drm/panthor: reject firmware sections with oversized data
authorOsama Abdelkader <osama.abdelkader@gmail.com>
Thu, 16 Jul 2026 14:39:38 +0000 (16:39 +0200)
committerSteven Price <steven.price@arm.com>
Fri, 24 Jul 2026 15:35:12 +0000 (16:35 +0100)
commita3caaa06809248b996254be5b47e10804a3494e2
treec633304072032b385a8d91e65256faca2159f6fa
parent112badb7245059c176e3924f9cd9ce2933cb0082
drm/panthor: reject firmware sections with oversized data

In panthor_fw_load_section_entry(), the data size to copy is calculated
without validating it against the allocated section_size:

    section->data.size = hdr.data.end - hdr.data.start;

If a crafted firmware sets data.size larger than the allocated memory,
this could cause a heap buffer overflow in panthor_fw_init_section_mem()

    memcpy(section->mem->kmap, section->data.buf, section->data.size);

Additionally, if the section->data.size exceeds the BO size, could this
memset underflow the size calculation, leading to a massive out-of-bounds
zeroing of kernel memory?

    memset(section->mem->kmap + section->data.size, 0,
           panthor_kernel_bo_size(section->mem) - section->data.size);

Reject section entries whose initial data is larger than the section size.

Fixes: 2718d91816ee ("drm/panthor: Add the FW logical block")
Cc: stable@vger.kernel.org
Signed-off-by: Osama Abdelkader <osama.abdelkader@gmail.com>
Reviewed-by: Steven Price <steven.price@arm.com>
Reviewed-by: Boris Brezillon <boris.brezillon@collabora.com>
Link: https://patch.msgid.link/20260716143939.21903-1-osama.abdelkader@gmail.com
Signed-off-by: Steven Price <steven.price@arm.com>
drivers/gpu/drm/panthor/panthor_fw.c