[PATCH v2 4/5] drm/gud: Fix bulk_len divide-by-zero in gud_flush_damage()
From: Hui Peng
Date: Wed Sep 30 2026 - 03:06:29 EST
In gud_flush_damage(), if pitch or lines is zero (for example, if bulk_len
is smaller than pitch), evaluating lines = gdrm->bulk_len / pitch can
produce lines = 0, triggering a divide-by-zero (Oops: divide error) in
DIV_ROUND_UP(drm_rect_height(damage), lines).
Add checks for !pitch || !lines and !lines before the loop in
gud_flush_damage().
Tested in QEMU against Linux 7.3.0-rc3 by setting bulk_len smaller than
format pitch during damage flush: on the unfixed kernel evaluating
lines = gdrm->bulk_len / pitch produced lines = 0 and triggered
Oops: divide error: 0000 in DIV_ROUND_UP(); whereas with this fix applied,
zero pitch/lines checks return cleanly without faulting.
Fixes: 40e1a70b4aed ("drm: Add GUD USB Display driver")
Cc: stable@xxxxxxxxxxxxxxx
Assisted-by: LLM
Signed-off-by: Hui Peng <benquike@xxxxxxxxx>
---
drivers/gpu/drm/gud/gud_pipe.c | 5 +++++
1 file changed, 5 insertions(+)
diff --git a/drivers/gpu/drm/gud/gud_pipe.c b/drivers/gpu/drm/gud/gud_pipe.c
index aa7792966287..fa726e3d849f 100644
--- a/drivers/gpu/drm/gud/gud_pipe.c
+++ b/drivers/gpu/drm/gud/gud_pipe.c
@@ -340,8 +340,13 @@ static void gud_flush_damage(struct gud_device *gdrm, struct drm_framebuffer *fb
pitch = drm_format_info_min_pitch(format, 0, drm_rect_width(damage));
lines = drm_rect_height(damage);
+ if (!pitch || !lines)
+ return;
+
if (gdrm->bulk_len < lines * pitch)
lines = gdrm->bulk_len / pitch;
+ if (!lines)
+ return;
for (i = 0; i < DIV_ROUND_UP(drm_rect_height(damage), lines); i++) {
struct drm_rect rect = *damage;