From: Shixiong Ou <[email protected]>

drm_log_draw_kmsg_record() accesses s[len - 1] to strip the trailing
newline, but len is unsigned int. If len is 0, the subtraction wraps
to UINT_MAX, causing an out-of-bounds read.

Add an early return when len is 0.

Signed-off-by: Shixiong Ou <[email protected]>
---
 drivers/gpu/drm/clients/drm_log.c | 3 +++
 1 file changed, 3 insertions(+)

diff --git a/drivers/gpu/drm/clients/drm_log.c 
b/drivers/gpu/drm/clients/drm_log.c
index e3e02c84a4cf..294b3be1a6b3 100644
--- a/drivers/gpu/drm/clients/drm_log.c
+++ b/drivers/gpu/drm/clients/drm_log.c
@@ -162,6 +162,9 @@ static void drm_log_draw_kmsg_record(struct drm_log_scanout 
*scanout,
 {
        u32 prefix_len = 0;
 
+       if (!len)
+               return;
+
        if (len > TS_PREFIX_LEN && s[0] == '[' && s[6] == '.' && 
s[TS_PREFIX_LEN] == ']')
                prefix_len = TS_PREFIX_LEN + 1;
 
-- 
2.25.1


No virus found
                Checked by Hillstone Network AntiVirus

Reply via email to