From nobody Mon Feb 9 07:11:26 2026 Received: from mail-qk1-f170.google.com (mail-qk1-f170.google.com [209.85.222.170]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id BEAB5946A for ; Sun, 8 Feb 2026 00:02:58 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.222.170 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1770508979; cv=none; b=X1lRlrI4qUS+6q9cCy48lBzCbjq1xFIZ6S9kynn6/IlzrFDSHQxslL/gJUus6owgppZEt47WfllUWFj4urADkZrdls++oxu6zW76evkReBk/pzLeOvAYgHlTCjYLYZxTzovY5GfcPsqot+RVRR3HJblN5QITrKxHBW2lUI8a02M= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1770508979; c=relaxed/simple; bh=3HlwgSXIWUCKuNUwBIeUsuoI/lv7KnEcp3YoxhBwj10=; h=From:To:Cc:Subject:Date:Message-Id:MIME-Version; b=KOE3au6lz5bd0SJCMEBOPA9XODsBsmaujbLiv00/pVverKU4OTlYz5gle862bUx+m7wyP3uY0/Y4bRQG8O753PYJOBUkEIUs/t9NZt2oJsI+/2jv0ELAJD8IoFd+Rb68WA6QkOSeBseehXbb2zoIUMAcMXyXd5bE0pPybE/zQSE= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=u.northwestern.edu; spf=pass smtp.mailfrom=u.northwestern.edu; dkim=pass (2048-bit key) header.d=u-northwestern-edu.20230601.gappssmtp.com header.i=@u-northwestern-edu.20230601.gappssmtp.com header.b=luzqEDqI; arc=none smtp.client-ip=209.85.222.170 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=u.northwestern.edu Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=u.northwestern.edu Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=u-northwestern-edu.20230601.gappssmtp.com header.i=@u-northwestern-edu.20230601.gappssmtp.com header.b="luzqEDqI" Received: by mail-qk1-f170.google.com with SMTP id af79cd13be357-8c9eedc2363so341543285a.1 for ; Sat, 07 Feb 2026 16:02:58 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=u-northwestern-edu.20230601.gappssmtp.com; s=20230601; t=1770508977; x=1771113777; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to; bh=/ixKYwI8fU81gZ+QKkq1WjH9E+1EyNt8hakHtj7h1q4=; b=luzqEDqIVraT8ZIT6Rpk4vqwIbt4mVF6RvWQotgVl96PAPiTPV0B6EqN2U+Q+ZRg97 R2i5PT9aOhgCVEYDcDF2cFU4pmJMHr639JPr8SLSPCHyVpFv1SYYkOI+RuL57vqdB0kh lebmZAWqOr+jWQzGb0vq2JDS7HlZt8fR1HptRelBQDLiqcq6vR3mAAQi1Ale9nyAj065 4aXNzSvahfzqFsZ9rk8uUWpEeFfLuu+umE6smXBBVVLcfQVQT7/FtjtmhB+gxAQcp0IK GxulwpdRDzfAcHsVGtCo+tv3w5Qmc+37JLmO4Bn7PObjgmQGvccKr/yYPnqy/BXVUbVb +FQA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1770508977; x=1771113777; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to; bh=/ixKYwI8fU81gZ+QKkq1WjH9E+1EyNt8hakHtj7h1q4=; b=pGZ5/Q/kUooAI6PyRigb+sYTCLiyyykwfeu0WVqkfbZtPwOVxxdQ9E35XPVqJ8MjP1 LoT/jMAQ1Z7Exr3ctTEdIbSb6KL9kbfted/qoWQIcp8p9YrWszVnqyVy34VstHGrYASS dd+u/2tmmIEGd3E9mDZFmO0uBoOJ1EEbYSbf4rQPPWgmb/Pd2dwMErOdFlll+K947NZD yuvPxJFKEJatWoqEs9QcYFPHS7Mip7o2Qm/pPJhQeE2dOAIZAz3rJd0OmzPFk9f3pW2A FVt25Gc1H5EXcDWhj8SqXl0SNrkJhuNJg2zmsUnFjPaSSPkCsJtEbwmY7ft3CnMt+DH8 Dh9A== X-Forwarded-Encrypted: i=1; AJvYcCU7eNVhHc3Q1b9HNCVqnM+FQIDH/AvstR8tT4JjF2pWwWF3O0HCP9ijQQjytEHq1jptbLBnns28sQZ4Udc=@vger.kernel.org X-Gm-Message-State: AOJu0YzMCbWBktbyg++N6VxoCMXnrD917KDk5bqanw1RY3A94SyJxQT3 kv+dK35MkKenaEzYWpJMTov9NmP3qjktErP452+PXz5vY7TygKFZds1c7MtQKd8w8Bc= X-Gm-Gg: AZuq6aJTu/KrDbNUNSoMds8JbCLw53q2T3WwnlvlyZiLlG4f/D98kmWAEolNNhylyqm 8j4y9O5W0UAcXHd+uErioSArZVSM0cJn4VunvtfpF6v0+gCJxsk5/xtfVrkUBADKOZ9dJuS/aUR qysEkFT0ZPBUNZYUFT5k8oujuUzn+B+lnWTzFqtryj1UMdhDeFONuA3qj698dbUjkILBRuL+PhJ rmC6TVUjNVVXWb4tUDSg5B7XVqLkOUKEUyQGeFSlh1gUwQnKXjAHCyi/zdEEhLXPlPoTajREjnt IDkBruh8Z4qiBREQv3u24ajPrchaVCSGsGToduOwrLesb+S9FJVIvAjW9gdMhycFtXUatgXj51m k1rF6NKrvYajWu9PwjXwYF6p8a0vufyxbBperNrk9BagEDPBy3NZVFMdM83o388a0oNHXiAYFa4 3MC6/ZN+j9fbfYwAggYkthmqRhdcOslWmjlK/lGHwpd499wqPqvNAVtU7EblxUc/Q+nTHdSiHBK tgPXkkh0nNRt08iFAERoQdK48I6+R4= X-Received: by 2002:a05:620a:4485:b0:8c6:a5bb:f464 with SMTP id af79cd13be357-8caf17e3e69mr972256985a.66.1770508977586; Sat, 07 Feb 2026 16:02:57 -0800 (PST) Received: from security.cs.northwestern.edu (security.cs.northwestern.edu. [165.124.184.136]) by smtp.gmail.com with ESMTPSA id 6a1803df08f44-89546b09f77sm30968746d6.31.2026.02.07.16.02.56 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sat, 07 Feb 2026 16:02:57 -0800 (PST) From: Ziyi Guo To: Alex Deucher , =?UTF-8?q?Christian=20K=C3=B6nig?= Cc: David Airlie , Simona Vetter , amd-gfx@lists.freedesktop.org, dri-devel@lists.freedesktop.org, linux-kernel@vger.kernel.org, Ziyi Guo Subject: [PATCH] drm/amdgpu: check num_entries in GEM_OP GET_MAPPING_INFO Date: Sun, 8 Feb 2026 00:02:55 +0000 Message-Id: <20260208000255.4073363-1-n7l8m4@u.northwestern.edu> X-Mailer: git-send-email 2.34.1 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" kvcalloc(args->num_entries, sizeof(*vm_entries), GFP_KERNEL) at amdgpu_gem.c:1050 uses the user-supplied num_entries directly without any upper bounds check. Since num_entries is a __u32 and sizeof(drm_amdgpu_gem_vm_entry) is 32 bytes, a large num_entries produces an allocation exceeding INT_MAX, triggering WARNING in __kvmalloc_node_noprof(), causing a kernel WARNING, TAINT_WARN, and panic on CONFIG_PANIC_ON_WARN=3Dy systems. Add a size bounds check before we invoke the kvzalloc() to reject oversized num_entries early with -EINVAL. Fixes: 4d82724f7f2b ("drm/amdgpu: Add mapping info option for GEM_OP ioctl") Signed-off-by: Ziyi Guo --- drivers/gpu/drm/amd/amdgpu/amdgpu_gem.c | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/drivers/gpu/drm/amd/amdgpu/amdgpu_gem.c b/drivers/gpu/drm/amd/= amdgpu/amdgpu_gem.c index 3e38c5db2987..ef5d8bd216b2 100644 --- a/drivers/gpu/drm/amd/amdgpu/amdgpu_gem.c +++ b/drivers/gpu/drm/amd/amdgpu/amdgpu_gem.c @@ -1047,6 +1047,11 @@ int amdgpu_gem_op_ioctl(struct drm_device *dev, void= *data, * If that number is larger than the size of the array, the ioctl must * be retried. */ + if (args->num_entries > INT_MAX / sizeof(*vm_entries)) { + r =3D -EINVAL; + goto out_exec; + } + vm_entries =3D kvcalloc(args->num_entries, sizeof(*vm_entries), GFP_KERN= EL); if (!vm_entries) return -ENOMEM; --=20 2.34.1