On Mon, Jul 6, 2026 at 10:44 AM William Palacek <[email protected]> wrote:
>
> The CRAT parser validates that the subtype header fits within the image,
> but does not verify that the advertised subtype length fits. A malformed
> CRAT table with an oversized length field causes out-of-bounds reads when
> kfd_parse_subtype() casts the header to specific subtype structures.
>
> Add validation that sub_type_hdr + length does not exceed the image
> boundary before parsing the subtype contents.
>
> Signed-off-by: William Palacek <[email protected]>

Acked-by: Alex Deucher <[email protected]>

> ---
>  drivers/gpu/drm/amd/amdkfd/kfd_crat.c | 9 +++++++++
>  1 file changed, 9 insertions(+)
>
> diff --git a/drivers/gpu/drm/amd/amdkfd/kfd_crat.c 
> b/drivers/gpu/drm/amd/amdkfd/kfd_crat.c
> index 2a239f45fc24..6e0df685503d 100644
> --- a/drivers/gpu/drm/amd/amdkfd/kfd_crat.c
> +++ b/drivers/gpu/drm/amd/amdkfd/kfd_crat.c
> @@ -1412,6 +1412,15 @@ int kfd_parse_crat_table(void *crat_image, struct 
> list_head *device_list,
>                         break;
>                 }
>
> +               /* Validate subtype fits within remaining image */
> +               if ((char *)sub_type_hdr + sub_type_hdr->length >
> +                   (char *)crat_image + image_len) {
> +                       pr_warn("CRAT subtype length %u exceeds image 
> bounds\n",
> +                               sub_type_hdr->length);
> +                       ret = -EINVAL;
> +                       break;
> +               }
> +
>                 if (sub_type_hdr->flags & CRAT_SUBTYPE_FLAGS_ENABLED) {
>                         ret = kfd_parse_subtype(sub_type_hdr, device_list);
>                         if (ret)
> --
> 2.34.1
>

Reply via email to