summaryrefslogtreecommitdiff
path: root/drivers/gpu
diff options
context:
space:
mode:
authorShixiong Ou <oushixiong@kylinos.cn>2026-08-25 18:41:34 +0800
committerThomas Zimmermann <tzimmermann@suse.de>2026-08-26 08:50:09 +0200
commitc6f48e59ece0123f6a11527ad4d89b21c2d65b87 (patch)
tree109d1f5ad041602c95d44d426449b452611b9a2e /drivers/gpu
parent5bb489b333237c1bf63a891a4362986253a0060a (diff)
downloadlinux-c6f48e59ece0123f6a11527ad4d89b21c2d65b87.tar.gz
linux-c6f48e59ece0123f6a11527ad4d89b21c2d65b87.zip
drm/sysfb: ofdrm: Fix integer overflow in fb_size calculation
The framebuffer size calculation `fb_size = linebytes * height` can overflow when both values are large (e.g., 46341 * 46341 > INT_MAX). Since linebytes and height are both int types, the multiplication is performed as int * int, which results in undefined behavior on overflow. Use check_mul_overflow() to detect and prevent this overflow, consistent with the approach used in simpledrm.c and corebootdrm.c. Signed-off-by: Shixiong Ou <oushixiong@kylinos.cn> Reviewed-by: Thomas Zimmermann <tzimmermann@suse.de> Signed-off-by: Thomas Zimmermann <tzimmermann@suse.de> Fixes: c8a17756c425 ("drm/ofdrm: Add ofdrm for Open Firmware framebuffers") Cc: <stable@vger.kernel.org> # v6.2+ Link: https://patch.msgid.link/20260825104134.669676-1-oushixiong1025@163.com
Diffstat (limited to 'drivers/gpu')
-rw-r--r--drivers/gpu/drm/sysfb/ofdrm.c6
1 files changed, 5 insertions, 1 deletions
diff --git a/drivers/gpu/drm/sysfb/ofdrm.c b/drivers/gpu/drm/sysfb/ofdrm.c
index 819aed466727..a6dc34b9ec0f 100644
--- a/drivers/gpu/drm/sysfb/ofdrm.c
+++ b/drivers/gpu/drm/sysfb/ofdrm.c
@@ -2,6 +2,7 @@
#include <linux/aperture.h>
#include <linux/of_address.h>
+#include <linux/overflow.h>
#include <linux/pci.h>
#include <linux/platform_device.h>
#include <linux/pm.h>
@@ -913,7 +914,10 @@ static struct ofdrm_device *ofdrm_device_create(struct drm_driver *drv,
return ERR_PTR(-EINVAL);
}
- fb_size = linebytes * height;
+ if (check_mul_overflow(linebytes, height, &fb_size)) {
+ drm_err(dev, "framebuffer size exceeds maximum\n");
+ return ERR_PTR(-EINVAL);
+ }
/*
* Try to figure out the address of the framebuffer. Unfortunately, Open