Received: by 2002:a25:4158:0:0:0:0:0 with SMTP id o85csp172061yba; Mon, 20 May 2019 06:53:08 -0700 (PDT) X-Google-Smtp-Source: APXvYqxgmQvGc7vFLEZ3XmhdtTNy4aeQX2jSkba1oK1wVJVeTGvdomAMrRadyMm4LJ5coEfShBWz X-Received: by 2002:a17:902:8e87:: with SMTP id bg7mr68511161plb.281.1558360388202; Mon, 20 May 2019 06:53:08 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1558360388; cv=none; d=google.com; s=arc-20160816; b=w0xJnHd7dHkop0qBD2UMWc5AM7POIH6KyRNw0leS2uzaSnNklY1xMCKTl59qZZg9+5 6NlWgcVahw8GAkqFb0VvgJw818cuqt5c1fceTMhsEBczJ4jipyW74iQyLYlOvzR6Wr/0 SMw2wKuDP+ZLIMj3Twpj4DZ/F1VpTkpfF5JsBpJo2HVs9dyc/zWEhhYspXqAoChKE3qC zMU39rVy4pBQomC3zyWM8j95eCvgPYfI+qEKUv2OgXdUlmzJKseh55Rw5uWaZuaY+SV8 auyOhDpatIAz9Ijj6D2NIJSBAYoQiD7Ngi8HDANlcyHZr11MgDwX7FgbCcDjiL8l0mio HqWA== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:sender:to:content-transfer-encoding:mime-version :message-id:date:subject:cc:from:dkim-signature; bh=+fjtvBI18+4dOm0uYdGwPyts2yAmhCRRn5DGw8hysxY=; b=v728u/kCc6R5AKyCTpv/6N1T6EQWaE1WHpShK0mY0XqkxRRG7pPtjlS69RWQdSMyOO ALJYwbKobxu9gajDhkMc5ILr1dozGKtnd866SX2KaDGe4TuZ7fl7j4WFsQRLTJyzQQjL 6TjjZsz4FCez9ivkKO7KqgzizS/N7G1iXseiJLyid4aqo38C/wDZ7VKOC9e1qnQW7tNT xegaamXgIUMqoVonpJ8SRCShMM/pHts9QpmDZiIy1I+vNTbDjn7wl8K0Jot8GPWbYZnL KM/AWcENTkEVWgZvGzcyo7kP5LW2+qxpc9+GrViapkLzMyykqgJ7HTvXeZcBX8mRyITY nNSA== ARC-Authentication-Results: i=1; mx.google.com; dkim=fail header.i=@gmail.com header.s=20161025 header.b="KUn1g5/T"; spf=pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=fail (p=NONE sp=QUARANTINE dis=NONE) header.from=gmail.com Return-Path: Received: from vger.kernel.org (vger.kernel.org. [209.132.180.67]) by mx.google.com with ESMTP id s73si10630167pfs.15.2019.05.20.06.52.53; Mon, 20 May 2019 06:53:08 -0700 (PDT) Received-SPF: pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) client-ip=209.132.180.67; Authentication-Results: mx.google.com; dkim=fail header.i=@gmail.com header.s=20161025 header.b="KUn1g5/T"; spf=pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=fail (p=NONE sp=QUARANTINE dis=NONE) header.from=gmail.com Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1730740AbfETJ6x (ORCPT + 99 others); Mon, 20 May 2019 05:58:53 -0400 Received: from mail-pl1-f196.google.com ([209.85.214.196]:42794 "EHLO mail-pl1-f196.google.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1730221AbfETJ6x (ORCPT ); Mon, 20 May 2019 05:58:53 -0400 Received: by mail-pl1-f196.google.com with SMTP id x15so6479945pln.9 for ; Mon, 20 May 2019 02:58:53 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=from:to:cc:subject:date:message-id:mime-version :content-transfer-encoding; bh=+fjtvBI18+4dOm0uYdGwPyts2yAmhCRRn5DGw8hysxY=; b=KUn1g5/T7/kkbkiWBQl45OWxshQehWVf1/UP9bgWFIfx9chCmsx6fpjCJaoEzKBo1a otJJsSeR/66OGpQdHq0U4tSLrCZ7lvim/usSC67EgaavaxXFCPxSrC+yZvHVK0Bhn7HX PTkga2R/vMEJgUP8LDZst+RSCzXwxAtMgNEuv0fpbqQQnONeSeYKi2MIoVDVB+GE9WbE IT5Ua3LPBc3IgbQidvWKTlxqeKkABXxE20AbQlTGAbvG7xXx+iJXX2W2igMBVmeNU574 2aY64x0kCJGofeBSsN8VLt7zCSBcR7azS0Bt/Ag8JuJkm7y4DIbtoKThbVX8F3bF+oB8 ZdFw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:from:to:cc:subject:date:message-id:mime-version :content-transfer-encoding; bh=+fjtvBI18+4dOm0uYdGwPyts2yAmhCRRn5DGw8hysxY=; b=WaLdOH2aGsfwfOZgoEgWdMXwYc0cHH2Lx0Dy+6UhY7RMPAip+/N4Koe/ARlN1qlE62 MdTsBOjF7hIwgZyiEGcSccfTbmRQt+34VZLWDi/viP7gusW44mYxekjtmwH1L1ms3XPH 1C8wZ/GE7GRdlweWeAhb3agYF5PNTFZhoLZGiKwJ5XqqPjQkcBdSPYfECOgPtrvK9u1a IjXUvxUZNPtNcCrWDdrlEREOEUYnuLOqVqwiCieZCjrMAMZapIjQuQRa/TR18X5QVZ7s oyI9DE7/ZFsqMQBiug8UM883bXR7HXfanPRxox3zF040YPHGfIE47LFroFdDiLkkm/BO j6cA== X-Gm-Message-State: APjAAAWF+fzTpqAXebYH/z0UKpaAsjwgAaz0Bk6nt/jIbv8kqN3dNnh1 MjtEzuxjm0+UM2TRn0+SuQV0paqMhTcXFQ== X-Received: by 2002:a17:902:243:: with SMTP id 61mr30834953plc.132.1558346332842; Mon, 20 May 2019 02:58:52 -0700 (PDT) Received: from localhost.localdomain (112.237.225.49.dyn.cust.vf.net.nz. [49.225.237.112]) by smtp.gmail.com with ESMTPSA id o7sm25129376pfp.168.2019.05.20.02.58.49 (version=TLS1_2 cipher=ECDHE-RSA-CHACHA20-POLY1305 bits=256/256); Mon, 20 May 2019 02:58:52 -0700 (PDT) From: Murray McAllister Cc: murray.mcallister@gmail.com, VMware Graphics , Thomas Hellstrom , David Airlie , Daniel Vetter , dri-devel@lists.freedesktop.org, linux-kernel@vger.kernel.org Subject: [PATCH] drm/vmwgfx: integer underflow in vmw_cmd_dx_set_shader() leading to an invalid read Date: Mon, 20 May 2019 21:57:34 +1200 Message-Id: <20190520095734.4655-1-murray.mcallister@gmail.com> X-Mailer: git-send-email 2.20.1 MIME-Version: 1.0 Content-Transfer-Encoding: 8bit To: unlisted-recipients:; (no To-header on input) Sender: linux-kernel-owner@vger.kernel.org Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org If SVGA_3D_CMD_DX_SET_SHADER is called with a shader ID of SVGA3D_INVALID_ID, and a shader type of SVGA3D_SHADERTYPE_INVALID, the calculated binding.shader_slot will be 4294967295, leading to an out-of-bounds read in vmw_binding_loc() when the offset is calculated. Signed-off-by: Murray McAllister --- drivers/gpu/drm/vmwgfx/vmwgfx_execbuf.c | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/drivers/gpu/drm/vmwgfx/vmwgfx_execbuf.c b/drivers/gpu/drm/vmwgfx/vmwgfx_execbuf.c index 2ff7ba04d8c8..9aeb5448cfc1 100644 --- a/drivers/gpu/drm/vmwgfx/vmwgfx_execbuf.c +++ b/drivers/gpu/drm/vmwgfx/vmwgfx_execbuf.c @@ -2193,7 +2193,8 @@ static int vmw_cmd_dx_set_shader(struct vmw_private *dev_priv, cmd = container_of(header, typeof(*cmd), header); - if (cmd->body.type >= SVGA3D_SHADERTYPE_DX10_MAX) { + if (cmd->body.type >= SVGA3D_SHADERTYPE_DX10_MAX || + cmd->body.type < SVGA3D_SHADERTYPE_MIN) { VMW_DEBUG_USER("Illegal shader type %u.\n", (unsigned int) cmd->body.type); return -EINVAL; -- 2.20.1