Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1487450

[PATCH][V2] drm/amdgpu: avoid out of bounds access on array interrupt_status_offsets

From Colin King <colin.king@canonical.com>
Newsgroups linux.kernel
Subject [PATCH][V2] drm/amdgpu: avoid out of bounds access on array interrupt_status_offsets
Date 2016-09-20 17:50 +0200
Message-ID <sjvt0-4Ti-19@gated-at.bofh.it> (permalink)
Organization linux.* mail to news gateway

Show all headers | View raw


From: Colin Ian King <colin.king@canonical.com>

The check for an out of bound index into array interrupt_status_offsets
is off-by-one. Fix this and also don't compared to a hard coded array
size but use adev->mode_info.num_hpd instead.

Signed-off-by: Colin Ian King <colin.king@canonical.com>
---
 drivers/gpu/drm/amd/amdgpu/dce_v6_0.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/drivers/gpu/drm/amd/amdgpu/dce_v6_0.c b/drivers/gpu/drm/amd/amdgpu/dce_v6_0.c
index d3512f3..4ce4c1a 100644
--- a/drivers/gpu/drm/amd/amdgpu/dce_v6_0.c
+++ b/drivers/gpu/drm/amd/amdgpu/dce_v6_0.c
@@ -2782,7 +2782,7 @@ static int dce_v6_0_hpd_irq(struct amdgpu_device *adev,
 	uint32_t disp_int, mask, int_control, tmp;
 	unsigned hpd;
 
-	if (entry->src_data > 6) {
+	if (entry->src_data >= adev->mode_info.num_hpd) {
 		DRM_DEBUG("Unhandled interrupt: %d %d\n", entry->src_id, entry->src_data);
 		return 0;
 	}
-- 
2.9.3

Back to linux.kernel | Previous | NextNext in thread | Find similar | Unroll thread


Thread

[PATCH][V2] drm/amdgpu: avoid out of bounds access on array interrupt_status_offsets Colin King <colin.king@canonical.com> - 2016-09-20 17:50 +0200
  Re: [PATCH][V2] drm/amdgpu: avoid out of bounds access on array interrupt_status_offsets Alex Deucher <alexdeucher@gmail.com> - 2016-09-20 18:00 +0200

csiph-web