On 29/07/2026 10:45, [email protected] wrote:
From: Shixiong Ou <[email protected]>

drm_log_draw_kmsg_record() accesses s[len - 1] to strip the trailing
newline, but len is unsigned int. If len is 0, the subtraction wraps
to UINT_MAX, causing an out-of-bounds read.

Add an early return when len is 0.

Thanks, for your contribution

Reviewed-by: Jocelyn Falempe <[email protected]>


Signed-off-by: Shixiong Ou <[email protected]>
---
  drivers/gpu/drm/clients/drm_log.c | 3 +++
  1 file changed, 3 insertions(+)

diff --git a/drivers/gpu/drm/clients/drm_log.c 
b/drivers/gpu/drm/clients/drm_log.c
index e3e02c84a4cf..294b3be1a6b3 100644
--- a/drivers/gpu/drm/clients/drm_log.c
+++ b/drivers/gpu/drm/clients/drm_log.c
@@ -162,6 +162,9 @@ static void drm_log_draw_kmsg_record(struct drm_log_scanout 
*scanout,
  {
        u32 prefix_len = 0;
+ if (!len)
+               return;
+
        if (len > TS_PREFIX_LEN && s[0] == '[' && s[6] == '.' && 
s[TS_PREFIX_LEN] == ']')
                prefix_len = TS_PREFIX_LEN + 1;

Reply via email to