gud_connector_add_tv_mode() reads a buffer of fixed-size mode names from
the USB device and passes pointers into it to
drm_mode_create_tv_properties_legacy(), which calls strlen() on each one.
Nothing guarantees the device NUL-terminates a name, so strlen() can run
past the end of a slot and, for the last mode, past the end of the
allocation.

Terminate each name at the end of its slot before use.

Fixes: 40e1a70b4aed ("drm: Add GUD USB Display driver")
Reported-by: [email protected]
Closes: https://syzkaller.appspot.com/bug?extid=916c888ba5f1a54c9526
Tested-by: [email protected]
Signed-off-by: Deepanshu Kartikey <[email protected]>
---
 drivers/gpu/drm/gud/gud_connector.c | 9 +++++++--
 1 file changed, 7 insertions(+), 2 deletions(-)

diff --git a/drivers/gpu/drm/gud/gud_connector.c 
b/drivers/gpu/drm/gud/gud_connector.c
index ea0cca58b7c8..5c0065c876a7 100644
--- a/drivers/gpu/drm/gud/gud_connector.c
+++ b/drivers/gpu/drm/gud/gud_connector.c
@@ -396,8 +396,13 @@ static int gud_connector_add_tv_mode(struct gud_device 
*gdrm, struct drm_connect
        }
 
        num_modes = ret / GUD_CONNECTOR_TV_MODE_NAME_LEN;
-       for (i = 0; i < num_modes; i++)
-               modes[i] = &buf[i * GUD_CONNECTOR_TV_MODE_NAME_LEN];
+       for (i = 0; i < num_modes; i++) {
+               char *mode = &buf[i * GUD_CONNECTOR_TV_MODE_NAME_LEN];
+
+               /* The device is not trusted to NUL-terminate the name */
+               mode[GUD_CONNECTOR_TV_MODE_NAME_LEN - 1] = '\0';
+               modes[i] = mode;
+       }
 
        ret = drm_mode_create_tv_properties_legacy(connector->dev, num_modes, 
modes);
 free:
-- 
2.43.0

Reply via email to