From nobody Tue Sep 29 09:46:27 2026 Received: from mail-pl1-f175.google.com (mail-pl1-f175.google.com [209.85.214.175]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id AA1A228CF5D for ; Sun, 9 Aug 2026 13:25:43 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.214.175 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786281944; cv=none; b=IsW7vmi8quV6IwC3aqnXu+NtHF6Uajcgv0XkqXWUu/X4vFwmimoLepP7Q5F5P5CkHzDwd7WfNsY+Cdp9VtlLSWuSPK3IvLpRozVZnTmGpqle1peuFqlwa/7E0wjLkNDe3unMcpzhoqpYMDHKOBZ7V5HrafvFUAU/26jrQbgcnvM= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786281944; c=relaxed/simple; bh=+Q9X8t7fMSDBCFFpc/4f3mweWsXWLmjgKSxL3Jr7Exg=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=S5o1avYZ1omp2Q2gguKrEq1+P5/OMiEhp80b7yFomOK/j3gQBzbs/sk9eVojgTOptv9P0FBnZaTWMYt85hczh2ZefV6hDb/xKL+xLK3f2colKevnYE2K7ajkj9GEv6k4tAXAdoBd1eiYlGmClQ0Vdr/JlPOcNyv8Yx3uowUTbyw= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=sdrbqtDj; arc=none smtp.client-ip=209.85.214.175 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="sdrbqtDj" Received: by mail-pl1-f175.google.com with SMTP id d9443c01a7336-2cace91f112so9878105ad.0 for ; Sun, 09 Aug 2026 06:25:43 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1786281943; x=1786886743; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to:content-type; bh=kfmNB6Xrai7eTejryQxi97VAY3eGViiWgp3/xoXdPsU=; b=sdrbqtDj1nCcWYP3YYAnqiViTCgvS5G0jkMGnWecE+MjXHJYZe113+u04S9lD3fMz7 q120KxnNpCmrVz/63unzfzoEuw6ednmb63/syAsUZCqtoF2y0y66QhchJEN72BXX/4/A MZGhcwzYvmrwq0YiOHJaVYcY6HJyvU46IGfiXxYC2GscVn3k1lSlPWJ3CK5mEL5HOkcq C1od+w6oxZPjnUy0NCxC2PfnUYep7f9c5llbaT/3A3l6H8LP1kLxfY2sPO4A9yTiqOyT 6Kh38kwgTrUdotzb3BcZN/DXXuNef+4WphtAvF4CXgu6TD3XPVjFU1f9Eko00gZhTbPG TCow== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1786281943; x=1786886743; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=kfmNB6Xrai7eTejryQxi97VAY3eGViiWgp3/xoXdPsU=; b=DHZHsPbjOvg6Zl9Z6KZJ+d0CkHZE714acoRh8QbQ1fDql30guciBP8EAlZ/WY4TWH2 A8iEO5GZlRvxfSSvHk738yi6fGYdRDyx3KPFbCPY+UTaQ7gWtfKfiz/7QVQDlcGPOugj 2pzVBqoCDAme0jloo6y6RyReeHiMeF2h+OcqInXiwQtW3d7UiVuljQrpzKlDurXa9vVG ilN1ZwG7KI54B01MbMoQa+MSOe5afc6Cios3X3CGOSO6KhWj4y63qSV8v+muvJGvzHF3 BmnMrfWYluxyxTK/645bONnqMHk0e5JF9XVtwZrINCiAVJOXcO6Feoo+qZ+Wd0+KOgit q4Sg== X-Forwarded-Encrypted: i=1; AHgh+Rp+lCdguWMoEZxWKibh9oNPbgYDd+yz/sUEkrDK4nsyKu6hVEWL+CVzmpmNFiQ12lzK1bZgvo8zSBBCRKg=@vger.kernel.org X-Gm-Message-State: AOJu0YyZKwqHtHIFhuT3GdF1bE5Dv0qG/57KY0z4L7jWgAl8NKw/ZcqM uhB/ZcMNXNoA2vqMMqrVoXaMpkTj52CnlSTtPvN0zE3w/D9sCEhIJqOQ X-Gm-Gg: AR+sD125SmKrmrUI+RANv2G1bqmTi7yMPa5IT6oGOvyYYrFRh3TE1AYb3SgXE5PNmGM V8jSkq24+0Mfc6p8j2JtnAY73Jl3E+QiPihq3J8NUrRkCS8QUwahIn7G5clH2ENtvEdrbBHVXJr e4jaRiTbn6+6Gd1UWUjGEkkYaR3aGH9NC9OpNuFEzX3sxJbNZOsk5ihLp9+1bDnslgHfmQ/rwUc XGyNqbWG+DY1GCCIwA4/Gp1/jKmwHlNQ9yegYiUThQkgTAo6HvCYTPnSOSYEJob//7Drkw2Znqt k02TI3gGPWdo2uoxljmyR8gl826YSs9WoflbAifJXSW3CLcQh28PUOheDVnrHJT+fDDNBddBEPB KPHiCgHdP50BH6qauJluSgj6Oqa1CuZKWnK9h/A8C1GnqkrAL8ak8tCHWvhKFiiB1v0k3L7YaQy RQK1M7pW8uewZCnXLaByDTJRYya3vCklTZHXme7R8RsAVsnzh+d8x5 X-Received: by 2002:a05:6a20:a114:b0:3c3:7cfe:b337 with SMTP id adf61e73a8af0-3cb85f88bf2mr37654661637.30.1786281942902; Sun, 09 Aug 2026 06:25:42 -0700 (PDT) Received: from beelink.. ([186.22.57.86]) by smtp.gmail.com with ESMTPSA id 5a478bee46e88-315be86fc7bsm31512690eec.1.2026.08.09.06.25.39 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 09 Aug 2026 06:25:41 -0700 (PDT) From: Aldo Ariel Panzardo To: Zack Rusin Cc: Broadcom internal kernel review list , Maarten Lankhorst , Maxime Ripard , Thomas Zimmermann , David Airlie , Simona Vetter , dri-devel@lists.freedesktop.org, linux-kernel@vger.kernel.org, Aldo Ariel Panzardo Subject: [PATCH] drm/vmwgfx: reject SURFACE_DMA commands smaller than body + suffix Date: Sun, 9 Aug 2026 10:25:14 -0300 Message-ID: <20260809132514.421679-1-qwe.aldo@gmail.com> X-Mailer: git-send-email 2.43.0 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" vmw_cmd_dma() locates the SVGA3dCmdSurfaceDMASuffix at the end of the command and dereferences it: suffix =3D (SVGA3dCmdSurfaceDMASuffix *)((unsigned long) &cmd->body + header->size - sizeof(*suffix)); if (unlikely(suffix->suffixSize !=3D sizeof(*suffix))) { header->size comes straight from userspace through DRM_IOCTL_VMW_EXECBUF (DRM_RENDER_ALLOW) and is only bounded from above: vmw_cmd_check() rejects header->size > SVGA_CMD_MAX_DATASIZE and commands that do not fit the buffer, and struct vmw_cmd_entry carries no per-command minimum size. There is no lower bound. When header->size is smaller than sizeof(*suffix) the pointer arithmetic underflows and the read of suffix->suffixSize is an out-of-bounds read ahead of the command; when it is smaller than the body plus the suffix, the body accesses that follow are out of bounds as well. Reject the command before computing the suffix pointer when header->size cannot hold both the fixed body and the trailing suffix. Found by a syzkaller instance fuzzing the vmwgfx command stream: BUG: KASAN: vmalloc-out-of-bounds in vmw_cmd_dma+0x508/0x5b0 Read of size 4 ... vmw_cmd_dma+0x508/0x5b0 drivers/gpu/drm/vmwgfx/vmwgfx_execbuf.c vmw_execbuf_process+0xd06/0x35f0 vmw_execbuf_ioctl+0x1cc/0x5a0 Fixes: cbd75e97a525 ("drm/vmwgfx: Make sure user-space can't DMA across buf= fer object boundaries v2") Cc: stable@vger.kernel.org Signed-off-by: Aldo Ariel Panzardo --- drivers/gpu/drm/vmwgfx/vmwgfx_execbuf.c | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/drivers/gpu/drm/vmwgfx/vmwgfx_execbuf.c b/drivers/gpu/drm/vmwg= fx/vmwgfx_execbuf.c index 6b921db2dcd2..02eb383f91b5 100644 --- a/drivers/gpu/drm/vmwgfx/vmwgfx_execbuf.c +++ b/drivers/gpu/drm/vmwgfx/vmwgfx_execbuf.c @@ -1524,6 +1524,12 @@ static int vmw_cmd_dma(struct vmw_private *dev_priv, bool dirty; =20 cmd =3D container_of(header, typeof(*cmd), header); + + if (unlikely(header->size < sizeof(cmd->body) + sizeof(*suffix))) { + VMW_DEBUG_USER("Invalid SURFACE_DMA command size.\n"); + return -EINVAL; + } + suffix =3D (SVGA3dCmdSurfaceDMASuffix *)((unsigned long) &cmd->body + header->size - sizeof(*suffix)); =20 --=20 2.43.0