blob: c1d003a5ccdb121ea4013922b990346d2a90b181 [file]
From 8321b093fa6c297b80586460ce6914d9655df170 Mon Sep 17 00:00:00 2001
From: Osama Abdelkader <osama.abdelkader@gmail.com>
Date: Mon, 20 Jul 2026 13:32:11 +0200
Subject: drm/panthor: harden firmware build-info bounds checks
From: Osama Abdelkader <osama.abdelkader@gmail.com>
commit 8321b093fa6c297b80586460ce6914d9655df170 upstream.
panthor_fw_read_build_info() checks whether the metadata range fits in the
firmware image with hdr.meta_start + hdr.meta_size. Both fields are u32, so
the addition can wrap and let an out-of-bounds range pass validation.
The function also reads the "git_sha: " prefix without first checking that
the metadata is long enough, and meta_size == 0 can underflow the NULL
terminator index.
Use subtraction-based bounds checking and reject metadata that is too short
to contain the expected prefix and trailing NULL byte.
Fixes: 2718d91816ee ("drm/panthor: Add the FW logical block")
Cc: stable@vger.kernel.org
Signed-off-by: Osama Abdelkader <osama.abdelkader@gmail.com>
Reviewed-by: Steven Price <steven.price@arm.com>
Signed-off-by: Steven Price <steven.price@arm.com>
Link: https://patch.msgid.link/20260720113212.11981-1-osama.abdelkader@gmail.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/gpu/drm/panthor/panthor_fw.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
--- a/drivers/gpu/drm/panthor/panthor_fw.c
+++ b/drivers/gpu/drm/panthor/panthor_fw.c
@@ -707,7 +707,8 @@ static int panthor_fw_read_build_info(st
return ret;
if (hdr.meta_start > fw->size ||
- hdr.meta_start + hdr.meta_size > fw->size) {
+ hdr.meta_size > fw->size - hdr.meta_start ||
+ hdr.meta_size <= header_len) {
drm_err(&ptdev->base, "Firmware build info corrupt\n");
/* We don't need the build info, so continue */
return 0;