
Subject: [PATCH] drm/amd/display: Check link_index before accessing dc->links[]
Link: https://lore.kernel.org/stable/20250123120822.1983325-1-spushpka%40cisco.com

-- 
0-DAY CI Kernel Test Service
https://github.com/intel/lkp-tests/wiki




^ permalink raw reply	[flat|nested] 3+ messages in thread

* Re: [PATCH] drm/amd/display: Check link_index before accessing dc->links[]
  2025-01-23 12:08 [PATCH] drm/amd/display: Check link_index before accessing dc->links[] Shubham Pushpkar
  2025-01-23 12:10 ` kernel test robot
@ 2025-01-23 14:10 ` Greg KH
  1 sibling, 0 replies; 3+ messages in thread
From: Greg KH @ 2025-01-23 14:10 UTC (permalink / raw)
  To: Shubham Pushpkar
  Cc: stable, linux-kernel, deeratho, Harry Wentland, Tom Chung,
	Daniel Wheeler

On Thu, Jan 23, 2025 at 04:08:22AM -0800, Shubham Pushpkar wrote:
> From: Alex Hung <alex.hung@amd.com>
> 
> commit 8aa2864044b9d13e95fe224f32e808afbf79ecdf ("drm/amd/display:
> Check link_index before accessing dc->links[]")
> 
> [WHY & HOW]
> dc->links[] has max size of MAX_LINKS and NULL is return when trying to
> access with out-of-bound index.
> 
> This fixes 3 OVERRUN and 1 RESOURCE_LEAK issues reported by Coverity.
> 
> Fixes: CVE-2024-46813
> Reviewed-by: Harry Wentland <harry.wentland@amd.com>
> Acked-by: Tom Chung <chiahsuan.chung@amd.com>
> Signed-off-by: Alex Hung <alex.hung@amd.com>
> Tested-by: Daniel Wheeler <daniel.wheeler@amd.com>
> Signed-off-by: Alex Deucher <alexander.deucher@amd.com>
> (cherry picked from commit 8aa2864044b9d13e95fe224f32e808afbf79ecdf)
> Signed-off-by: Shubham Pushpkar <spushpka@cisco.com>
> ---
>  drivers/gpu/drm/amd/display/dc/core/dc_link_exports.c | 3 +++
>  1 file changed, 3 insertions(+)

What branch is this for?

thanks,

greg k-h

^ permalink raw reply	[flat|nested] 3+ messages in thread

end of thread, other threads:[~2025-01-23 14:10 UTC | newest]

Thread overview: 3+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2025-01-23 12:08 [PATCH] drm/amd/display: Check link_index before accessing dc->links[] Shubham Pushpkar
2025-01-23 12:10 ` kernel test robot
2025-01-23 14:10 ` Greg KH

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox