Files
buildroot/package/mesa3d/0009-spirv-Use-STACK_ARRAY-instead-of-NIR_VLA.patch
Quentin Schulz e50c8f179b package/mesa3d: patch CVE-2026-40393
This patches CVE-2026-40393 by backporting the two patches from the
Merge Request listed in the CVE[1]. They don't apply cleanly when
backported. While the conflict is mechanically easy to resolve (simply
a few include directives missing in git context), it's not enough as
src/util/stack_array.h is not present on 24.0.9. Hence the three
additional patches before the patches listed in the Merge Request so
that file actually exists. Technically, only patch 8 is required but
patch 7 make for a conflict-free application of patch 8, itself only
conflict-free if patch 6 is applied.

[1] https://www.cve.org/CVERecord?id=CVE-2026-40393

Signed-off-by: Quentin Schulz <quentin.schulz@cherry.de>
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
2026-06-18 15:07:51 +02:00

109 lines
4.5 KiB
Diff

From 17d07f85828eca081d7fe1bcd9cbbf747fcc1300 Mon Sep 17 00:00:00 2001
From: Ian Romanick <ian.d.romanick@intel.com>
Date: Fri, 23 Jan 2026 09:58:26 -0800
Subject: [PATCH] spirv: Use STACK_ARRAY instead of NIR_VLA
The number of fields comes from the shader, so it could be a value large
enough that using alloca would be problematic.
Fixes: 2a023f30a64 ("nir/spirv: Add basic support for types")
Reviewed-by: Caio Oliveira <caio.oliveira@intel.com>
Reviewed-by: Ryan Neph <ryanneph@google.com>
Reviewed-by: Lionel Landwerlin <lionel.g.landwerlin@intel.com>
(cherry picked from commit 3da828d2dd12e20ba2afc152db8d7236c7a48c13)
Part-of: <https://gitlab.freedesktop.org/mesa/mesa/-/merge_requests/39969>
Upstream: https://gitlab.freedesktop.org/mesa/mesa/-/commit/3db355dc37e823011666767ecc1f9d48bdc6e3a0
[removed changes to .pick_status.json, not applicable to 24.0.9]
[conflict in git context around the added include directive due to
missing 51d3c4c8896a ("spirv: support float8 spec constant op"),
90e1b128903c ("spirv: Add bfloat16 support to SpecConstantOp"),
d21926bc0433 ("spirv: Emit code for NonSemantic.DebugPrintf if
supported"), 221371e9039b ("mesa: replace shader_info::source_sha1")]
CVE: CVE-2026-40393
Signed-off-by: Quentin Schulz <quentin.schulz@cherry.de>
---
src/compiler/spirv/spirv_to_nir.c | 27 +++++++++++++++++----------
1 file changed, 17 insertions(+), 10 deletions(-)
diff --git a/src/compiler/spirv/spirv_to_nir.c b/src/compiler/spirv/spirv_to_nir.c
index f57c9ba42a2..17ae5a64301 100644
--- a/src/compiler/spirv/spirv_to_nir.c
+++ b/src/compiler/spirv/spirv_to_nir.c
@@ -27,7 +27,6 @@
#include "glsl_types.h"
#include "vtn_private.h"
-#include "nir/nir_vla.h"
#include "nir/nir_control_flow.h"
#include "nir/nir_constant_expressions.h"
#include "nir/nir_deref.h"
@@ -37,6 +36,7 @@
#include "util/u_math.h"
#include "util/u_string.h"
#include "util/u_debug.h"
+#include "util/stack_array.h"
#include <stdio.h>
@@ -1013,7 +1013,7 @@ vtn_type_get_nir_type(struct vtn_builder *b, struct vtn_type *type,
case vtn_base_type_struct: {
bool need_new_struct = false;
const uint32_t num_fields = type->length;
- NIR_VLA(struct glsl_struct_field, fields, num_fields);
+ STACK_ARRAY(struct glsl_struct_field, fields, num_fields);
for (unsigned i = 0; i < num_fields; i++) {
fields[i] = *glsl_get_struct_field_data(type->type, i);
const struct glsl_type *field_nir_type =
@@ -1023,20 +1023,25 @@ vtn_type_get_nir_type(struct vtn_builder *b, struct vtn_type *type,
need_new_struct = true;
}
}
+
+ const struct glsl_type *result;
if (need_new_struct) {
if (glsl_type_is_interface(type->type)) {
- return glsl_interface_type(fields, num_fields,
- /* packing */ 0, false,
- glsl_get_type_name(type->type));
+ result = glsl_interface_type(fields, num_fields,
+ /* packing */ 0, false,
+ glsl_get_type_name(type->type));
} else {
- return glsl_struct_type(fields, num_fields,
- glsl_get_type_name(type->type),
- glsl_struct_type_is_packed(type->type));
+ result = glsl_struct_type(fields, num_fields,
+ glsl_get_type_name(type->type),
+ glsl_struct_type_is_packed(type->type));
}
} else {
/* No changes, just pass it on */
- return type->type;
+ result = type->type;
}
+
+ STACK_ARRAY_FINISH(fields);
+ return result;
}
case vtn_base_type_image:
@@ -1647,7 +1652,7 @@ vtn_handle_type(struct vtn_builder *b, SpvOp opcode,
val->type->offsets = vtn_alloc_array(b, unsigned, num_fields);
val->type->packed = false;
- NIR_VLA(struct glsl_struct_field, fields, count);
+ STACK_ARRAY(struct glsl_struct_field, fields, count);
for (unsigned i = 0; i < num_fields; i++) {
val->type->members[i] = vtn_get_type(b, w[i + 2]);
const char *name = NULL;
@@ -1703,6 +1708,8 @@ vtn_handle_type(struct vtn_builder *b, SpvOp opcode,
name ? name : "struct",
val->type->packed);
}
+
+ STACK_ARRAY_FINISH(fields);
break;
}