mirror of
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
synced 2026-09-22 09:34:56 +02:00
drm/amdgpu: Add basic validation for RAS header
commit 5df0d6addb upstream.
If RAS header read from EEPROM is corrupted, it could result in trying
to allocate huge memory for reading the records. Add some validation to
header fields.
Signed-off-by: Lijo Lazar <lijo.lazar@amd.com>
Reviewed-by: Hawking Zhang <Hawking.Zhang@amd.com>
Signed-off-by: Alex Deucher <alexander.deucher@amd.com>
[ RAS_TABLE_VER_V3 is not supported in v6.6.y. ]
Signed-off-by: Alva Lan <alvalan9@foxmail.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
This commit is contained in:
committed by
Greg Kroah-Hartman
parent
ce63943f9b
commit
e1903358b2
@@ -1338,15 +1338,31 @@ int amdgpu_ras_eeprom_init(struct amdgpu_ras_eeprom_control *control,
|
||||
|
||||
__decode_table_header_from_buf(hdr, buf);
|
||||
|
||||
if (hdr->version == RAS_TABLE_VER_V2_1) {
|
||||
switch (hdr->version) {
|
||||
case RAS_TABLE_VER_V2_1:
|
||||
control->ras_num_recs = RAS_NUM_RECS_V2_1(hdr);
|
||||
control->ras_record_offset = RAS_RECORD_START_V2_1;
|
||||
control->ras_max_record_count = RAS_MAX_RECORD_COUNT_V2_1;
|
||||
} else {
|
||||
break;
|
||||
case RAS_TABLE_VER_V1:
|
||||
control->ras_num_recs = RAS_NUM_RECS(hdr);
|
||||
control->ras_record_offset = RAS_RECORD_START;
|
||||
control->ras_max_record_count = RAS_MAX_RECORD_COUNT;
|
||||
break;
|
||||
default:
|
||||
dev_err(adev->dev,
|
||||
"RAS header invalid, unsupported version: %u",
|
||||
hdr->version);
|
||||
return -EINVAL;
|
||||
}
|
||||
|
||||
if (control->ras_num_recs > control->ras_max_record_count) {
|
||||
dev_err(adev->dev,
|
||||
"RAS header invalid, records in header: %u max allowed :%u",
|
||||
control->ras_num_recs, control->ras_max_record_count);
|
||||
return -EINVAL;
|
||||
}
|
||||
|
||||
control->ras_fri = RAS_OFFSET_TO_INDEX(control, hdr->first_rec_offset);
|
||||
|
||||
if (hdr->header == RAS_TABLE_HDR_VAL) {
|
||||
|
||||
Reference in New Issue
Block a user