The VFCT path accepted whatever kmemdup() returned without checking that the copied image is a valid VBIOS. Every other radeon BIOS fetch path verifies the 0x55 0xaa signature before trusting the image; the VFCT path is the odd one out.
Check the signature after copying the image and reject it (freeing the buffer) if it does not match, matching the amdgpu VFCT path which validates via check_atom_bios(). Signed-off-by: Mario Limonciello <[email protected]> --- Cc: Oz Tiram <[email protected]> drivers/gpu/drm/radeon/radeon_bios.c | 9 +++++++-- 1 file changed, 7 insertions(+), 2 deletions(-) diff --git a/drivers/gpu/drm/radeon/radeon_bios.c b/drivers/gpu/drm/radeon/radeon_bios.c index cc10880af096b..215e47c94d29e 100644 --- a/drivers/gpu/drm/radeon/radeon_bios.c +++ b/drivers/gpu/drm/radeon/radeon_bios.c @@ -676,9 +676,14 @@ static bool radeon_acpi_vfct_bios(struct radeon_device *rdev) rdev->bios = kmemdup(&vbios->VbiosContent, vhdr->ImageLength, GFP_KERNEL); - if (rdev->bios) - r = true; + if (!rdev->bios || + rdev->bios[0] != 0x55 || rdev->bios[1] != 0xaa) { + kfree(rdev->bios); + rdev->bios = NULL; + goto out; + } + r = true; goto out; } } -- 2.43.0
