Commit 4f69851f authored by Dan Carpenter's avatar Dan Carpenter Committed by Chris Wilson

drm/i810: Prevent underflow in ioctl

The "used" variables here come from the user in the ioctl and it can be
negative.  It could result in an out of bounds write.
Signed-off-by: default avatarDan Carpenter <dan.carpenter@oracle.com>
Reviewed-by: default avatarChris Wilson <chris@chris-wilson.co.uk>
Signed-off-by: default avatarChris Wilson <chris@chris-wilson.co.uk>
Link: https://patchwork.freedesktop.org/patch/msgid/20191004102251.GC823@mwanda
Cc: stable@vger.kernel.org
parent ba2a1c87
...@@ -728,7 +728,7 @@ static void i810_dma_dispatch_vertex(struct drm_device *dev, ...@@ -728,7 +728,7 @@ static void i810_dma_dispatch_vertex(struct drm_device *dev,
if (nbox > I810_NR_SAREA_CLIPRECTS) if (nbox > I810_NR_SAREA_CLIPRECTS)
nbox = I810_NR_SAREA_CLIPRECTS; nbox = I810_NR_SAREA_CLIPRECTS;
if (used > 4 * 1024) if (used < 0 || used > 4 * 1024)
used = 0; used = 0;
if (sarea_priv->dirty) if (sarea_priv->dirty)
...@@ -1048,7 +1048,7 @@ static void i810_dma_dispatch_mc(struct drm_device *dev, struct drm_buf *buf, in ...@@ -1048,7 +1048,7 @@ static void i810_dma_dispatch_mc(struct drm_device *dev, struct drm_buf *buf, in
if (u != I810_BUF_CLIENT) if (u != I810_BUF_CLIENT)
DRM_DEBUG("MC found buffer that isn't mine!\n"); DRM_DEBUG("MC found buffer that isn't mine!\n");
if (used > 4 * 1024) if (used < 0 || used > 4 * 1024)
used = 0; used = 0;
sarea_priv->dirty = 0x7f; sarea_priv->dirty = 0x7f;
......
Markdown is supported
0%
or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment