drm/amd/display: Reject gpio_bitshift >= 32 in bios_parser_get_gpio_pin_info()

JIRA: https://issues.redhat.com/browse/RHEL-180329

commit 9b0104625451d3931acceabd7c74155764bccf38
Author: Harry Wentland <harry.wentland@amd.com>
Date:   Tue May 5 11:50:07 2026 -0400

    drm/amd/display: Reject gpio_bitshift >= 32 in bios_parser_get_gpio_pin_info()

    commit 49c3da65961fe9857c831d47fa1989084e87514a upstream.

    [Why & How]
    gpio_bitshift is a uint8_t read directly from the VBIOS GPIO pin table.
    If the value is >= 32, the expression "1 << gpio_bitshift" triggers
    undefined behaviour in C (shift count exceeds type width). On x86 the
    shift is silently masked to 5 bits, producing an incorrect GPIO mask
    that may cause wrong MMIO register bits to be toggled.

    Validate gpio_bitshift before use and return BP_RESULT_BADBIOSTABLE for
    out-of-range values.

    Fixes: ae79c310b1 ("drm/amd/display: Add DCE12 bios parser support")
    Assisted-by: Copilot:claude-opus-4.6
    Reviewed-by: Alex Hung <alex.hung@amd.com>
    Signed-off-by: Harry Wentland <harry.wentland@amd.com>
    Signed-off-by: Ray Wu <ray.wu@amd.com>
    Tested-by: Daniel Wheeler <daniel.wheeler@amd.com>
    Signed-off-by: Alex Deucher <alexander.deucher@amd.com>
    (cherry picked from commit eadf438ab8d370b9d19acee9359918c85afeb80d)
    Cc: stable@vger.kernel.org
    Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>

Signed-off-by: Anusha Srivatsa <asrivats@redhat.com>
This commit is contained in:
Anusha Srivatsa
2026-08-03 14:53:57 -05:00
parent 3fb231ff89
commit 3253c878f4
@@ -700,8 +700,10 @@ static enum bp_result bios_parser_get_gpio_pin_info(
info->offset_en = info->offset + 1;
info->offset_mask = info->offset - 1;
info->mask = (uint32_t) (1 <<
header->gpio_pin[i].gpio_bitshift);
if (header->gpio_pin[i].gpio_bitshift >= 32)
return BP_RESULT_BADBIOSTABLE;
info->mask = 1u << header->gpio_pin[i].gpio_bitshift;
info->mask_y = info->mask + 2;
info->mask_en = info->mask + 1;
info->mask_mask = info->mask - 1;