From: Hyunwoo Kim <hidden> Date: 2022-06-11 19:28:57
In pxa3xx_gcu_write, a count parameter of
type size_t is passed to words of type int.
Then, copy_from_user may cause a heap overflow because
it is used as the third argument of copy_from_user.
Signed-off-by: Hyunwoo Kim <redacted>
---
drivers/video/fbdev/pxa3xx-gcu.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
@@ -389,7 +389,7 @@ pxa3xx_gcu_write(struct file *file, const char *buff,priv->shared->num_words+=words;/* Last word reserved for batch buffer end command */-if(words>=PXA3XX_GCU_BATCH_WORDS)+if(words>=PXA3XX_GCU_BATCH_WORDS||words<0)return-E2BIG;/* Wait for a free buffer */
In pxa3xx_gcu_write, a count parameter of
type size_t is passed to words of type int.
Then, copy_from_user may cause a heap overflow because
it is used as the third argument of copy_from_user.
I suggest to simply change the type of "words" a few lines above:
Instead of
int words = count / 4;
use
size_t words = count / 4;
count is already of type size_t and then you don't need to check against < 0.
Can you resend such a patch?
Helge
@@ -389,7 +389,7 @@ pxa3xx_gcu_write(struct file *file, const char *buff,priv->shared->num_words+=words;/* Last word reserved for batch buffer end command */-if(words>=PXA3XX_GCU_BATCH_WORDS)+if(words>=PXA3XX_GCU_BATCH_WORDS||words<0)return-E2BIG;/* Wait for a free buffer */
From: Hyunwoo Kim <hidden> Date: 2022-06-20 14:57:37
From 1c55d1e084071caf02e7739e71e65f52206e872c Mon Sep 17 00:00:00 2001
From: Hyunwoo Kim <redacted>
Date: Mon, 20 Jun 2022 07:00:10 -0700
Subject: [PATCH] pxa3xx-gcu: Fix integer overflow in pxa3xx_gcu_write
In pxa3xx_gcu_write, a count parameter of
type size_t is passed to words of type int.
Then, copy_from_user may cause a heap overflow because
it is used as the third argument of copy_from_user.
Signed-off-by: Hyunwoo Kim <redacted>
---
drivers/video/fbdev/pxa3xx-gcu.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
@@ -381,7 +381,7 @@ pxa3xx_gcu_write(struct file *file, const char *buff,structpxa3xx_gcu_batch*buffer;structpxa3xx_gcu_priv*priv=to_pxa3xx_gcu_priv(file);-intwords=count/4;+size_twords=count/4;/* Does not need to be atomic. There's a lock in user space,*butanyhow,thisisjustforstatistics.*/--
2.25.1
Hello Helge,
Fixed the patch as requested.
Regards,
Hyunwoo Kim
From 1c55d1e084071caf02e7739e71e65f52206e872c Mon Sep 17 00:00:00 2001
From: Hyunwoo Kim <redacted>
Date: Mon, 20 Jun 2022 07:00:10 -0700
Subject: [PATCH] pxa3xx-gcu: Fix integer overflow in pxa3xx_gcu_write
In pxa3xx_gcu_write, a count parameter of
type size_t is passed to words of type int.
Then, copy_from_user may cause a heap overflow because
it is used as the third argument of copy_from_user.
Signed-off-by: Hyunwoo Kim <redacted>
@@ -381,7 +381,7 @@ pxa3xx_gcu_write(struct file *file, const char *buff,structpxa3xx_gcu_batch*buffer;structpxa3xx_gcu_priv*priv=to_pxa3xx_gcu_priv(file);-intwords=count/4;+size_twords=count/4;/* Does not need to be atomic. There's a lock in user space,*butanyhow,thisisjustforstatistics.*/--
2.25.1
Hello Helge,
Fixed the patch as requested.
Regards,
Hyunwoo Kim