summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorYudi Yang <2000jedi@gmail.com>2026-09-01 14:55:11 -0500
committerHeiko Stuebner <heiko@sntech.de>2026-09-03 15:59:56 +0200
commitbc69439d983cc491cc86e01fafc1deb94e1bb85e (patch)
tree6d8597eacdb8fd0d7c20b4d6c01a201fa31a7a59
parentd3609b540838945ab2ca5b65f32a2eb67bb284c8 (diff)
downloadlinux-next-bc69439d983cc491cc86e01fafc1deb94e1bb85e.tar.gz
linux-next-bc69439d983cc491cc86e01fafc1deb94e1bb85e.zip
drm/rockchip: analogix_dp: fix unchecked bound endpoint name length
rockchip_dp_drm_encoder_enable() uses sprintf() to format a device tree path into a 32-byte stack buffer. Device tree paths are not limited to this size, so a sufficiently long path can overflow the buffer. Use snprintf() with the destination size to truncate the generated name and keep the writes within bounds. Fixes: 729f8eefdcad ("drm/rockchip: analogix_dp: Add support for RK3588") Cc: stable@vger.kernel.org Signed-off-by: Yudi Yang <2000jedi@gmail.com> Signed-off-by: Heiko Stuebner <heiko@sntech.de> Link: https://patch.msgid.link/20260901195511.2761251-1-2000jedi@gmail.com
-rw-r--r--drivers/gpu/drm/rockchip/analogix_dp-rockchip.c7
1 files changed, 4 insertions, 3 deletions
diff --git a/drivers/gpu/drm/rockchip/analogix_dp-rockchip.c b/drivers/gpu/drm/rockchip/analogix_dp-rockchip.c
index 587e60232ec7..efd5a98e80bd 100644
--- a/drivers/gpu/drm/rockchip/analogix_dp-rockchip.c
+++ b/drivers/gpu/drm/rockchip/analogix_dp-rockchip.c
@@ -241,10 +241,11 @@ static void rockchip_dp_drm_encoder_enable(struct drm_encoder *encoder,
of_graph_get_remote_port(endpoint.local_node);
of_property_read_u32(remote_port, "reg", &port_id);
- sprintf(name, "%s vp%d", remote_port_parent->full_name, port_id);
+ snprintf(name, sizeof(name), "%s vp%d",
+ remote_port_parent->full_name, port_id);
} else {
- sprintf(name, "%s %s",
- remote_port_parent->full_name, endpoint.id ? "vopl" : "vopb");
+ snprintf(name, sizeof(name), "%s %s",
+ remote_port_parent->full_name, endpoint.id ? "vopl" : "vopb");
}
DRM_DEV_DEBUG(dp->dev, "vop %s output to dp\n", (ret) ? "LIT" : "BIG");