On Mon, Jul 6, 2026 at 10:44 AM William Palacek <[email protected]> wrote: > > The CRAT parser validates that the subtype header fits within the image, > but does not verify that the advertised subtype length fits. A malformed > CRAT table with an oversized length field causes out-of-bounds reads when > kfd_parse_subtype() casts the header to specific subtype structures. > > Add validation that sub_type_hdr + length does not exceed the image > boundary before parsing the subtype contents. > > Signed-off-by: William Palacek <[email protected]>
Acked-by: Alex Deucher <[email protected]> > --- > drivers/gpu/drm/amd/amdkfd/kfd_crat.c | 9 +++++++++ > 1 file changed, 9 insertions(+) > > diff --git a/drivers/gpu/drm/amd/amdkfd/kfd_crat.c > b/drivers/gpu/drm/amd/amdkfd/kfd_crat.c > index 2a239f45fc24..6e0df685503d 100644 > --- a/drivers/gpu/drm/amd/amdkfd/kfd_crat.c > +++ b/drivers/gpu/drm/amd/amdkfd/kfd_crat.c > @@ -1412,6 +1412,15 @@ int kfd_parse_crat_table(void *crat_image, struct > list_head *device_list, > break; > } > > + /* Validate subtype fits within remaining image */ > + if ((char *)sub_type_hdr + sub_type_hdr->length > > + (char *)crat_image + image_len) { > + pr_warn("CRAT subtype length %u exceeds image > bounds\n", > + sub_type_hdr->length); > + ret = -EINVAL; > + break; > + } > + > if (sub_type_hdr->flags & CRAT_SUBTYPE_FLAGS_ENABLED) { > ret = kfd_parse_subtype(sub_type_hdr, device_list); > if (ret) > -- > 2.34.1 >
