Skip to content
Commit a5cd3351 authored by Xi Wang's avatar Xi Wang Committed by Dave Airlie
Browse files

drm: integer overflow in drm_mode_dirtyfb_ioctl()



There is a potential integer overflow in drm_mode_dirtyfb_ioctl()
if userspace passes in a large num_clips.  The call to kmalloc would
allocate a small buffer, and the call to fb->funcs->dirty may result
in a memory corruption.

Reported-by: default avatarHaogang Chen <haogangchen@gmail.com>
Signed-off-by: default avatarXi Wang <xi.wang@gmail.com>
Cc: stable@kernel.org
Signed-off-by: default avatarDave Airlie <airlied@redhat.com>
parent c916874d
0% or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment