diff options
| author | Osama Abdelkader <osama.abdelkader@gmail.com> | 2026-07-20 13:49:17 +0200 |
|---|---|---|
| committer | Steven Price <steven.price@arm.com> | 2026-07-29 16:15:47 +0100 |
| commit | b921b8613790a3f9e78ab64017fa7149ef0b750c (patch) | |
| tree | 0efbb9247d3434e6d6190f4f8d08578649434a83 /tools/perf/scripts/python/bin/flamegraph-record | |
| parent | c256bd486855d8948aff29e0c97d50712da4e85e (diff) | |
drm/panthor: validate firmware interface structure sizes
iface_fw_to_cpu_addr() only checks that the firmware-provided MCU virtual
address points inside the shared section. The returned pointer is later
used as a full firmware interface structure, so accepting an address near
the end of the shared section can still lead to out-of-bounds accesses.
Pass the expected object size to iface_fw_to_cpu_addr() and reject ranges
that do not fit entirely in the shared section.
Fixes: 2718d91816ee ("drm/panthor: Add the FW logical block")
Cc: stable@vger.kernel.org
Signed-off-by: Osama Abdelkader <osama.abdelkader@gmail.com>
Reviewed-by: Steven Price <steven.price@arm.com>
Signed-off-by: Steven Price <steven.price@arm.com>
Link: https://patch.msgid.link/20260720114918.15973-1-osama.abdelkader@gmail.com
Diffstat (limited to 'tools/perf/scripts/python/bin/flamegraph-record')
0 files changed, 0 insertions, 0 deletions
