lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [day] [month] [year] [list]
Message-ID: <20250930120858.251255-1-Pavel.Zhigulin@kaspersky.com>
Date: Tue, 30 Sep 2025 15:08:55 +0300
From: Pavel Zhigulin <Pavel.Zhigulin@...persky.com>
To: Xinliang Liu <xinliang.liu@...aro.org>
CC: Pavel Zhigulin <Pavel.Zhigulin@...persky.com>, Tian Tao
	<tiantao6@...ilicon.com>, Xinwei Kong <kong.kongxinwei@...ilicon.com>, Sumit
 Semwal <sumit.semwal@...aro.org>, Yongqin Liu <yongqin.liu@...aro.org>, John
 Stultz <jstultz@...gle.com>, Maarten Lankhorst
	<maarten.lankhorst@...ux.intel.com>, Maxime Ripard <mripard@...nel.org>,
	Thomas Zimmermann <tzimmermann@...e.de>, David Airlie <airlied@...il.com>,
	Simona Vetter <simona@...ll.ch>, Anusha Srivatsa <asrivats@...hat.com>, Andy
 Green <andy.green@...aro.org>, <dri-devel@...ts.freedesktop.org>,
	<linux-kernel@...r.kernel.org>, <lvc-project@...uxtesting.org>
Subject: [PATCH] gpu: fix potential division by zero in DesignWare controller driver

A division by zero may occur in the dsi_get_phy_params function if
phy_req_kHz is in the range [1000000, 1500000]. In this case,
dsi_calc_phy_rate can return a value greater than 1000000, which sets
the 'ui' variable to zero. The variable is then used as the denominator
in the ROUND macro.

This patch adds an additional check of phy_rate_kHz to prevent 'ui'
from being zero.

Found by Linux Verification Center (linuxtesting.org) with SVACE.

Fixes: f819b0d4a913 ("drm/hisilicon: Add designware dsi encoder driver")
Signed-off-by: Pavel Zhigulin <Pavel.Zhigulin@...persky.com>
---
 drivers/gpu/drm/hisilicon/kirin/dw_drm_dsi.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/drivers/gpu/drm/hisilicon/kirin/dw_drm_dsi.c b/drivers/gpu/drm/hisilicon/kirin/dw_drm_dsi.c
index e80debdc4176..7502a9ddbbf5 100644
--- a/drivers/gpu/drm/hisilicon/kirin/dw_drm_dsi.c
+++ b/drivers/gpu/drm/hisilicon/kirin/dw_drm_dsi.c
@@ -251,7 +251,7 @@ static void dsi_get_phy_params(u32 phy_req_kHz,
 	memset(phy, 0, sizeof(*phy));

 	phy_rate_kHz = dsi_calc_phy_rate(phy_req_kHz, phy);
-	if (!phy_rate_kHz)
+	if (!phy_rate_kHz || phy_rate_kHz > 1000000)
 		return;

 	ui = 1000000 / phy_rate_kHz;
--
2.43.0


Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ