Skip to content

video: video_bmp: fix out-of-bounds write in RLE8 decoder - #944

Open
atkinchris wants to merge 1 commit into
u-boot:masterfrom
atkinchris:master
Open

video: video_bmp: fix out-of-bounds write in RLE8 decoder#944
atkinchris wants to merge 1 commit into
u-boot:masterfrom
atkinchris:master

Conversation

@atkinchris

Copy link
Copy Markdown

Summary

Detail

y starts at height - 1 and decrements. The RLE8 DELTA escape (0x00 0x02 dx dy) subtracts dy from y with no validation, and the EOL handler decrements y unconditionally. Either can drive y negative. The existing bounds checks on encoded runs (y < height) and unencoded runs (y < height) both pass for negative y because the comparisons are signed, so the decoder continues writing through an underflowed framebuffer pointer.

This patch adds bounds checks to the DELTA and EOL handlers to stop decoding when y goes negative, and adds a lower-bound check for y on both run-type code paths.

The same bug exists independently in the Rockchip U-Boot fork's drivers/video/drm/bmp_helper.c, where a fix has been submitted as rockchip-linux/u-boot#100.

video_display_rle8_bitmap() handles the BMP RLE8 DELTA escape and EOL
marker without bounds checking y before writing through the fb pointer.
y starts at height-1 and decrements; a single DELTA can drive it
negative. Subsequent encoded and unencoded run checks use
"if (y < height)" which passes for any negative y (signed comparison),
so the decoder continues writing through an underflowed fb pointer.

Add bounds checks to the DELTA and EOL handlers to stop decoding when y
leaves the image, and add a lower-bound check for y on both the encoded
and unencoded run paths.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant