From nobody Tue Sep 29 10:32:13 2026 Received: from mail-pl1-f180.google.com (mail-pl1-f180.google.com [209.85.214.180]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 1FBFC233D9E for ; Sun, 9 Aug 2026 00:26:42 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.214.180 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786235204; cv=none; b=vFvd48rtqR1A7yYibbkMRTjuzA/xi/RdrQ7Mw5JngGuly4lXykYGc1z9MGUgCH0cAzvFoW9a63/XRqF4pbn8DbWbklbDh35/1QcPxZJMzMtc7JM4n68G0Ju736kJIa25yHTRUOW/mmf1RH3tLuzpedPVn9tAOUrxaNc9s4CQ51U= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786235204; c=relaxed/simple; bh=cD6iwbu7Yz4gJgFpHxHHjHRe6DiqimV0yMAD6yEPlqE=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=sXW11mObp+mc6NvMWm7/I43vjgFmhbCfD/+PS211Y2TDpJfWi2o+23sDFcQ2YRftZgaTXxwZSj4UQsZl1+MwZxbxh1a4pJRkxzgSn/oOable7ZIci3hY3BXhRLhTDa1Ic6qKcasgpOY90w9EcRpH2kUTnbqdcQzmt/QwroUm5F4= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=gPSUR1qT; arc=none smtp.client-ip=209.85.214.180 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="gPSUR1qT" Received: by mail-pl1-f180.google.com with SMTP id d9443c01a7336-2d0407aedd6so8059825ad.0 for ; Sat, 08 Aug 2026 17:26:42 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1786235202; x=1786840002; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to:content-type; bh=EgyjptlT6DdPuhzR18wm1dZCjjUWW4FZP2FThtl49rY=; b=gPSUR1qTOWUqPvIxzeNtT3Rx83lax5hgwQy9+JNgwD+RujRGN8kVSaUDIreo0YB8dV VGaeIUumsMm/C7f/BU9xIeB37Qt1C3Edh1FnWu+iR92GVBaR+Aiu6Og2XWJE25STwrpP dXKBtHO252bvA/Xy55q1z3EG6SZ/151X7cQVTYgI7Zig+wc4D15p1Vww77Wvo4mfcAO+ s6ddLBAE8CPVO6ljnyP67WdiQMVLt/iC49lD1BWddGgv5ctv0jvKJt6DOgurODmGIel+ +fbGE+STGzwKTUv9wOY3HoGkH7hPCUeCIyY8S61tlxf5ACDi2awBgVzH6a39WjffAS5n AxkQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1786235202; x=1786840002; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=EgyjptlT6DdPuhzR18wm1dZCjjUWW4FZP2FThtl49rY=; b=HJ/myyK2esxEOmVtlFVmz1cvyN19CHFoaEHigVQF+Uj2S10wqVnoFVCxpVYJ42Lvcp aQTYVFc/gLldeXGYlDlyLg6mYDFtsjrrncKLD2R9K8C8GVRGtCSdQsa6FlDVP1m6nmKP NRADdL/qBf2DBf8klU+vpYmEUnFlkYa+Eny1ux7CXcRjCH7bVSzNSjsFY4f30IdMzdFe r3rMSVk3SLWDQ0R27JcktqSy2e20D40yS+C/ryp665xb2zUS+n+ONsyQj/0U7Ls3sGPB KQrZFa0mp6dK1SDoEY2OPA93xq6Fp3xAaDdSclk/dKqXc98bTVX4bXiqhe9DvR/scxRb bIoA== X-Forwarded-Encrypted: i=1; AHgh+RrEhanYJNqybMyPxy4jgfpQ1xQ164nm8RhPgc+cpB5GDYznp2ATAngXxtMnHUKebz+HCdE8Nr/KWU101YA=@vger.kernel.org X-Gm-Message-State: AOJu0YxbKV+YPSyq80kMfjMrhZx+tPBn+194lcYEsLzERELnc7DxQ9Fy qCDRO9geO8smXdiFUKec0KALdgF3CwrYQKDoKixeEeG2OjbUgSNJRF59 X-Gm-Gg: AR+sD11qXulxgnJC6UmmTVOHpRhVCcrhGpvRA/Z4+GlyIDoRm2dJ2kcAlinNYDfM+n9 MVtmZ24EJPwm86IqhS3/FwtyBD6XidUQSEC3NYnDSYQ/K2nxxDc2+14JfAzI+RYDY+cxX2O+m6K mfI0gjpJq7ieHqTvkHxWIxJ25p2bHPwXUFkUMMGYRCm+ZIZIgTUSqOwMgFmyjpcO+TMpXo0zxG3 y5hSLgECPF7PipZnxR6eH1gU5MXrjy5EVMIGoeVCxgaUXTWtl3+A+p8PWzqZfH1VxtchyvNVkyX bNvJHX6enOALlyAdD9Dh16qMhGWpYhLQuIA5TaAAcGTZH7YGsXOIEDwBFbMX+AouuMCoCE33kgw iEZ5h6DWo8jbhT8S22GgsrNoHo9shI3sl8uiKnIFZby3rA+AseaRdZIGsozaOBOyD6kx8OX838S sT4oKjcMtqO+ThyKaruK0/om9rfkDBG8f7XoGNCPjebHkEh4vZhD96f5KCXOz1Pxg= X-Received: by 2002:a17:90b:1843:b0:37f:bfa2:1887 with SMTP id 98e67ed59e1d1-3903c53639amr35887499a91.8.1786235202259; Sat, 08 Aug 2026 17:26:42 -0700 (PDT) Received: from beelink.. ([186.22.57.86]) by smtp.gmail.com with ESMTPSA id 5a478bee46e88-315beb8844fsm25270201eec.16.2026.08.08.17.26.38 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sat, 08 Aug 2026 17:26:41 -0700 (PDT) From: Aldo Ariel Panzardo To: Dave Airlie , Gerd Hoffmann Cc: Maarten Lankhorst , Maxime Ripard , Thomas Zimmermann , David Airlie , Simona Vetter , virtualization@lists.linux.dev, spice-devel@lists.freedesktop.org, dri-devel@lists.freedesktop.org, linux-kernel@vger.kernel.org, Aldo Ariel Panzardo Subject: [PATCH v2] drm/qxl: fix 32-bit overflow in the ALLOC_SURF size computation Date: Sat, 8 Aug 2026 21:26:21 -0300 Message-ID: <20260809002621.122832-1-qwe.aldo@gmail.com> X-Mailer: git-send-email 2.43.0 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" qxl_alloc_surf_ioctl() works out the backing size of a surface with actual_stride =3D param->stride < 0 ? -param->stride : param->stride; size =3D actual_stride * param->height + actual_stride; where size and actual_stride are int and param->height is __u32. Every operand comes straight from userspace through DRM_IOCTL_QXL_ALLOC_SURF, which is DRM_AUTH, and the expression is evaluated modulo 2^32 with no overflow check. The wrapped value is what reaches qxl_bo_create(), which only rounds it up to a page. The original width, height and stride are kept verbatim in bo->surf and are later handed to the device by qxl_hw_surface_alloc() together with the address of that undersized allocation, so the driver tells the host about a surface far larger than the memory backing it. For example stride=3D4096, height=3D1048576 gives 4096 * (1048576 + 1) =3D 0x1_0000_1000, which truncates to 4096: a one-page buffer object described to the device as a 4 GiB surface. Measured on 6.12.101 by probing mmap() lengths against the resulting GEM object, the backing is 4096 bytes while the surface declared to the device is 4294967296 bytes. Two smaller problems are fixed at the same time. Negating param->stride is undefined for INT_MIN, and unlike QXL_ALLOC there is no rejection of a zero-sized request. Compute the size in u64, which cannot wrap for the u32 inputs, reject INT_MIN and zero dimensions, and bound the result so it still fits the int parameter of qxl_gem_object_create(). Fixes: f64122c1f6ad ("drm: add new QXL driver. (v1.4)") Cc: stable@vger.kernel.org Signed-off-by: Aldo Ariel Panzardo --- v2: compute the size in u64 instead of size_t, so the (height + 1) addition cannot wrap on 32-bit either (reported by Sashiko AI review); the v1 include is no longer needed. drivers/gpu/drm/qxl/qxl_ioctl.c | 16 ++++++++++++++-- 1 file changed, 14 insertions(+), 2 deletions(-) diff --git a/drivers/gpu/drm/qxl/qxl_ioctl.c b/drivers/gpu/drm/qxl/qxl_ioct= l.c index cd1901d5c7c0..75abfc1db0f5 100644 --- a/drivers/gpu/drm/qxl/qxl_ioctl.c +++ b/drivers/gpu/drm/qxl/qxl_ioctl.c @@ -385,12 +385,24 @@ int qxl_alloc_surf_ioctl(struct drm_device *dev, void= *data, struct drm_file *fi struct drm_qxl_alloc_surf *param =3D data; int handle; int ret; - int size, actual_stride; + int actual_stride; + u64 size; struct qxl_surface surf; =20 /* work out size allocate bo with handle */ + if (param->stride =3D=3D INT_MIN) + return -EINVAL; actual_stride =3D param->stride < 0 ? -param->stride : param->stride; - size =3D actual_stride * param->height + actual_stride; + if (!actual_stride || !param->width || !param->height) + return -EINVAL; + /* + * size =3D actual_stride * (height + 1), computed in u64 so it cannot + * wrap on any architecture, then bounded so it still fits the int + * parameter of qxl_gem_object_create(). + */ + size =3D (u64)actual_stride * ((u64)param->height + 1); + if (size > INT_MAX) + return -EINVAL; =20 surf.format =3D param->format; surf.width =3D param->width; --=20 2.43.0