The CRAT parser validates that the subtype header fits within the image,
but does not verify that the advertised subtype length fits. A malformed
CRAT table with an oversized length field causes out-of-bounds reads when
kfd_parse_subtype() casts the header to specific subtype structures.

Add validation that sub_type_hdr + length does not exceed the image
boundary before parsing the subtype contents.

Signed-off-by: William Palacek <[email protected]>
---
 drivers/gpu/drm/amd/amdkfd/kfd_crat.c | 9 +++++++++
 1 file changed, 9 insertions(+)

diff --git a/drivers/gpu/drm/amd/amdkfd/kfd_crat.c 
b/drivers/gpu/drm/amd/amdkfd/kfd_crat.c
index 2a239f45fc24..6e0df685503d 100644
--- a/drivers/gpu/drm/amd/amdkfd/kfd_crat.c
+++ b/drivers/gpu/drm/amd/amdkfd/kfd_crat.c
@@ -1412,6 +1412,15 @@ int kfd_parse_crat_table(void *crat_image, struct 
list_head *device_list,
                        break;
                }
 
+               /* Validate subtype fits within remaining image */
+               if ((char *)sub_type_hdr + sub_type_hdr->length >
+                   (char *)crat_image + image_len) {
+                       pr_warn("CRAT subtype length %u exceeds image bounds\n",
+                               sub_type_hdr->length);
+                       ret = -EINVAL;
+                       break;
+               }
+
                if (sub_type_hdr->flags & CRAT_SUBTYPE_FLAGS_ENABLED) {
                        ret = kfd_parse_subtype(sub_type_hdr, device_list);
                        if (ret)
-- 
2.34.1

Reply via email to