From patchwork Tue Jun 14 09:24:49 2011 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Laurent Pinchart X-Patchwork-Id: 878462 Received: from vger.kernel.org (vger.kernel.org [209.132.180.67]) by demeter2.kernel.org (8.14.4/8.14.4) with ESMTP id p5E9PJ0B004599 for ; Tue, 14 Jun 2011 09:25:21 GMT Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1755893Ab1FNJZP (ORCPT ); Tue, 14 Jun 2011 05:25:15 -0400 Received: from perceval.ideasonboard.com ([95.142.166.194]:58401 "EHLO perceval.ideasonboard.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1755858Ab1FNJZM (ORCPT ); Tue, 14 Jun 2011 05:25:12 -0400 Received: from localhost.localdomain (unknown [91.178.246.59]) by perceval.ideasonboard.com (Postfix) with ESMTPSA id EAF3835B6B; Tue, 14 Jun 2011 09:25:01 +0000 (UTC) From: Laurent Pinchart To: linux-fbdev@vger.kernel.org Cc: Ferenc Bakonyi , Brent Cook Subject: [PATCH v2 11/29] hgafb: use display information in info not in var for panning Date: Tue, 14 Jun 2011 11:24:49 +0200 Message-Id: <1308043507-11083-12-git-send-email-laurent.pinchart@ideasonboard.com> X-Mailer: git-send-email 1.7.3.4 In-Reply-To: <1308043507-11083-1-git-send-email-laurent.pinchart@ideasonboard.com> References: <1308043507-11083-1-git-send-email-laurent.pinchart@ideasonboard.com> Sender: linux-fbdev-owner@vger.kernel.org Precedence: bulk List-ID: X-Mailing-List: linux-fbdev@vger.kernel.org X-Greylist: IP, sender and recipient auto-whitelisted, not delayed by milter-greylist-4.2.6 (demeter2.kernel.org [140.211.167.43]); Tue, 14 Jun 2011 09:25:21 +0000 (UTC) We must not use any information in the passed var besides xoffset, yoffset and vmode as otherwise applications might abuse it. Signed-off-by: Laurent Pinchart Cc: Ferenc Bakonyi Cc: Brent Cook --- drivers/video/hgafb.c | 4 ++-- 1 files changed, 2 insertions(+), 2 deletions(-) diff --git a/drivers/video/hgafb.c b/drivers/video/hgafb.c index 4052718..4394389 100644 --- a/drivers/video/hgafb.c +++ b/drivers/video/hgafb.c @@ -422,8 +422,8 @@ static int hgafb_pan_display(struct fb_var_screeninfo *var, var->xoffset) return -EINVAL; } else { - if (var->xoffset + var->xres > info->var.xres_virtual - || var->yoffset + var->yres > info->var.yres_virtual + if (var->xoffset + info->var.xres > info->var.xres_virtual + || var->yoffset + info->var.yres > info->var.yres_virtual || var->yoffset % 8) return -EINVAL; }