drm/mediatek: Add 0 size check to mtk_drm_gem_obj
authorJustin Green <greenjustin@chromium.org>
Thu, 7 Mar 2024 18:00:51 +0000 (13:00 -0500)
committerChun-Kuang Hu <chunkuang.hu@kernel.org>
Mon, 1 Apr 2024 14:52:31 +0000 (14:52 +0000)
Add a check to mtk_drm_gem_init if we attempt to allocate a GEM object
of 0 bytes. Currently, no such check exists and the kernel will panic if
a userspace application attempts to allocate a 0x0 GBM buffer.

Tested by attempting to allocate a 0x0 GBM buffer on an MT8188 and
verifying that we now return EINVAL.

Fixes: 119f5173628a ("drm/mediatek: Add DRM Driver for Mediatek SoC MT8173.")
Signed-off-by: Justin Green <greenjustin@chromium.org>
Reviewed-by: AngeloGioacchino Del Regno <angelogioacchino.delregno@collabora.com>
Reviewed-by: CK Hu <ck.hu@mediatek.com>
Link: https://patchwork.kernel.org/project/dri-devel/patch/20240307180051.4104425-1-greenjustin@chromium.org/
Signed-off-by: Chun-Kuang Hu <chunkuang.hu@kernel.org>
drivers/gpu/drm/mediatek/mtk_drm_gem.c

index 4f2e3feabc0f8afd76b43db5d637d83746764c58..1bf229615b018874f7340cbe0f60bb6e2b57f48c 100644 (file)
@@ -38,6 +38,9 @@ static struct mtk_drm_gem_obj *mtk_drm_gem_init(struct drm_device *dev,
 
        size = round_up(size, PAGE_SIZE);
 
+       if (size == 0)
+               return ERR_PTR(-EINVAL);
+
        mtk_gem_obj = kzalloc(sizeof(*mtk_gem_obj), GFP_KERNEL);
        if (!mtk_gem_obj)
                return ERR_PTR(-ENOMEM);