From 0c5e316fe953d411fba627e8ac752f1fb9343f40 Mon Sep 17 00:00:00 2001 From: Prashant Singh Date: Thu, 13 Jun 2019 17:51:14 +0530 Subject: [PATCH] disp: msm: add array out of bounds index check Add check for plane used as index on accessing for bytes per pixel value. Change-Id: I3642f9a57bf2eee7fa0dbf0965bd8497f3911e18 Signed-off-by: Prashant Singh --- msm/msm_fb.c | 8 +++++++- 1 file changed, 7 insertions(+), 1 deletion(-) diff --git a/msm/msm_fb.c b/msm/msm_fb.c index 66ae54e6f12f..ddc699e5e864 100644 --- a/msm/msm_fb.c +++ b/msm/msm_fb.c @@ -375,11 +375,17 @@ struct drm_framebuffer *msm_framebuffer_init(struct drm_device *dev, goto fail; } } else { + const struct drm_format_info *info; + + info = drm_format_info(mode_cmd->pixel_format); + if (!info || num_planes > ARRAY_SIZE(info->cpp)) + goto fail; + for (i = 0; i < num_planes; i++) { unsigned int width = mode_cmd->width / (i ? hsub : 1); unsigned int height = mode_cmd->height / (i ? vsub : 1); unsigned int min_size; - unsigned int cpp; + unsigned int cpp = 0; cpp = drm_format_plane_cpp(mode_cmd->pixel_format, i);