summaryrefslogtreecommitdiffstats
path: root/tools
diff options
context:
space:
mode:
authorZheyu Ma <zheyuma97@gmail.com>2022-08-03 17:23:12 +0800
committerGreg Kroah-Hartman <gregkh@linuxfoundation.org>2022-08-25 11:11:26 +0200
commit76b3f0a0b56e53a960a14624a0f48b3d94b5e7e7 (patch)
treef368c1de4f895e0a61b5572981e120cb58637835 /tools
parent26baff5a7d748211eea15ef7a5779747eb2cbed4 (diff)
downloadlinux-stable-76b3f0a0b56e53a960a14624a0f48b3d94b5e7e7.tar.gz
linux-stable-76b3f0a0b56e53a960a14624a0f48b3d94b5e7e7.tar.bz2
linux-stable-76b3f0a0b56e53a960a14624a0f48b3d94b5e7e7.zip
video: fbdev: arkfb: Fix a divide-by-zero bug in ark_set_pixclock()
[ Upstream commit 2f1c4523f7a3aaabe7e53d3ebd378292947e95c8 ] Since the user can control the arguments of the ioctl() from the user space, under special arguments that may result in a divide-by-zero bug in: drivers/video/fbdev/arkfb.c:784: ark_set_pixclock(info, (hdiv * info->var.pixclock) / hmul); with hdiv=1, pixclock=1 and hmul=2 you end up with (1*1)/2 = (int) 0. and then in: drivers/video/fbdev/arkfb.c:504: rv = dac_set_freq(par->dac, 0, 1000000000 / pixclock); we'll get a division-by-zero. The following log can reveal it: divide error: 0000 [#1] PREEMPT SMP KASAN PTI RIP: 0010:ark_set_pixclock drivers/video/fbdev/arkfb.c:504 [inline] RIP: 0010:arkfb_set_par+0x10fc/0x24c0 drivers/video/fbdev/arkfb.c:784 Call Trace: fb_set_var+0x604/0xeb0 drivers/video/fbdev/core/fbmem.c:1034 do_fb_ioctl+0x234/0x670 drivers/video/fbdev/core/fbmem.c:1110 fb_ioctl+0xdd/0x130 drivers/video/fbdev/core/fbmem.c:1189 Fix this by checking the argument of ark_set_pixclock() first. Fixes: 681e14730c73 ("arkfb: new framebuffer driver for ARK Logic cards") Signed-off-by: Zheyu Ma <zheyuma97@gmail.com> Signed-off-by: Helge Deller <deller@gmx.de> Signed-off-by: Sasha Levin <sashal@kernel.org>
Diffstat (limited to 'tools')
0 files changed, 0 insertions, 0 deletions