From nobody Tue Sep 29 00:33:19 2026 Received: from cstnet.cn (smtp21.cstnet.cn [159.226.251.21]) (using TLSv1.2 with cipher DHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 0406E3587DE for ; Fri, 14 Aug 2026 08:03:43 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=159.226.251.21 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786694626; cv=none; b=Q+u5+7vPdZAKZEb8T1inrIShIZSyGaxDgnsnm+nygPNHUh3yOtjNaikmQU0XmjcaDQJ/0D4bQBZUBa4q8/goivjOykTjiCLdcOxUwS3n+5ld7kktvJBbYrNbc5YJSmlCGZJtgURGDVH2Ss4ds7lh9HEuC1326JnIKwMRn3+hcBk= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786694626; c=relaxed/simple; bh=sXpyhbFEz7u1m+4L3rRn6IrgwlHQSUKbopYF8+O4WFI=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version:Content-Type; b=N/kxORN9slkxYOZGbSQTE1edV9iVJd/B/AgjgHP07TXw9DYAArnJQir2sPZor7927Pj4Ofv3mMrzXZykuccd98JcnYPd801otQM3MgEPQ7R2HjuOpoEFApJDBNIE9pCUFvqiWGDgBSJQDtYIW+4izrVhXB96OwYB8+WprF6xFCU= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=iscas.ac.cn; spf=pass smtp.mailfrom=iscas.ac.cn; arc=none smtp.client-ip=159.226.251.21 Authentication-Results: smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=iscas.ac.cn Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=iscas.ac.cn Received: from localhost.localdomain (unknown [111.196.241.250]) by APP-01 (Coremail) with SMTP id qwCowACnffHXy35q_MOeBQ--.48866S2; Fri, 14 Aug 2026 16:03:36 +0800 (CST) From: Pengpeng Hou To: Lyude Paul , Danilo Krummrich Cc: Maarten Lankhorst , Maxime Ripard , Thomas Zimmermann , David Airlie , Simona Vetter , dri-devel@lists.freedesktop.org, nouveau@lists.freedesktop.org, linux-kernel@vger.kernel.org, Pengpeng Hou Subject: [PATCH v2] drm/nouveau: validate legacy BIT table bounds Date: Fri, 14 Aug 2026 16:03:35 +0800 Message-ID: <20260814080335.22263-1-pengpeng@iscas.ac.cn> X-Mailer: git-send-email 2.50.1 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable X-CM-TRANSID: qwCowACnffHXy35q_MOeBQ--.48866S2 X-Coremail-Antispam: 1UD129KBjvJXoW7Ww45Zw18ZrW5ur13WryfJFb_yoW5JryUpF W7WasrAr4rtr4agr4Iyr45Aa4fZws3Wr9rGFy3KryY9ryftF10k3W8Ar1Yg345JryDuryY yF4DKa4Uur45t3DanT9S1TB71UUUUU7qnTZGkaVYY2UrUUUUjbIjqfuFe4nvWSU5nxnvy2 9KBjDU0xBIdaVrnRJUUU9I14x267AKxVW8JVW5JwAFc2x0x2IEx4CE42xK8VAvwI8IcIk0 rVWrJVCq3wAFIxvE14AKwVWUJVWUGwA2ocxC64kIII0Yj41l84x0c7CEw4AK67xGY2AK02 1l84ACjcxK6xIIjxv20xvE14v26ryj6F1UM28EF7xvwVC0I7IYx2IY6xkF7I0E14v26r4U JVWxJr1l84ACjcxK6I8E87Iv67AKxVWxJr0_GcWl84ACjcxK6I8E87Iv6xkF7I0E14v26r xl6s0DM2AIxVAIcxkEcVAq07x20xvEncxIr21l5I8CrVACY4xI64kE6c02F40Ex7xfMcIj 6xIIjxv20xvE14v26r1q6rW5McIj6I8E87Iv67AKxVW8JVWxJwAm72CE4IkC6x0Yz7v_Jr 0_Gr1lF7xvr2IYc2Ij64vIr41lF7I21c0EjII2zVCS5cI20VAGYxC7M4IIrI8v6xkF7I0E 8cxan2IY04v7MxkF7I0En4kS14v26r1q6r43MxAIw28IcxkI7VAKI48JMxC20s026xCaFV Cjc4AY6r1j6r4UMI8I3I0E5I8CrVAFwI0_Jr0_Jr4lx2IqxVCjr7xvwVAFwI0_JrI_JrWl x4CE17CEb7AF67AKxVWUtVW8ZwCIc40Y0x0EwIxGrwCI42IY6xIIjxv20xvE14v26r4j6r yUMIIF0xvE2Ix0cI8IcVCY1x0267AKxVWxJVW8Jr1lIxAIcVCF04k26cxKx2IYs7xG6r1j 6r1xMIIF0xvEx4A2jsIE14v26r4j6F4UMIIF0xvEx4A2jsIEc7CjxVAFwI0_Gr1j6F4UJb IYCTnIWIevJa73UjIFyTuYvjfU5byZUUUUU X-CM-SenderInfo: pshqw1xhqjqxpvfd2hldfou0/ The legacy BIT parser finds the BIT signature and then reads the entry shape and entry array directly from the VBIOS image. The signature does not prove that the complete header, entry array or referenced table payload fits in the image. Validate each extent before use. Preserve the legacy zero-offset meaning for zero-length entries, but reject non-empty entries with a null or out-of-range offset. Fixes: 6ee738610f41 ("drm/nouveau: Add DRM driver for NVIDIA GPUs") Assisted-by: Codex:gpt-5 Signed-off-by: Pengpeng Hou --- Changes since v1: https://lore.kernel.org/all/20260706093856.81984-1-pengpe= ng@iscas.ac.cn/ - validate the complete BIT header and entry array - validate each referenced payload extent - preserve zero-offset semantics for zero-length entries only The legacy BIT and ROMPTR contracts were reviewed statically; no malformed VBIOS image was exercised. drivers/gpu/drm/nouveau/nouveau_bios.c | 21 ++++++++++++++++++--- 1 file changed, 18 insertions(+), 3 deletions(-) diff --git a/drivers/gpu/drm/nouveau/nouveau_bios.c b/drivers/gpu/drm/nouve= au/nouveau_bios.c index 38032bb95826..a4ef62928ba3 100644 --- a/drivers/gpu/drm/nouveau/nouveau_bios.c +++ b/drivers/gpu/drm/nouveau/nouveau_bios.c @@ -972,24 +972,39 @@ bit_table(struct drm_device *dev, u8 id, struct bit_e= ntry *bit) { struct nouveau_drm *drm =3D nouveau_drm(dev); struct nvbios *bios =3D &drm->vbios; - u8 entries, *entry; + u32 entry_size, entries, offset; + u8 *entry; =20 if (bios->type !=3D NVBIOS_BIT) return -ENODEV; =20 + if (bios->offset > bios->length || bios->length - bios->offset < 12) + return -EINVAL; + + entry_size =3D bios->data[bios->offset + 9]; entries =3D bios->data[bios->offset + 10]; - entry =3D &bios->data[bios->offset + 12]; + if (entry_size < 6 || + entries > (bios->length - bios->offset - 12) / entry_size) + return -EINVAL; + + entry =3D &bios->data[bios->offset + 12]; while (entries--) { if (entry[0] =3D=3D id) { bit->id =3D entry[0]; bit->version =3D entry[1]; bit->length =3D ROM16(entry[2]); bit->offset =3D ROM16(entry[4]); + + offset =3D bit->offset; + if ((bit->length && !offset) || offset > bios->length || + bit->length > bios->length - offset) + return -EINVAL; + bit->data =3D ROMPTR(dev, entry[4]); return 0; } =20 - entry +=3D bios->data[bios->offset + 9]; + entry +=3D entry_size; } =20 return -ENOENT; --=20 2.50.1 (Apple Git-155)