if supplied msg[2] in the header is too large (around
0x40000000 and above), 4 times of this unsigned 32 bit value
will overflow and the test could pass.

Widen it with uint64_t instead. Also drop the redundant
first check and make the check clear that 6 dwords of
header plus 4 dwords of each msg cannot exceed the overall
packet size in dwords.

Signed-off-by: David (Ming Qiang) Wu <[email protected]>
---
 drivers/gpu/drm/amd/amdgpu/vcn_v3_0.c | 2 +-
 drivers/gpu/drm/amd/amdgpu/vcn_v4_0.c | 2 +-
 2 files changed, 2 insertions(+), 2 deletions(-)

diff --git a/drivers/gpu/drm/amd/amdgpu/vcn_v3_0.c 
b/drivers/gpu/drm/amd/amdgpu/vcn_v3_0.c
index 81bba3ec2a93..06dcf736b15a 100644
--- a/drivers/gpu/drm/amd/amdgpu/vcn_v3_0.c
+++ b/drivers/gpu/drm/amd/amdgpu/vcn_v3_0.c
@@ -1965,7 +1965,7 @@ static int vcn_v3_0_dec_msg(struct amdgpu_cs_parser *p, 
struct amdgpu_job *job,
        num_buffers = msg[2];
 
        /* Verify that all indices fit within the claimed length. Each index is 
4 DWORDs */
-       if (num_buffers > len_dw || 6 + num_buffers * 4 > len_dw) {
+       if ((uint64_t)6 + (uint64_t)num_buffers * 4 > len_dw) {
                DRM_ERROR("VCN message has too many buffers!\n");
                r = -EINVAL;
                goto out;
diff --git a/drivers/gpu/drm/amd/amdgpu/vcn_v4_0.c 
b/drivers/gpu/drm/amd/amdgpu/vcn_v4_0.c
index 0cce78b205a8..7950a020f4e1 100644
--- a/drivers/gpu/drm/amd/amdgpu/vcn_v4_0.c
+++ b/drivers/gpu/drm/amd/amdgpu/vcn_v4_0.c
@@ -1881,7 +1881,7 @@ static int vcn_v4_0_dec_msg(struct amdgpu_cs_parser *p, 
struct amdgpu_job *job,
        num_buffers = msg[2];
 
        /* Verify that all indices fit within the claimed length. Each index is 
4 DWORDs */
-       if (num_buffers > len_dw || 6 + num_buffers * 4 > len_dw) {
+       if ((uint64_t)6 + (uint64_t)num_buffers * 4 > len_dw) {
                DRM_ERROR("VCN message has too many buffers!\n");
                r = -EINVAL;
                goto out;
-- 
2.43.0

Reply via email to