2021-12-18 04:22:51

by Yizhuo Zhai

[permalink] [raw]
Subject: [PATCH] drm/amd/display: Fix the uninitialized variable in enable_stream_features()

In function enable_stream_features(), the variable "old_downspread.raw"
could be uninitialized if core_link_read_dpcd() fails, however, it is
used in the later if statement, and further, core_link_write_dpcd()
may write random value, which is potentially unsafe.

Fixes: 6016cd9dba0f ("drm/amd/display: add helper for enabling mst stream features")
Cc: [email protected]
Signed-off-by: Yizhuo Zhai <[email protected]>
---
drivers/gpu/drm/amd/display/dc/core/dc_link.c | 2 ++
1 file changed, 2 insertions(+)

diff --git a/drivers/gpu/drm/amd/display/dc/core/dc_link.c b/drivers/gpu/drm/amd/display/dc/core/dc_link.c
index c8457babfdea..fd5a0e7eb029 100644
--- a/drivers/gpu/drm/amd/display/dc/core/dc_link.c
+++ b/drivers/gpu/drm/amd/display/dc/core/dc_link.c
@@ -1844,6 +1844,8 @@ static void enable_stream_features(struct pipe_ctx *pipe_ctx)
union down_spread_ctrl old_downspread;
union down_spread_ctrl new_downspread;

+ memset(&old_downspread, 0, sizeof(old_downspread));
+
core_link_read_dpcd(link, DP_DOWNSPREAD_CTRL,
&old_downspread.raw, sizeof(old_downspread));

--
2.25.1



2021-12-22 14:36:15

by Alex Deucher

[permalink] [raw]
Subject: Re: [PATCH] drm/amd/display: Fix the uninitialized variable in enable_stream_features()

Applied. Thanks!

Alex

On Fri, Dec 17, 2021 at 11:22 PM Yizhuo Zhai <[email protected]> wrote:
>
> In function enable_stream_features(), the variable "old_downspread.raw"
> could be uninitialized if core_link_read_dpcd() fails, however, it is
> used in the later if statement, and further, core_link_write_dpcd()
> may write random value, which is potentially unsafe.
>
> Fixes: 6016cd9dba0f ("drm/amd/display: add helper for enabling mst stream features")
> Cc: [email protected]
> Signed-off-by: Yizhuo Zhai <[email protected]>
> ---
> drivers/gpu/drm/amd/display/dc/core/dc_link.c | 2 ++
> 1 file changed, 2 insertions(+)
>
> diff --git a/drivers/gpu/drm/amd/display/dc/core/dc_link.c b/drivers/gpu/drm/amd/display/dc/core/dc_link.c
> index c8457babfdea..fd5a0e7eb029 100644
> --- a/drivers/gpu/drm/amd/display/dc/core/dc_link.c
> +++ b/drivers/gpu/drm/amd/display/dc/core/dc_link.c
> @@ -1844,6 +1844,8 @@ static void enable_stream_features(struct pipe_ctx *pipe_ctx)
> union down_spread_ctrl old_downspread;
> union down_spread_ctrl new_downspread;
>
> + memset(&old_downspread, 0, sizeof(old_downspread));
> +
> core_link_read_dpcd(link, DP_DOWNSPREAD_CTRL,
> &old_downspread.raw, sizeof(old_downspread));
>
> --
> 2.25.1
>