Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1486686

[PATCH 07/26] drm/rockchip: dw-mipi-dsi: avoid out-of-bounds read on tx_buf

From John Keeping <john@metanate.com>
Newsgroups linux.kernel
Subject [PATCH 07/26] drm/rockchip: dw-mipi-dsi: avoid out-of-bounds read on tx_buf
Date 2016-09-19 19:30 +0200
Message-ID <sjaye-8kP-13@gated-at.bofh.it> (permalink)
References <sjaox-8hd-7@gated-at.bofh.it>
Organization linux.* mail to news gateway

Show all headers | View raw


As a side-effect of this, encode the endianness explicitly rather than
casting a u16.

Signed-off-by: John Keeping <john@metanate.com>
---
 drivers/gpu/drm/rockchip/dw-mipi-dsi.c | 9 +++++++--
 1 file changed, 7 insertions(+), 2 deletions(-)

diff --git a/drivers/gpu/drm/rockchip/dw-mipi-dsi.c b/drivers/gpu/drm/rockchip/dw-mipi-dsi.c
index f2bed2a0f907..38186df8476e 100644
--- a/drivers/gpu/drm/rockchip/dw-mipi-dsi.c
+++ b/drivers/gpu/drm/rockchip/dw-mipi-dsi.c
@@ -573,8 +573,13 @@ static int dw_mipi_dsi_gen_pkt_hdr_write(struct dw_mipi_dsi *dsi, u32 hdr_val)
 static int dw_mipi_dsi_dcs_short_write(struct dw_mipi_dsi *dsi,
 				       const struct mipi_dsi_msg *msg)
 {
-	const u16 *tx_buf = msg->tx_buf;
-	u32 val = GEN_HDATA(*tx_buf) | GEN_HTYPE(msg->type);
+	const u8 *tx_buf = msg->tx_buf;
+	u32 val = GEN_HTYPE(msg->type);
+
+	if (msg->tx_len > 0)
+		val |= GEN_HDATA(tx_buf[0]);
+	if (msg->tx_len > 1)
+		val |= GEN_HDATA(tx_buf[1] << 8);
 
 	if (msg->tx_len > 2) {
 		dev_err(dsi->dev, "too long tx buf length %zu for short write\n",
-- 
2.10.0.278.g4f427b1.dirty

Back to linux.kernel | Previous | NextPrevious in thread | Next in thread | Find similar | Unroll thread


Thread

[PATCH 00/27] drm/rockchip: MIPI fixes & improvements John Keeping <john@metanate.com> - 2016-09-19 19:30 +0200
  [PATCH 07/26] drm/rockchip: dw-mipi-dsi: avoid out-of-bounds read on tx_buf John Keeping <john@metanate.com> - 2016-09-19 19:30 +0200
  [PATCH 15/26] drm/rockchip: dw-mipi-dsi: ensure PHY is reset John Keeping <john@metanate.com> - 2016-09-19 19:30 +0200
  [PATCH 14/26] drm/rockchip: dw-mipi-dsi: fix escape clock rate John Keeping <john@metanate.com> - 2016-09-19 19:30 +0200
  [PATCH 21/27] drm/rockchip: dw-mipi-dsi: improve PLL configuration John Keeping <john@metanate.com> - 2016-09-19 19:30 +0200
  [PATCH 09/26] drm/rockchip: dw-mipi-dsi: respect message flags John Keeping <john@metanate.com> - 2016-09-19 19:30 +0200
  [PATCH 22/26] drm/rockchip: vop: test for P{H,V}SYNC John Keeping <john@metanate.com> - 2016-09-19 19:30 +0200
  [PATCH 18/26] drm/rockchip: dw-mipi-dsi: properly configure PHY timing John Keeping <john@metanate.com> - 2016-09-19 19:30 +0200
  [PATCH 11/26] drm/rockchip: dw-mipi-dsi: don't assume buffer is aligned John Keeping <john@metanate.com> - 2016-09-19 19:30 +0200
  [PATCH 15/27] drm/rockchip: dw-mipi-dsi: use positive check for N{H,V}SYNC John Keeping <john@metanate.com> - 2016-09-19 19:30 +0200
  [PATCH 22/27] drm/rockchip: dw-mipi-dsi: defer probe if panel is not loaded John Keeping <john@metanate.com> - 2016-09-19 19:30 +0200
  [PATCH 18/27] drm/rockchip: dw-mipi-dsi: configure bias and bandgap before enable John Keeping <john@metanate.com> - 2016-09-19 19:30 +0200
  [PATCH 25/26] drm/rockchip: dw-mipi-dsi: add reset control John Keeping <john@metanate.com> - 2016-09-19 19:30 +0200
  [PATCH 16/26] drm/rockchip: dw-mipi-dsi: configure bias and bandgap before enable John Keeping <john@metanate.com> - 2016-09-19 19:30 +0200
  Re: [PATCH 00/27] drm/rockchip: MIPI fixes & improvements John Keeping <john@metanate.com> - 2016-09-19 19:30 +0200
  [PATCH 02/26] drm/rockchip: dw-mipi-dsi: pass new mode into MIPI mode set John Keeping <john@metanate.com> - 2016-09-19 19:30 +0200
  [PATCH 14/27] drm/rockchip: dw-mipi-dsi: use specific poll helper John Keeping <john@metanate.com> - 2016-09-19 19:30 +0200
  [PATCH 20/27] drm/rockchip: dw-mipi-dsi: properly configure PHY timing John Keeping <john@metanate.com> - 2016-09-19 19:30 +0200
  [PATCH 23/26] drm/rockchip: dw-mipi-dsi: defer probe if panel is not loaded John Keeping <john@metanate.com> - 2016-09-19 19:30 +0200
  [PATCH 16/27] drm/rockchip: dw-mipi-dsi: fix escape clock rate John Keeping <john@metanate.com> - 2016-09-19 19:30 +0200
  [PATCH 24/26] drm/rockchip: dw-mipi-dsi: support non-burst modes John Keeping <john@metanate.com> - 2016-09-19 19:40 +0200
  [PATCH 23/27] drm/rockchip: dw-mipi-dsi: support non-burst modes John Keeping <john@metanate.com> - 2016-09-19 19:40 +0200
  [PATCH 24/27] drm/rockchip: vop: test for P{H,V}SYNC John Keeping <john@metanate.com> - 2016-09-19 19:40 +0200

csiph-web