panthor_fw_read_build_info() checks whether the metadata range fits in the
firmware image with hdr.meta_start + hdr.meta_size. Both fields are u32, so
the addition can wrap and let an out-of-bounds range pass validation.

The function also reads the "git_sha: " prefix without first checking that
the metadata is long enough, and meta_size == 0 can underflow the NULL
terminator index.

Use subtraction-based bounds checking and reject metadata that is too short
to contain the expected prefix and trailing NULL byte.

Fixes: 2718d91816ee ("drm/panthor: Add the FW logical block")
Cc: [email protected]
Signed-off-by: Osama Abdelkader <[email protected]>
---
 drivers/gpu/drm/panthor/panthor_fw.c | 3 ++-
 1 file changed, 2 insertions(+), 1 deletion(-)

diff --git a/drivers/gpu/drm/panthor/panthor_fw.c 
b/drivers/gpu/drm/panthor/panthor_fw.c
index 6335893d3f16..9d0e1fafdce2 100644
--- a/drivers/gpu/drm/panthor/panthor_fw.c
+++ b/drivers/gpu/drm/panthor/panthor_fw.c
@@ -709,7 +709,8 @@ static int panthor_fw_read_build_info(struct panthor_device 
*ptdev,
                return ret;
 
        if (hdr.meta_start > fw->size ||
-           hdr.meta_start + hdr.meta_size > fw->size) {
+           hdr.meta_size > fw->size - hdr.meta_start ||
+           hdr.meta_size <= header_len) {
                drm_err(&ptdev->base, "Firmware build info corrupt\n");
                /* We don't need the build info, so continue */
                return 0;
-- 
2.43.0

Reply via email to