Commit c0837b9cf6ea for kernel

commit c0837b9cf6eabbad8b8cbddaff1a46a6d0a2e29d
Author: Muhammad Bilal <meatuni001@gmail.com>
Date:   Sat May 23 19:08:43 2026 +0000

    accel/ethosu: fix OOB write in ethosu_gem_cmdstream_copy_and_validate()

    The command stream parsing loop increments the index variable a second
    time when a 64-bit command word is encountered (bit 14 set), but does
    not re-check the loop bound before writing the second word:

        for (i = 0; i < size / 4; i++) {
            bocmds[i] = cmds[0];
            if (cmd & 0x4000) {
                i++;
                bocmds[i] = cmds[1];   /* unchecked */
            }
        }

    The buffer bocmds is backed by a DMA allocation of exactly size bytes
    from drm_gem_dma_create(ddev, size), giving valid indices [0, size/4-1].

    When i == size/4 - 1 on entry to an iteration and bit 14 of cmds[0] is
    set, bocmds[size/4-1] is written in bounds, i is then incremented to
    size/4, and bocmds[size/4] writes four bytes past the end of the
    allocation.

    Userspace controls both the buffer contents and the size argument via
    the ioctl, making this a userspace-triggerable heap out-of-bounds write.

    Fix by checking the incremented index against the buffer bound before
    the second write and returning -EINVAL if the buffer is too small to
    contain the extended command.

    Fixes: 5a5e9c0228e6 ("accel: Add Arm Ethos-U NPU driver")
    Cc: stable@vger.kernel.org
    Signed-off-by: Muhammad Bilal <meatuni001@gmail.com>
    Link: https://patch.msgid.link/20260523190843.33977-1-meatuni001@gmail.com
    Signed-off-by: Rob Herring (Arm) <robh@kernel.org>

diff --git a/drivers/accel/ethosu/ethosu_gem.c b/drivers/accel/ethosu/ethosu_gem.c
index 2cb7964ddfa5..3401883e207f 100644
--- a/drivers/accel/ethosu/ethosu_gem.c
+++ b/drivers/accel/ethosu/ethosu_gem.c
@@ -401,6 +401,8 @@ static int ethosu_gem_cmdstream_copy_and_validate(struct drm_device *ddev,
 				return -EFAULT;

 			i++;
+			if (i >= size / 4)
+				return -EINVAL;
 			bocmds[i] = cmds[1];
 			addr = cmd_to_addr(cmds);
 		}