add buf length check before using it to access data

Signed-off-by: Gangliang Xie <[email protected]>
---
 drivers/gpu/drm/amd/amdgpu/amdgpu_psp_ta.c | 5 ++++-
 1 file changed, 4 insertions(+), 1 deletion(-)

diff --git a/drivers/gpu/drm/amd/amdgpu/amdgpu_psp_ta.c 
b/drivers/gpu/drm/amd/amdgpu/amdgpu_psp_ta.c
index 0d3c18f04ac3..8ae72c862d11 100644
--- a/drivers/gpu/drm/amd/amdgpu/amdgpu_psp_ta.c
+++ b/drivers/gpu/drm/amd/amdgpu/amdgpu_psp_ta.c
@@ -166,7 +166,8 @@ static ssize_t ta_if_load_debugfs_write(struct file *fp, 
const char *buf, size_t
        if (ret)
                return -EFAULT;
 
-       if (ta_bin_len > PSP_1_MEG)
+       if (ta_bin_len < sizeof(struct common_firmware_header) ||
+           ta_bin_len > PSP_1_MEG)
                return -EINVAL;
 
        copy_pos += sizeof(uint32_t);
@@ -321,6 +322,8 @@ static ssize_t ta_if_invoke_debugfs_write(struct file *fp, 
const char *buf, size
        ret = copy_from_user((void *)&shared_buf_len, &buf[copy_pos], 
sizeof(uint32_t));
        if (ret)
                return -EFAULT;
+       if (!shared_buf_len || shared_buf_len > PSP_1_MEG)
+               return -EINVAL;
        copy_pos += sizeof(uint32_t);
 
        shared_buf = memdup_user(&buf[copy_pos], shared_buf_len);
-- 
2.34.1

Reply via email to