* [PATCH 5.10 1/3] string.h: add array-wrappers for (v)memdup_user()
@ 2026-09-23 14:56 Roman Demidov
2026-09-23 14:56 ` [PATCH 5.10 2/3] drm/amdgpu: Use vmemdup_array_user in amdgpu_bo_create_list_entry_array Roman Demidov
2026-09-23 14:56 ` [PATCH 5.10 3/3] drm/amdgpu: Limit BO list entry count to prevent resource exhaustion Roman Demidov
0 siblings, 2 replies; 3+ messages in thread
From: Roman Demidov @ 2026-09-23 14:56 UTC (permalink / raw)
To: stable, Greg Kroah-Hartman
Cc: Roman Demidov, Alex Deucher, Christian König, David Airlie,
Daniel Vetter, Kees Cook, Andy Shevchenko, Sasha Levin,
Jani Nikula, amd-gfx, dri-devel, linux-kernel, lvc-project,
David Airlie, Philipp Stanner, Andy Shevchenko, Kees Cook,
Zack Rusin
From: Philipp Stanner <pstanner@redhat.com>
commit 313ebe47d75558511aa1237b6e35c663b5c0ec6f upstream.
Currently, user array duplications are sometimes done without an
overflow check. Sometimes the checks are done manually; sometimes the
array size is calculated with array_size() and sometimes by calculating
n * size directly in code.
Introduce wrappers for arrays for memdup_user() and vmemdup_user() to
provide a standardized and safe way for duplicating user arrays.
This is both for new code as well as replacing usage of (v)memdup_user()
in existing code that uses, e.g., n * size to calculate array sizes.
Suggested-by: David Airlie <airlied@redhat.com>
Signed-off-by: Philipp Stanner <pstanner@redhat.com>
Reviewed-by: Andy Shevchenko <andy.shevchenko@gmail.com>
Reviewed-by: Kees Cook <keescook@chromium.org>
Reviewed-by: Zack Rusin <zackr@vmware.com>
Signed-off-by: Dave Airlie <airlied@redhat.com>
Link: https://patchwork.freedesktop.org/patch/msgid/20230920123612.16914-3-pstanner@redhat.com
Stable-dep-of: c833d6c7199c ("drm/amdgpu: Limit BO list entry count to prevent resource exhaustion")
Signed-off-by: Roman Demidov <roman.demidov.nn@gmail.com>
---
Backport fix for CVE-2026-23468
include/linux/string.h | 40 ++++++++++++++++++++++++++++++++++++++++
1 file changed, 40 insertions(+)
diff --git a/include/linux/string.h b/include/linux/string.h
index 98b053d9c700..85efd2b738ea 100644
--- a/include/linux/string.h
+++ b/include/linux/string.h
@@ -5,6 +5,8 @@
#include <linux/compiler.h> /* for inline */
#include <linux/types.h> /* for size_t */
#include <linux/stddef.h> /* for NULL */
+#include <linux/err.h> /* for ERR_PTR() */
+#include <linux/overflow.h> /* for check_mul_overflow() */
#include <stdarg.h>
#include <uapi/linux/string.h>
@@ -13,6 +15,44 @@ extern void *memdup_user(const void __user *, size_t);
extern void *vmemdup_user(const void __user *, size_t);
extern void *memdup_user_nul(const void __user *, size_t);
+/**
+ * memdup_array_user - duplicate array from user space
+ * @src: source address in user space
+ * @n: number of array members to copy
+ * @size: size of one array member
+ *
+ * Return: an ERR_PTR() on failure. Result is physically
+ * contiguous, to be freed by kfree().
+ */
+static inline void *memdup_array_user(const void __user *src, size_t n, size_t size)
+{
+ size_t nbytes;
+
+ if (check_mul_overflow(n, size, &nbytes))
+ return ERR_PTR(-EOVERFLOW);
+
+ return memdup_user(src, nbytes);
+}
+
+/**
+ * vmemdup_array_user - duplicate array from user space
+ * @src: source address in user space
+ * @n: number of array members to copy
+ * @size: size of one array member
+ *
+ * Return: an ERR_PTR() on failure. Result may be not
+ * physically contiguous. Use kvfree() to free.
+ */
+static inline void *vmemdup_array_user(const void __user *src, size_t n, size_t size)
+{
+ size_t nbytes;
+
+ if (check_mul_overflow(n, size, &nbytes))
+ return ERR_PTR(-EOVERFLOW);
+
+ return vmemdup_user(src, nbytes);
+}
+
/*
* Include machine specific inline routines
*/
--
2.53.0
^ permalink raw reply [flat|nested] 3+ messages in thread
* [PATCH 5.10 2/3] drm/amdgpu: Use vmemdup_array_user in amdgpu_bo_create_list_entry_array
2026-09-23 14:56 [PATCH 5.10 1/3] string.h: add array-wrappers for (v)memdup_user() Roman Demidov
@ 2026-09-23 14:56 ` Roman Demidov
2026-09-23 14:56 ` [PATCH 5.10 3/3] drm/amdgpu: Limit BO list entry count to prevent resource exhaustion Roman Demidov
1 sibling, 0 replies; 3+ messages in thread
From: Roman Demidov @ 2026-09-23 14:56 UTC (permalink / raw)
To: stable, Greg Kroah-Hartman
Cc: Roman Demidov, Alex Deucher, Christian König, David Airlie,
Daniel Vetter, Kees Cook, Andy Shevchenko, Sasha Levin,
Jani Nikula, amd-gfx, dri-devel, linux-kernel, lvc-project,
Tvrtko Ursulin, Fang Wang
From: Tvrtko Ursulin <tvrtko.ursulin@igalia.com>
commit c4ac100e9ae252b09986766ad23b1f83ca3a369d upstream.
Replace kvmalloc_array() + copy_from_user() with vmemdup_array_user() on
the fast path.
This shrinks the source code and improves separation between the kernel
and userspace slabs.
Signed-off-by: Tvrtko Ursulin <tvrtko.ursulin@igalia.com>
Signed-off-by: Alex Deucher <alexander.deucher@amd.com>
Signed-off-by: Fang Wang <32840572@qq.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
Stable-dep-of: c833d6c7199c ("drm/amdgpu: Limit BO list entry count to prevent resource exhaustion")
Signed-off-by: Roman Demidov <roman.demidov.nn@gmail.com>
---
Backport fix for CVE-2026-23468
drivers/gpu/drm/amd/amdgpu/amdgpu_bo_list.c | 41 +++++++++------------
1 file changed, 17 insertions(+), 24 deletions(-)
diff --git a/drivers/gpu/drm/amd/amdgpu/amdgpu_bo_list.c b/drivers/gpu/drm/amd/amdgpu/amdgpu_bo_list.c
index 9fb8012007e2..22d7b7c504db 100644
--- a/drivers/gpu/drm/amd/amdgpu/amdgpu_bo_list.c
+++ b/drivers/gpu/drm/amd/amdgpu/amdgpu_bo_list.c
@@ -224,43 +224,36 @@ void amdgpu_bo_list_put(struct amdgpu_bo_list *list)
int amdgpu_bo_create_list_entry_array(struct drm_amdgpu_bo_list_in *in,
struct drm_amdgpu_bo_list_entry **info_param)
{
- const void __user *uptr = u64_to_user_ptr(in->bo_info_ptr);
const uint32_t info_size = sizeof(struct drm_amdgpu_bo_list_entry);
+ const void __user *uptr = u64_to_user_ptr(in->bo_info_ptr);
+ const uint32_t bo_info_size = in->bo_info_size;
+ const uint32_t bo_number = in->bo_number;
struct drm_amdgpu_bo_list_entry *info;
- int r;
-
- info = kvmalloc_array(in->bo_number, info_size, GFP_KERNEL);
- if (!info)
- return -ENOMEM;
/* copy the handle array from userspace to a kernel buffer */
- r = -EFAULT;
- if (likely(info_size == in->bo_info_size)) {
- unsigned long bytes = in->bo_number *
- in->bo_info_size;
-
- if (copy_from_user(info, uptr, bytes))
- goto error_free;
-
+ if (likely(info_size == bo_info_size)) {
+ info = vmemdup_array_user(uptr, bo_number, info_size);
+ if (IS_ERR(info))
+ return PTR_ERR(info);
} else {
- unsigned long bytes = min(in->bo_info_size, info_size);
+ const uint32_t bytes = min(bo_info_size, info_size);
unsigned i;
- memset(info, 0, in->bo_number * info_size);
- for (i = 0; i < in->bo_number; ++i) {
- if (copy_from_user(&info[i], uptr, bytes))
- goto error_free;
+ info = kvmalloc_array(bo_number, info_size, GFP_KERNEL);
+ if (!info)
+ return -ENOMEM;
- uptr += in->bo_info_size;
+ memset(info, 0, bo_number * info_size);
+ for (i = 0; i < bo_number; ++i, uptr += bo_info_size) {
+ if (copy_from_user(&info[i], uptr, bytes)) {
+ kvfree(info);
+ return -EFAULT;
+ }
}
}
*info_param = info;
return 0;
-
-error_free:
- kvfree(info);
- return r;
}
int amdgpu_bo_list_ioctl(struct drm_device *dev, void *data,
--
2.53.0
^ permalink raw reply [flat|nested] 3+ messages in thread
* [PATCH 5.10 3/3] drm/amdgpu: Limit BO list entry count to prevent resource exhaustion
2026-09-23 14:56 [PATCH 5.10 1/3] string.h: add array-wrappers for (v)memdup_user() Roman Demidov
2026-09-23 14:56 ` [PATCH 5.10 2/3] drm/amdgpu: Use vmemdup_array_user in amdgpu_bo_create_list_entry_array Roman Demidov
@ 2026-09-23 14:56 ` Roman Demidov
1 sibling, 0 replies; 3+ messages in thread
From: Roman Demidov @ 2026-09-23 14:56 UTC (permalink / raw)
To: stable, Greg Kroah-Hartman
Cc: Roman Demidov, Alex Deucher, Christian König, David Airlie,
Daniel Vetter, Kees Cook, Andy Shevchenko, Sasha Levin,
Jani Nikula, amd-gfx, dri-devel, linux-kernel, lvc-project,
Jesse Zhang, Fang Wang
From: "Jesse.Zhang" <Jesse.Zhang@amd.com>
commit 6270b1a5dab94665d7adce3dc78bc9066ed28bdd upstream.
Userspace can pass an arbitrary number of BO list entries via the
bo_number field. Although the previous multiplication overflow check
prevents out-of-bounds allocation, a large number of entries could still
cause excessive memory allocation (up to potentially gigabytes) and
unnecessarily long list processing times.
Introduce a hard limit of 128k entries per BO list, which is more than
sufficient for any realistic use case (e.g., a single list containing all
buffers in a large scene). This prevents memory exhaustion attacks and
ensures predictable performance.
Return -EINVAL if the requested entry count exceeds the limit
Reviewed-by: Christian König <christian.koenig@amd.com>
Suggested-by: Christian König <christian.koenig@amd.com>
Signed-off-by: Jesse Zhang <jesse.zhang@amd.com>
Signed-off-by: Alex Deucher <alexander.deucher@amd.com>
(cherry picked from commit 688b87d39e0aa8135105b40dc167d74b5ada5332)
Cc: stable@vger.kernel.org
Signed-off-by: Fang Wang <32840572@qq.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Roman Demidov <roman.demidov.nn@gmail.com>
---
Backport fix for CVE-2026-23468
drivers/gpu/drm/amd/amdgpu/amdgpu_bo_list.c | 4 ++++
1 file changed, 4 insertions(+)
diff --git a/drivers/gpu/drm/amd/amdgpu/amdgpu_bo_list.c b/drivers/gpu/drm/amd/amdgpu/amdgpu_bo_list.c
index 22d7b7c504db..ca0d82be5c9c 100644
--- a/drivers/gpu/drm/amd/amdgpu/amdgpu_bo_list.c
+++ b/drivers/gpu/drm/amd/amdgpu/amdgpu_bo_list.c
@@ -35,6 +35,7 @@
#define AMDGPU_BO_LIST_MAX_PRIORITY 32u
#define AMDGPU_BO_LIST_NUM_BUCKETS (AMDGPU_BO_LIST_MAX_PRIORITY + 1)
+#define AMDGPU_BO_LIST_MAX_ENTRIES (128 * 1024)
static void amdgpu_bo_list_free_rcu(struct rcu_head *rcu)
{
@@ -230,6 +231,9 @@ int amdgpu_bo_create_list_entry_array(struct drm_amdgpu_bo_list_in *in,
const uint32_t bo_number = in->bo_number;
struct drm_amdgpu_bo_list_entry *info;
+ if (bo_number > AMDGPU_BO_LIST_MAX_ENTRIES)
+ return -EINVAL;
+
/* copy the handle array from userspace to a kernel buffer */
if (likely(info_size == bo_info_size)) {
info = vmemdup_array_user(uptr, bo_number, info_size);
--
2.53.0
^ permalink raw reply [flat|nested] 3+ messages in thread
end of thread, other threads:[~2026-09-23 14:56 UTC | newest]
Thread overview: 3+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-09-23 14:56 [PATCH 5.10 1/3] string.h: add array-wrappers for (v)memdup_user() Roman Demidov
2026-09-23 14:56 ` [PATCH 5.10 2/3] drm/amdgpu: Use vmemdup_array_user in amdgpu_bo_create_list_entry_array Roman Demidov
2026-09-23 14:56 ` [PATCH 5.10 3/3] drm/amdgpu: Limit BO list entry count to prevent resource exhaustion Roman Demidov
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®