From: George Kennedy <hidden> Date: 2020-07-07 19:26:03
A fb_ioctl() FBIOPUT_VSCREENINFO call with invalid xres setting
or yres setting in struct fb_var_screeninfo will result in a
KASAN: vmalloc-out-of-bounds failure in bitfill_aligned() as
the margins are being cleared. The margins are cleared in
chunks and if the xres setting or yres setting is a value of
zero upto the chunk size, the failure will occur.
Add a margin check to validate xres and yres settings.
Signed-off-by: George Kennedy <redacted>
Suggested-by: Dan Carpenter <redacted>
Reported-by: syzbot+e5fd3e65515b48c02a30@syzkaller.appspotmail.com
---
drivers/video/fbdev/core/fbmem.c | 4 ++++
1 file changed, 4 insertions(+)
@@ -1007,6 +1007,10 @@ static int fb_check_caps(struct fb_info *info, struct fb_var_screeninfo *var,return0;}+/* bitfill_aligned() assumes that it's at least 8x8 */+if(var->xres<8||var->yres<8)+return-EINVAL;+ret=info->fbops->fb_check_var(var,info);if(ret)
From: Dan Carpenter <hidden> Date: 2020-07-07 19:47:14
On Tue, Jul 07, 2020 at 03:26:03PM -0400, George Kennedy wrote:
A fb_ioctl() FBIOPUT_VSCREENINFO call with invalid xres setting
or yres setting in struct fb_var_screeninfo will result in a
KASAN: vmalloc-out-of-bounds failure in bitfill_aligned() as
the margins are being cleared. The margins are cleared in
chunks and if the xres setting or yres setting is a value of
zero upto the chunk size, the failure will occur.
Add a margin check to validate xres and yres settings.
Signed-off-by: George Kennedy <redacted>
Suggested-by: Dan Carpenter <redacted>
Suggested-by is perhaps a bit strong. Let's change that to:
Reviewed-by: Dan Carpenter <redacted>
regards,
dan carpenter
[ added dri-devel ML to Cc: ]
On 7/7/20 9:47 PM, Dan Carpenter wrote:
On Tue, Jul 07, 2020 at 03:26:03PM -0400, George Kennedy wrote:
quoted
A fb_ioctl() FBIOPUT_VSCREENINFO call with invalid xres setting
or yres setting in struct fb_var_screeninfo will result in a
KASAN: vmalloc-out-of-bounds failure in bitfill_aligned() as
the margins are being cleared. The margins are cleared in
chunks and if the xres setting or yres setting is a value of
zero upto the chunk size, the failure will occur.
Add a margin check to validate xres and yres settings.
Signed-off-by: George Kennedy <redacted>
Suggested-by: Dan Carpenter <redacted>
Suggested-by is perhaps a bit strong. Let's change that to:
Reviewed-by: Dan Carpenter <redacted>
Applied to drm-misc-next tree, thanks and sorry for the delay.
Best regards,
--
Bartlomiej Zolnierkiewicz
Samsung R&D Institute Poland
Samsung Electronics