From: Alex Hung <[email protected]> [ Upstream commit 687fe329f18ab0ab0496b20ed2cb003d4879d931 ]
[WHY & HOW] tg_inst will be a negative if timing_generator_count equals 0, which should be checked before used. This fixes 2 OVERRUN issues reported by Coverity. [ Backport to 6.6.y: mapped the newer pipe index and helper to i in the older acquire_first_free_pipe(). ] Reviewed-by: Harry Wentland <[email protected]> Acked-by: Tom Chung <[email protected]> Signed-off-by: Alex Hung <[email protected]> Tested-by: Daniel Wheeler <[email protected]> Signed-off-by: Alex Deucher <[email protected]> Assisted-by: LLM Signed-off-by: Artem Dinaburg <[email protected]> --- Hi Greg, Sasha, and drm amd maintainers, I am working through the small CVE backports still missing from 6.6.y. This one addresses CVE-2024-46730. It adds upstream's zero-count guard before the fallback timing-generator index is computed. The condition now avoids forming timing_generators[-1] if a zero-count pool reaches this helper. I did not find a successfully constructed in-tree resource pool with zero timing generators on this revision, so this is a defensive match to the upstream check rather than a reproduced fault. The fix is already present in 6.12.y, 6.18.y, and 7.2.y, but not in 6.6.y. This fix also affects 6.1.y, which will need a separate backport; this submission contains only the 6.6.y patch. The target-specific adjustment is recorded in the bracketed note above. Could you please queue it for 6.6.y? CVE: CVE-2024-46730 Upstream: 687fe329f18ab0ab0496b20ed2cb003d4879d931 AI assistance: An LLM helped identify, adapt, and validate this backport; I reviewed the resulting code and validation evidence. Thanks, Artem Dinaburg drivers/gpu/drm/amd/display/dc/core/dc_resource.c | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/drivers/gpu/drm/amd/display/dc/core/dc_resource.c b/drivers/gpu/drm/amd/display/dc/core/dc_resource.c index 84474d5122284a..1f576b2a1960fd 100644 --- a/drivers/gpu/drm/amd/display/dc/core/dc_resource.c +++ b/drivers/gpu/drm/amd/display/dc/core/dc_resource.c @@ -2354,7 +2354,8 @@ static int acquire_first_free_pipe( pipe_ctx->plane_res.mpcc_inst = pool->dpps[i]->inst; pipe_ctx->pipe_idx = i; - if (i >= pool->timing_generator_count) { + if (i >= pool->timing_generator_count && + pool->timing_generator_count != 0) { int tg_inst = pool->timing_generator_count - 1; pipe_ctx->stream_res.tg = pool->timing_generators[tg_inst]; -- 2.39.5
