Forwarded: [PATCH] drm/gud: NUL-terminate TV mode names read from the device

From: syzbot

Date: Sun Aug 16 2026 - 04:23:32 EST


For archival purposes, forwarding an incoming command email to
linux-kernel@xxxxxxxxxxxxxxx, syzkaller-bugs@xxxxxxxxxxxxxxxx.

***

Subject: [PATCH] drm/gud: NUL-terminate TV mode names read from the device
Author: kartikey406@xxxxxxxxx

#syz test: git://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git master


gud_connector_add_tv_mode() reads a buffer of fixed-size mode names from
the USB device and passes pointers into it to
drm_mode_create_tv_properties_legacy(), which calls strlen() on each one.
Nothing guarantees the device NUL-terminates a name, so strlen() can run
past the end of a slot and, for the last mode, past the end of the
allocation.

Terminate each name at the end of its slot before use.

Reported-by: syzbot+916c888ba5f1a54c9526@xxxxxxxxxxxxxxxxxxxxxxxxx
Closes: https://syzkaller.appspot.com/bug?extid=916c888ba5f1a54c9526
Signed-off-by: Deepanshu Kartikey <kartikey406@xxxxxxxxx>
---
drivers/gpu/drm/gud/gud_connector.c | 9 +++++++--
1 file changed, 7 insertions(+), 2 deletions(-)

diff --git a/drivers/gpu/drm/gud/gud_connector.c b/drivers/gpu/drm/gud/gud_connector.c
index ea0cca58b7c8..5c0065c876a7 100644
--- a/drivers/gpu/drm/gud/gud_connector.c
+++ b/drivers/gpu/drm/gud/gud_connector.c
@@ -396,8 +396,13 @@ static int gud_connector_add_tv_mode(struct gud_device *gdrm, struct drm_connect
}

num_modes = ret / GUD_CONNECTOR_TV_MODE_NAME_LEN;
- for (i = 0; i < num_modes; i++)
- modes[i] = &buf[i * GUD_CONNECTOR_TV_MODE_NAME_LEN];
+ for (i = 0; i < num_modes; i++) {
+ char *mode = &buf[i * GUD_CONNECTOR_TV_MODE_NAME_LEN];
+
+ /* The device is not trusted to NUL-terminate the name */
+ mode[GUD_CONNECTOR_TV_MODE_NAME_LEN - 1] = '\0';
+ modes[i] = mode;
+ }

ret = drm_mode_create_tv_properties_legacy(connector->dev, num_modes, modes);
free:
--
2.43.0