RE: [PATCH] drm/amdkfd: Add bounds check for CRAT subtype length

"Liu, Alysa" <[email protected]>
Newsgroups org.freedesktop.lists.amd-gfx
Message-ID <CH2PR12MB4055F2F1046C6C805042AFA1E5F82@CH2PR12MB4055.namprd12.prod.outlook.com>
AMD General

Reviewed-by: Alysa Liu <[email protected]>

-----Original Message-----
From: Palacek, William <[email protected]>
Sent: Wednesday, July 15, 2026 9:40 AM
To: [email protected]
Cc: Kasiviswanathan, Harish <[email protected]>; Liu, Alysa <[email protected]>; Palacek, William <[email protected]>
Subject: [PATCH] drm/amdkfd: Add bounds check for CRAT subtype length

The CRAT parser validates that the subtype header fits within the image, but does not verify that the advertised subtype length fits. A malformed CRAT table with an oversized length field causes out-of-bounds reads when
kfd_parse_subtype() casts the header to specific subtype structures.

Add validation that sub_type_hdr + length does not exceed the image boundary before parsing the subtype contents.

Signed-off-by: William Palacek <[email protected]>
---
 drivers/gpu/drm/amd/amdkfd/kfd_crat.c | 9 +++++++++
 1 file changed, 9 insertions(+)

diff --git a/drivers/gpu/drm/amd/amdkfd/kfd_crat.c b/drivers/gpu/drm/amd/amdkfd/kfd_crat.c
index 2a239f45fc24..6e0df685503d 100644
--- a/drivers/gpu/drm/amd/amdkfd/kfd_crat.c
+++ b/drivers/gpu/drm/amd/amdkfd/kfd_crat.c
@@ -1412,6 +1412,15 @@ int kfd_parse_crat_table(void *crat_image, struct list_head *device_list,
                        break;
                }

+               /* Validate subtype fits within remaining image */
+               if ((char *)sub_type_hdr + sub_type_hdr->length >
+                   (char *)crat_image + image_len) {
+                       pr_warn("CRAT subtype length %u exceeds image bounds\n",
+                               sub_type_hdr->length);
+                       ret = -EINVAL;
+                       break;
+               }
+
                if (sub_type_hdr->flags & CRAT_SUBTYPE_FLAGS_ENABLED) {
                        ret = kfd_parse_subtype(sub_type_hdr, device_list);
                        if (ret)
--
2.34.1
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.