From: Shixiong Ou <[email protected]> drm_log_draw_kmsg_record() accesses s[len - 1] to strip the trailing newline, but len is unsigned int. If len is 0, the subtraction wraps to UINT_MAX, causing an out-of-bounds read.
Add an early return when len is 0. Signed-off-by: Shixiong Ou <[email protected]> --- drivers/gpu/drm/clients/drm_log.c | 3 +++ 1 file changed, 3 insertions(+) diff --git a/drivers/gpu/drm/clients/drm_log.c b/drivers/gpu/drm/clients/drm_log.c index e3e02c84a4cf..294b3be1a6b3 100644 --- a/drivers/gpu/drm/clients/drm_log.c +++ b/drivers/gpu/drm/clients/drm_log.c @@ -162,6 +162,9 @@ static void drm_log_draw_kmsg_record(struct drm_log_scanout *scanout, { u32 prefix_len = 0; + if (!len) + return; + if (len > TS_PREFIX_LEN && s[0] == '[' && s[6] == '.' && s[TS_PREFIX_LEN] == ']') prefix_len = TS_PREFIX_LEN + 1; -- 2.25.1 No virus found Checked by Hillstone Network AntiVirus
