AMD General

Reviewed-by: Alysa Liu <[email protected]>

-----Original Message-----
From: Palacek, William <[email protected]>
Sent: Wednesday, July 15, 2026 9:40 AM
To: [email protected]
Cc: Kasiviswanathan, Harish <[email protected]>; Liu, Alysa 
<[email protected]>; Palacek, William <[email protected]>
Subject: [PATCH] drm/amdkfd: Add bounds check for CRAT subtype length

The CRAT parser validates that the subtype header fits within the image, but 
does not verify that the advertised subtype length fits. A malformed CRAT table 
with an oversized length field causes out-of-bounds reads when
kfd_parse_subtype() casts the header to specific subtype structures.

Add validation that sub_type_hdr + length does not exceed the image boundary 
before parsing the subtype contents.

Signed-off-by: William Palacek <[email protected]>
---
 drivers/gpu/drm/amd/amdkfd/kfd_crat.c | 9 +++++++++
 1 file changed, 9 insertions(+)

diff --git a/drivers/gpu/drm/amd/amdkfd/kfd_crat.c 
b/drivers/gpu/drm/amd/amdkfd/kfd_crat.c
index 2a239f45fc24..6e0df685503d 100644
--- a/drivers/gpu/drm/amd/amdkfd/kfd_crat.c
+++ b/drivers/gpu/drm/amd/amdkfd/kfd_crat.c
@@ -1412,6 +1412,15 @@ int kfd_parse_crat_table(void *crat_image, struct 
list_head *device_list,
                        break;
                }

+               /* Validate subtype fits within remaining image */
+               if ((char *)sub_type_hdr + sub_type_hdr->length >
+                   (char *)crat_image + image_len) {
+                       pr_warn("CRAT subtype length %u exceeds image bounds\n",
+                               sub_type_hdr->length);
+                       ret = -EINVAL;
+                       break;
+               }
+
                if (sub_type_hdr->flags & CRAT_SUBTYPE_FLAGS_ENABLED) {
                        ret = kfd_parse_subtype(sub_type_hdr, device_list);
                        if (ret)
--
2.34.1

Reply via email to