From nobody Tue Sep 29 10:31:58 2026 Received: from mail-pl1-f180.google.com (mail-pl1-f180.google.com [209.85.214.180]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 681C32EBB8D for ; Sat, 8 Aug 2026 23:10:02 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.214.180 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786230604; cv=none; b=Mzyo+E0Cei9QoQfHgpS0ZUPSUmYogyb9uCxwW0yRoMxYhagluwkhqvNENBqT1wokJ9jLLwNArfa2qAQ3frIa3+3gCajB+cNMSmgI29AGqHGH4cO/q2Ka0AoFKCdRUloI+CNuaFYmCZw4B9ynEC7cvXEZjnuOBeHIG+6/6WqRuxc= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786230604; c=relaxed/simple; bh=veI2S5AkKBecHOHYnAhkOXWI5HAFW6XLJIyvcYMukME=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=aL9H6T2AkJkzB4/qIFA/ZGULiBKORcko4m5oDidHdRccT6tz4u6OVm7Mi8pSG+1VdCLbqqK70eo63toP8R/oOYrenm/o+QfJuhkn1ZXoC/pBQl/omVFqzd+KSsZ71TeeAUXbpzPA7IHoFpSaKrmMKlVOSqbnq2/Aj0uh9TdkNsI= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=aE+/wO6R; arc=none smtp.client-ip=209.85.214.180 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="aE+/wO6R" Received: by mail-pl1-f180.google.com with SMTP id d9443c01a7336-2d049069377so5940865ad.0 for ; Sat, 08 Aug 2026 16:10:02 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1786230602; x=1786835402; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to:content-type; bh=rH2W1wopjxMu7bNPTu3XbUp0wkIuNWweLs/V8E2Ud3Y=; b=aE+/wO6RwgFQSPawoy+dFollE3MEZADeTxxAUq2J0hs3gpD4fj7R4iz9CIAwsd1bIn jGHCNJ6G33ckAHd1oMUWiplcY/9y0o/hPL7rm/yapGEp19joSceseq5vLW9nQZM2IaUS Fzxt9IeIiEDqSOec5bYDorxLIFPXAS2EMNa5m4vLZWNe+Upq47LmxtDqpb153iLEyMdQ uq/VMuMJhkhNibIjKNcMHJmu/RB/JEbnWXahe3R7x0ydcfU92l3xDWm2FX/TrSv7wzyx x0OOIDZsXLgyGW5bbHiDuXdQYDAq4mW6topJLsykSf0jmTLEw1DD9q2pqwfaM8Sq7mDY L8LQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1786230602; x=1786835402; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=rH2W1wopjxMu7bNPTu3XbUp0wkIuNWweLs/V8E2Ud3Y=; b=h/KQz+mAMbgasPaE1B9+9dEmTjYWbETG8F21UDn12eKM/yGnINgHc+0TIaFJUdfzth Lu2w8xAv/AlpsB4gVcr94K/HzztIrqW6qlTgJ7fw30ZCC640/WLjI1LPieTIWe3Wf51v 4gztp1o8CScb9VrAKkcJ805/tcJZVu1u7qt6eg9V5ZfrpnrdFsrVbe0J7n1/igs1GmFW 11vEdorqtxvQ5nBZmCPhTgfieb0Ya4fZJnRZ42vbWAamrMF9fxQPOn5KEOYTRRQ7tW7K bpxS90zZoZInoyw+xQJZsXb324qs9VqmfQOPXZVn2fvaUgruD9/Kwlb8W1tS4NlHtf7S /RgQ== X-Forwarded-Encrypted: i=1; AHgh+RqabOwldgaCzan9WUtKqWCX0ZYHYR1rGP3p/96KuazGDkQyvb7E9anf1GOeMI/Ab3+2r+VzjSNLEwUt160=@vger.kernel.org X-Gm-Message-State: AOJu0YxL4gfF9pRCNTjjlrwaNVHxtfkSDnkDnjAUf+Tcj73MQlGCv6lX qstbuCAB0BVl3yphTEKECxPl2zjS2Qas/pG8+wrFXbvGF0sCWA0AC05r X-Gm-Gg: AR+sD13pC3jEtMBGq/sGze/Q0yaLA9MVMRkAZFX9pYq1lV5WxcvU5Yc8Iptx4K+tnWU pBy2GLGukDXk8FSf6PdqwdFLBxS08X7kdWryqAc+Z7K5pYMfZs7P2KQ0LGAN/te4ZKuG2olFwP3 ShAVo1chudY3heTm/xQc8jVkkXtDpW792HV6x8N+D3SZ+9Tt5khIGp34bLQxoxCnwJG3VAGN3gR XMSBvtlggjfpiCHXCvLj4E5kYIfSuyFohRqTX3vB3EG6HRMbOEiWqIe6Sx9Cpgux38zHf2H9YRF h5jEVNqD3rSyPCwddkYmDtSxF0+ovgKd3lVw9Ze0aI96dwR1D3fi5Sb9+Re9x8IngS+koNupWNw YkZJF4AS/ND19mWEhcVavQaHLw/jF6iQPIalZJhxtq7xm8rQ7XNygh/NoSwF+vO9l+88aqq049Z 30R4h2kYz9RF311/RZlI3oUzXS5TK5v8OkCIcHwYXsjPJZnkSzsQCT X-Received: by 2002:a05:6a20:9c17:b0:3c4:397a:69b0 with SMTP id adf61e73a8af0-3cbadc17561mr24004662637.21.1786230602271; Sat, 08 Aug 2026 16:10:02 -0700 (PDT) Received: from beelink.. ([186.22.57.86]) by smtp.gmail.com with ESMTPSA id 5a478bee46e88-315bec26a5dsm23319791eec.26.2026.08.08.16.09.59 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sat, 08 Aug 2026 16:10:01 -0700 (PDT) From: Aldo Ariel Panzardo To: Dave Airlie , Gerd Hoffmann Cc: Maarten Lankhorst , Maxime Ripard , Thomas Zimmermann , David Airlie , Simona Vetter , virtualization@lists.linux.dev, spice-devel@lists.freedesktop.org, dri-devel@lists.freedesktop.org, linux-kernel@vger.kernel.org, Aldo Ariel Panzardo Subject: [PATCH] drm/qxl: fix 32-bit overflow in the ALLOC_SURF size computation Date: Sat, 8 Aug 2026 20:09:45 -0300 Message-ID: <20260808230945.67525-1-qwe.aldo@gmail.com> X-Mailer: git-send-email 2.43.0 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" qxl_alloc_surf_ioctl() works out the backing size of a surface with actual_stride =3D param->stride < 0 ? -param->stride : param->stride; size =3D actual_stride * param->height + actual_stride; where size and actual_stride are int and param->height is __u32. Every operand comes straight from userspace through DRM_IOCTL_QXL_ALLOC_SURF, which is DRM_AUTH, and the expression is evaluated modulo 2^32 with no overflow check. The wrapped value is what reaches qxl_bo_create(), which only rounds it up to a page. The original width, height and stride are kept verbatim in bo->surf and are later handed to the device by qxl_hw_surface_alloc() together with the address of that undersized allocation, so the driver tells the host about a surface far larger than the memory backing it. For example stride=3D4096, height=3D1048576 gives 4096 * (1048576 + 1) =3D 0x1_0000_1000, which truncates to 4096: a one-page buffer object described to the device as a 4 GiB surface. Measured on 6.12.101 by probing mmap() lengths against the resulting GEM object, the backing is 4096 bytes while the surface declared to the device is 4294967296 bytes. Two smaller problems are fixed at the same time. Negating param->stride is undefined for INT_MIN, and unlike QXL_ALLOC there is no rejection of a zero-sized request. Compute the size in a type that cannot wrap, reject INT_MIN and zero dimensions, and bound the result so it still fits the int parameter of qxl_gem_object_create(). Fixes: f64122c1f6ad ("drm: add new QXL driver. (v1.4)") Cc: stable@vger.kernel.org Signed-off-by: Aldo Ariel Panzardo --- drivers/gpu/drm/qxl/qxl_ioctl.c | 19 +++++++++++++++++-- 1 file changed, 17 insertions(+), 2 deletions(-) diff --git a/drivers/gpu/drm/qxl/qxl_ioctl.c b/drivers/gpu/drm/qxl/qxl_ioct= l.c --- a/drivers/gpu/drm/qxl/qxl_ioctl.c +++ b/drivers/gpu/drm/qxl/qxl_ioctl.c @@ -23,6 +23,7 @@ * Alon Levy */ =20 +#include #include #include =20 @@ -386,12 +387,26 @@ struct drm_qxl_alloc_surf *param =3D data; int handle; int ret; - int size, actual_stride; + int actual_stride; + size_t size; struct qxl_surface surf; =20 /* work out size allocate bo with handle */ + if (param->stride =3D=3D INT_MIN) + return -EINVAL; actual_stride =3D param->stride < 0 ? -param->stride : param->stride; - size =3D actual_stride * param->height + actual_stride; + if (!actual_stride || !param->width || !param->height) + return -EINVAL; + /* + * size =3D actual_stride * (height + 1), evaluated in a type that cannot + * wrap, then bounded so it survives the int parameter of + * qxl_gem_object_create(). + */ + if (check_mul_overflow((size_t)actual_stride, + (size_t)param->height + 1, &size)) + return -EINVAL; + if (size > INT_MAX) + return -EINVAL; =20 surf.format =3D param->format; surf.width =3D param->width;