From nobody Wed Sep 30 04:41:12 2026 Received: from mail-pl1-f179.google.com (mail-pl1-f179.google.com [209.85.214.179]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id D5A1E472F9A for ; Wed, 12 Aug 2026 14:57:08 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.214.179 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786546633; cv=none; b=ob/aROigMcdvHmvFTbo62fY/9XIFi6bqRYKj4oGcPvao42c64wnT3pxoaxcGeY6zzj/kHZyUfRkYJ3HRX7hIdp/uUAdoPDWNZtH0pq9lRPUBypgat6sUxgJIAXBshh7uzWEtHjNj/VDdsmnC+uSnipDQR9lxIUSsUfT45xYB/u4= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786546633; c=relaxed/simple; bh=FdyxRhhBKZiYZz3arqKV848UtUVhcBBrpdMBwG2g/dM=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:To:Cc; b=W5J7FGMGOE3ihpvxkUtqgHcXLbY3/034j2DzfLKARpoLOjPEgBvOTmL/pVyUuE8BUlzfzUNw425CQI3FPcS8ZR16cN2NOO9IhPcDEX4SjWT5iU3XLQEu8EYBRpynTDBfZDBuv8ozX97PrDc+cG7BLPXTF+1skthzf1YIv7Bly44= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=qAImTJA+; arc=none smtp.client-ip=209.85.214.179 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="qAImTJA+" Received: by mail-pl1-f179.google.com with SMTP id d9443c01a7336-2cf6d65d8a7so17680885ad.0 for ; Wed, 12 Aug 2026 07:57:07 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1786546623; x=1787151423; darn=vger.kernel.org; h=cc:to:message-id:content-transfer-encoding:content-type :mime-version:subject:date:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=YJqzV4FfWSH2549UJL4Hdtad7cbUf0wdUKVbd4knoqE=; b=qAImTJA+Yyu3BTpmbZsZWFWlulxKNHEeisg4eI/sTTi2LwkJdO1O5m86xKZhaijakQ 5DvnNLDOG+X7Dj7AANQCYLdOooKI2i0mYyQwWt1FVPacHMURKg7+svf8G09Y3SiJhJdE FP2fyn2savUXxFK0z83oZRW/bHkVdIdWpzEHIW+QfvaJzLNOwcqA+GjjV1fo6tMpd+5n qHFa8Y5d2cMZ0ZOU7QCRU0laLLh3aQBsMBlooMpgGxMcbpOt4An7BF20NqhwJhgwL9rv b6Nl/bQKIkkCnbsWVNplI3s2cy8L+J6THa4LB1Fn3hJFpBr9UNfVSaz1XTCc6Xv6pbMi j2KQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1786546623; x=1787151423; h=cc:to:message-id:content-transfer-encoding:content-type :mime-version:subject:date:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=YJqzV4FfWSH2549UJL4Hdtad7cbUf0wdUKVbd4knoqE=; b=InIer3H1VpvFnMk+Cgbl41se5LWKNDcrt1hvffsxiWy1Lx+ItCxWbN58FSqMei1P+Z paEuOder6I54p5J0WEQ9o/j4B0FnUUim1OcXiSsHG7JELaLEyDaAzFJa3P7OvLl6n9k9 btIQt5/jIfT7O8rgtVL5MwIy4Yzn1YzKiOPSQSUB6sibyJWYS83daut/+g/d+wJ2aK4R Omj9MMtzlZT0d9VoIa71crsS0VHWSeXVtdALH3Td9s/IXtO/pG0IgiO5Vo3nz13ncuUg oNQrPxuUWojbFI/KTOu3OJ9pz3igVOxJgNzFOM4V3jUKW4fS1+E/vOdAHJgIaCc/+XNH lgKw== X-Forwarded-Encrypted: i=1; AHgh+RqqlboM5Ofbrv6D6tpRkBmvLuP3eigUNMvGNdvNzRAaFDPAGJXyJI6Cy8rIi/bl2jlfvhy9b+r/2VUC2Ro=@vger.kernel.org X-Gm-Message-State: AOJu0Ywr/X14zDrz77vHJmTim43Ok4XzncLBkpqdXv/NK/JA0vnHATKy xiWSajTEDmf+gy4Pu9fTdizTUv3SXI9gKT+taOJet9BouEWg0Rb+vmoV X-Gm-Gg: AR+sD10YN65wYBtXVaTDEkFAS9Qx55ad8i2KoTiwkN1iSx6ssUBoXpDikFqaoq6luAb 9IN8vZc3v3ppxJftBMkRKdX5++eiPn8HDm9k3pnRFwbh9NW729DTyQZ9o/UEiIDSKVv4UyXhhxg XWEqaZX9K84jx0p1A/28DjjypgWWmC8GWfLK9aypHmmgXZvnr+mqwONNAm4pvxIXll5RB2U9DvL FwpIcrGz6L6dWSzt5YuZMWl/aI++GaxSNDiFwpHjujC2u4E+yr1KqLBT1z5WOC7QAwO8ztCeSI0 VMmGX42UimLn2S5K6T/1r2wo0AAoQFOb2a2rA0Zu2rCjDxwETJzmoW0tBJyinWBdGueQaLg4is5 krgVE3SMbb10nNe3HTI6BKF7Qma6ec83MPbJDUuLUpRBZsRk8xkcW/6+RzWQXJZ1qQHuDP69gf6 pKvXgrcm0Hoa8Unq7znpp4lrJ2p698sVur9eu5K91mFcsACFQe6ITBSkujaGY= X-Received: by 2002:a17:903:324d:b0:2ca:4f33:e86f with SMTP id d9443c01a7336-2d3455870eamr75737575ad.12.1786546622846; Wed, 12 Aug 2026 07:57:02 -0700 (PDT) Received: from LAPTOP-N3B6U5LC.localdomain ([117.147.100.52]) by smtp.gmail.com with ESMTPSA id d9443c01a7336-2d352208543sm8003165ad.60.2026.08.12.07.56.58 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 12 Aug 2026 07:57:02 -0700 (PDT) From: Zhenhao Wan Date: Wed, 12 Aug 2026 22:56:46 +0800 Subject: [PATCH] drm/nouveau/uvmm: reject zero-length range in validate_range Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260812-nouveau-uvmm-pt-fixes-v1-1-ab3a823f946e@gmail.com> X-B4-Tracking: v=1; b=H4sIAK2JfGoC/yXMQQqDMBCF4avIrB1IImjrVcRFjGM7BaNkTBDEu 5vq8uPxvwOEApNAWxwQKLHw4jN0WYD7Wv8h5DEbjDK1emmDfomJbMSY5hnXDSfeSfDdqHq02qr KTZDbNdA95LTrH0scfuS2/xmc5wUrhSUxeQAAAA== X-Change-ID: 20260812-nouveau-uvmm-pt-fixes-9706da1a03cf To: Lyude Paul , Danilo Krummrich , Maarten Lankhorst , Maxime Ripard , Thomas Zimmermann , David Airlie , Simona Vetter , Dave Airlie Cc: dri-devel@lists.freedesktop.org, nouveau@lists.freedesktop.org, linux-kernel@vger.kernel.org, Yuhao Jiang , stable@vger.kernel.org, Zhenhao Wan X-Mailer: b4 0.15.2 X-Developer-Signature: v=1; a=ed25519-sha256; t=1786546618; l=1968; i=whi4ed0g@gmail.com; h=from:subject:message-id; bh=FdyxRhhBKZiYZz3arqKV848UtUVhcBBrpdMBwG2g/dM=; b=ar5RYS5eT7jVtxn2WyhdU/5ZUt+UbSy5eflTkgD7wLRWZEeSTi2xLVN1+tdVDVmKDg8elm2v3 1ZlEgthYLiQCWaVIbnBvP5OHkT64+EpC1XNJ887M4atJGbdz4l+31Wx X-Developer-Key: i=whi4ed0g@gmail.com; a=ed25519; pk=zRTKlstE0LmilshGwJsFYEVjiT6RiXMBXK8Og6VmuVQ= nouveau_uvmm_validate_range() rejects misaligned addresses and ranges and defers the remaining bounds check to drm_gpuvm_range_valid(), but neither rejects a zero range: 0 is page-aligned and addr + 0 does not overflow, so a zero-length VM_BIND request from userspace passes validation. It then reaches the generic GPUVA interval-tree insertion, where the node last key is computed as addr + range - 1. With range =3D=3D 0 this underflows to addr - 1, producing an interval whose end lies below its start. The resulting malformed node corrupts the augmented interval tree and misleads the overlap checks of later map/unmap operations on the same VM. drm_gpuvm_range_valid() intentionally leaves the zero-range rejection to its callers; drm/imagination does exactly this with an explicit "size !=3D = 0" test next to its drm_gpuvm_range_valid() call. nouveau simply omitted it. Reject range =3D=3D 0 alongside the existing alignment test. Fixes: b88baab82871 ("drm/nouveau: implement new VM_BIND uAPI") Reported-by: Yuhao Jiang Assisted-by: Claude:claude-opus-5 Cc: stable@vger.kernel.org Signed-off-by: Zhenhao Wan --- drivers/gpu/drm/nouveau/nouveau_uvmm.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/drivers/gpu/drm/nouveau/nouveau_uvmm.c b/drivers/gpu/drm/nouve= au/nouveau_uvmm.c index f5e4756b4de4..0efedd9ecc75 100644 --- a/drivers/gpu/drm/nouveau/nouveau_uvmm.c +++ b/drivers/gpu/drm/nouveau/nouveau_uvmm.c @@ -1008,7 +1008,7 @@ nouveau_uvmm_validate_range(struct nouveau_uvmm *uvmm= , u64 addr, u64 range) if (addr & ~PAGE_MASK) return -EINVAL; =20 - if (range & ~PAGE_MASK) + if (!range || range & ~PAGE_MASK) return -EINVAL; =20 if (!drm_gpuvm_range_valid(&uvmm->base, addr, range)) --- base-commit: db2ddb87143519e20a95aa36c60b36107b736a58 change-id: 20260812-nouveau-uvmm-pt-fixes-9706da1a03cf Best regards, -- =20 Zhenhao Wan