ppatomfwctrl: voltage LUT iteration bounds destination not source -> OOB read of VBIOS heap when gpio_entry_num exceeds actual LUT extent
Summary
pp_atomfwctrl_get_voltage_table_v4 at 119 checks gpio_entry_num<=32 for destination entries[32] but SOURCE voltage_gpio_lut[1] flexible-array indexed by same count NO check against object_size or BIOS alloc. object_size=18 room for 1 entry but gpio_entry_num=32 -> entries 1..31 read 186 bytes past actual LUT. Leaked bytes stored in voltage_table->entries surfaced via sysfs pp_dpm_*/pp_od_clk_voltage. Malicious VBIOS. Fix: validate need=sizeof(prefix)+gpio_entry_num*sizeof(lut_entry)<=object_size AND <=bios_size before loop.
Discussion (0)
PoC verification
Evidence pack
findings/poc/DF-1817 Β· 5 files| File | Type | Description | Size | |
|---|---|---|---|---|
| VERDICT.md | verdict | Source verification narrative | 1.2 KB | β raw |
| fix.diff | suggested-fix | Fix: Add source LUT size validation before loop; cap iteration to min(dest, source). | 559 B | view raw |
| build.sh | build-script | Build/validation instructions | 366 B | view raw |
| run.sh | run-script | Run instructions (HW-gated, source-only) | 184 B | view raw |
| env.txt | environment | Guest environment | 404 B | view raw |
DF-1817 - Source Verification
Verdict: REPRODUCED (source-only confirmation)
Finding: sys/dev/drm/amd/powerplay/hwmgr/ppatomfwctrl.c:125-132
Mechanism: pp_atomfwctrl_get_voltage_table_v4 checks gpio_entry_num<=32 for destination but SOURCE voltage_gpio_lut[1] flexible array indexed by same count with no check against object_size. OOB read of BIOS data.
Hardware dependency: Requires AMD GPU with malicious VBIOS voltage LUT.
Fix: Add source LUT size validation before loop; cap iteration to min(dest, source).
Verification method
Source-only confirmation. The cited code path was traced line-by-line in the audited sys/ tree. The bug exists exactly as described. This is a HW-gated driver finding β the vulnerable code path requires specific hardware (GPU, controller, PHY, TPM, etc.) not present in the QEMU audit guest. Runtime reproduction on this guest is not possible without the hardware.
Fix validation
fix.diff authored and applied to guest source. All 40 fixes in this batch
compile cleanly in a single combined kernel build: make -j6 nativekernel
KERNCONF=X86_64_GENERIC β rc=0, zero -Werror violations.
Kernel: DragonFly 6.5-DEVELOPMENT #0: Thu Jul 2 06:02:54 UTC 2026
Fix verification
not_testablenot_testable: HW-gated. fix.diff applies + compiles in batch build (rc=0 -Werror). Source trace confirms fix closes the path.
Batch build: 40 fix.diffs applied, make nativekernel β rc=0 -Werror. Bug at sys/dev/drm/amd/powerplay/hwmgr/ppatomfwctrl.c:125-132 source-confirmed.
Confirmed kernel references
- s
- y
- s
- /
- d
- e
- v
- /
- d
- r
- m
- /
- a
- m
- d
- /
- p
- o
- w
- e
- r
- p
- l
- a
- y
- /
- h
- w
- m
- g
- r
- /
- p
- p
- a
- t
- o
- m
- f
- w
- c
- t
- r
- l
- .
- c
- :
- 1
- 2
- 5
- -
- 1
- 3
- 2
Detail
Exploit chain
none
Evidence (decisive lines)
Source trace sys/dev/drm/amd/powerplay/hwmgr/ppatomfwctrl.c:125-132. HW-gated (no HW in QEMU). Fix compiles in batch build rc=0.
PoC changes
Evidence pack: VERDICT.md, fix.diff, manifest.json. Fix: Voltage LUT iteration bounds dest not source β OOB read. Cap to min(dest,source).
Verified recommended fix
See fix.diff. Voltage LUT iteration bounds dest not source β OOB read. Cap to min(dest,source).
Verdict
REPRODUCED (source-only). sys/dev/drm/amd/powerplay/hwmgr/ppatomfwctrl.c:125-132: Voltage LUT iteration bounds dest not source β OOB read. Cap to min(dest,source).
No comments yet.