DF-1198 / run.log
== DF-1198 radeon_atombios_parse_power_table_6 harness == state i=1 writes via state_index=0 (alloc for state[0]=1 entries) state i=1 writes via state_index=0 (alloc for state[0]=1 entries) [!] OOB WRITE clock_info[1] into buffer sized 1 (state_index=0) state i=1 writes via state_index=0 (alloc for state[0]=1 entries) [!] OOB WRITE clock_info[2] into buffer sized 1 (state_index=0) state i=1 writes via state_index=0 (alloc for state[0]=1 entries) [!] OOB WRITE clock_info[3] into buffer sized 1 (state_index=0) [BUG REPRODUCED] 3 OOB clock_info writes, victim canary clobbered 48 bytes On a real kernel this overflows power_state[0].clock_info by (N-1)*sizeof(radeon_pm_clock_info) into adjacent heap. RUN_EXIT=0