[PATCH 1/2] drm/radeon: Check the VBIOS signature after copying it from VRAM

From: Imre Kaloz

Date: Sun Sep 27 2026 - 06:57:11 EST


On sparc64 a plain load through an ioremap() cookie is not a valid
access and faults; igp_read_bios_from_vram() does exactly that to check
the VBIOS signature, so radeon KMS never gets past this BIOS-fetch
attempt. Check the memcpy_fromio() copy instead, matching the file's
other paths.

Fixes: b442962a9e82 ("drm/radeon/kms: add support for "Surround View"")
Cc: stable@xxxxxxxxxxxxxxx
Signed-off-by: Imre Kaloz <kaloz@xxxxxxxxxx>
---
drivers/gpu/drm/radeon/radeon_bios.c | 10 ++++++----
1 file changed, 6 insertions(+), 4 deletions(-)

diff --git a/drivers/gpu/drm/radeon/radeon_bios.c b/drivers/gpu/drm/radeon/radeon_bios.c
index 8595f4c6e2e5..a8367e481182 100644
--- a/drivers/gpu/drm/radeon/radeon_bios.c
+++ b/drivers/gpu/drm/radeon/radeon_bios.c
@@ -63,10 +63,6 @@ static bool igp_read_bios_from_vram(struct radeon_device *rdev)
return false;
}

- if (size == 0 || bios[0] != 0x55 || bios[1] != 0xaa) {
- iounmap(bios);
- return false;
- }
rdev->bios = kmalloc(size, GFP_KERNEL);
if (rdev->bios == NULL) {
iounmap(bios);
@@ -74,6 +70,12 @@ static bool igp_read_bios_from_vram(struct radeon_device *rdev)
}
memcpy_fromio(rdev->bios, bios, size);
iounmap(bios);
+
+ if (size == 0 || rdev->bios[0] != 0x55 || rdev->bios[1] != 0xaa) {
+ kfree(rdev->bios);
+ rdev->bios = NULL;
+ return false;
+ }
return true;
}

--
2.47.3