The VFCT path accepted whatever kmemdup() returned without checking
that the copied image is a valid VBIOS. Every other radeon BIOS
fetch path verifies the 0x55 0xaa signature before trusting the
image; the VFCT path is the odd one out.

Check the signature after copying the image and reject it (freeing
the buffer) if it does not match, matching the amdgpu VFCT path
which validates via check_atom_bios().

Signed-off-by: Mario Limonciello <[email protected]>
---
Cc: Oz Tiram <[email protected]>
 drivers/gpu/drm/radeon/radeon_bios.c | 9 +++++++--
 1 file changed, 7 insertions(+), 2 deletions(-)

diff --git a/drivers/gpu/drm/radeon/radeon_bios.c 
b/drivers/gpu/drm/radeon/radeon_bios.c
index cc10880af096b..215e47c94d29e 100644
--- a/drivers/gpu/drm/radeon/radeon_bios.c
+++ b/drivers/gpu/drm/radeon/radeon_bios.c
@@ -676,9 +676,14 @@ static bool radeon_acpi_vfct_bios(struct radeon_device 
*rdev)
                        rdev->bios = kmemdup(&vbios->VbiosContent,
                                             vhdr->ImageLength,
                                             GFP_KERNEL);
-                       if (rdev->bios)
-                               r = true;
 
+                       if (!rdev->bios ||
+                           rdev->bios[0] != 0x55 || rdev->bios[1] != 0xaa) {
+                               kfree(rdev->bios);
+                               rdev->bios = NULL;
+                               goto out;
+                       }
+                       r = true;
                        goto out;
                }
        }
-- 
2.43.0

Reply via email to