AMD General

Series is

Reviewed-by: Hawking Zhang <[email protected]>

Regards,
Hawking
-----Original Message-----
From: Wang, Yang(Kevin) <[email protected]>
Sent: Tuesday, June 23, 2026 11:42
To: [email protected]
Cc: Deucher, Alexander <[email protected]>; Zhang, Hawking 
<[email protected]>; Feng, Kenneth <[email protected]>
Subject: [PATCH 1/5] drm/amd/pm: Validate pp_table header before reading size

smu_sys_set_pp_table() reads usStructureSize from the uploaded pp_table buffer 
before validating that the buffer contains a complete ATOM_COMMON_TABLE_HEADER. 
A short write can therefore make the driver read past the supplied sysfs buffer.

Reject empty or header-short uploads before dereferencing the header.
Keep the existing structure-size check for the full uploaded table.

Signed-off-by: Yang Wang <[email protected]>
---
 drivers/gpu/drm/amd/pm/swsmu/amdgpu_smu.c | 19 +++++++++++--------
 1 file changed, 11 insertions(+), 8 deletions(-)

diff --git a/drivers/gpu/drm/amd/pm/swsmu/amdgpu_smu.c 
b/drivers/gpu/drm/amd/pm/swsmu/amdgpu_smu.c
index d809487205a4..a6e451f1fef3 100644
--- a/drivers/gpu/drm/amd/pm/swsmu/amdgpu_smu.c
+++ b/drivers/gpu/drm/amd/pm/swsmu/amdgpu_smu.c
@@ -667,25 +667,28 @@ static int smu_sys_set_pp_table(void *handle,  {
        struct smu_context *smu = handle;
        struct smu_table_context *smu_table = &smu->smu_table;
-       ATOM_COMMON_TABLE_HEADER *header = (ATOM_COMMON_TABLE_HEADER *)buf;
+       ATOM_COMMON_TABLE_HEADER *header;
+       void *hardcode_pptable;
        int ret = 0;

        if (!smu->pm_enabled || !smu->adev->pm.dpm_enabled)
                return -EOPNOTSUPP;

+       if (!buf || size < sizeof(*header))
+               return -EINVAL;
+
+       header = (ATOM_COMMON_TABLE_HEADER *)buf;
        if (header->usStructureSize != size) {
                dev_err(smu->adev->dev, "pp table size not matched !\n");
                return -EIO;
        }

-       if (!smu_table->hardcode_pptable || smu_table->power_play_table_size < 
size) {
-               kfree(smu_table->hardcode_pptable);
-               smu_table->hardcode_pptable = kzalloc(size, GFP_KERNEL);
-               if (!smu_table->hardcode_pptable)
-                       return -ENOMEM;
-       }
+       hardcode_pptable = kmemdup(buf, size, GFP_KERNEL);
+       if (!hardcode_pptable)
+               return -ENOMEM;

-       memcpy(smu_table->hardcode_pptable, buf, size);
+       kfree(smu_table->hardcode_pptable);
+       smu_table->hardcode_pptable = hardcode_pptable;
        smu_table->power_play_table = smu_table->hardcode_pptable;
        smu_table->power_play_table_size = size;

--
2.47.3

Reply via email to