vmwgfx: integer overflow in vmw_kms_update_layout_ioctl()
There are two issues in vmw_kms_update_layout_ioctl(). First, the
for loop forgets to index rects and only checks the first element.
Second, there is a potential integer overflow if userspace passes
in a large arg->num_outputs. The call to kzalloc() would allocate
a small buffer, leading to out-of-bounds read.
Reported-by: Haogang Chen <firstname.lastname@example.org>
Signed-off-by: Xi Wang <email@example.com>
Signed-off-by: Thomas Hellstrom <firstname.lastname@example.org>
Signed-off-by: Dave Airlie <email@example.com>
1 file changed