On 20/07/2026 12:32, Osama Abdelkader wrote:
> panthor_fw_read_build_info() checks whether the metadata range fits in the
> firmware image with hdr.meta_start + hdr.meta_size. Both fields are u32, so
> the addition can wrap and let an out-of-bounds range pass validation.
> 
> The function also reads the "git_sha: " prefix without first checking that
> the metadata is long enough, and meta_size == 0 can underflow the NULL
> terminator index.
> 
> Use subtraction-based bounds checking and reject metadata that is too short
> to contain the expected prefix and trailing NULL byte.
> 
> Fixes: 2718d91816ee ("drm/panthor: Add the FW logical block")
> Cc: [email protected]
> Signed-off-by: Osama Abdelkader <[email protected]>

Reviewed-by: Steven Price <[email protected]>

I'll push this to drm-misc-fixes.

Thanks,
Steve

> ---
>  drivers/gpu/drm/panthor/panthor_fw.c | 3 ++-
>  1 file changed, 2 insertions(+), 1 deletion(-)
> 
> diff --git a/drivers/gpu/drm/panthor/panthor_fw.c 
> b/drivers/gpu/drm/panthor/panthor_fw.c
> index 6335893d3f16..9d0e1fafdce2 100644
> --- a/drivers/gpu/drm/panthor/panthor_fw.c
> +++ b/drivers/gpu/drm/panthor/panthor_fw.c
> @@ -709,7 +709,8 @@ static int panthor_fw_read_build_info(struct 
> panthor_device *ptdev,
>               return ret;
>  
>       if (hdr.meta_start > fw->size ||
> -         hdr.meta_start + hdr.meta_size > fw->size) {
> +         hdr.meta_size > fw->size - hdr.meta_start ||
> +         hdr.meta_size <= header_len) {
>               drm_err(&ptdev->base, "Firmware build info corrupt\n");
>               /* We don't need the build info, so continue */
>               return 0;

Reply via email to