* [PATCH] drm/amdgpu: fix a possible null pointer dereference
@ 2024-06-22 8:22 Ma Ke
2024-06-22 14:26 ` Markus Elfring
2024-06-23 9:20 ` Joshua Ashton
0 siblings, 2 replies; 3+ messages in thread
From: Ma Ke @ 2024-06-22 8:22 UTC (permalink / raw)
To: alexander.deucher, christian.koenig, Xinhui.Pan, airlied, daniel,
srinivasan.shanmugam, aurabindo.pillai, make24, guchun.chen,
chenjiahao16
Cc: amd-gfx, dri-devel, linux-kernel
In amdgpu_connector_add_common_modes(), the return value of drm_cvt_mode()
is assigned to mode, which will lead to a NULL pointer dereference on
failure of drm_cvt_mode(). Add a check to avoid npd.
Signed-off-by: Ma Ke <make24@iscas.ac.cn>
---
drivers/gpu/drm/amd/amdgpu/amdgpu_connectors.c | 2 ++
1 file changed, 2 insertions(+)
diff --git a/drivers/gpu/drm/amd/amdgpu/amdgpu_connectors.c b/drivers/gpu/drm/amd/amdgpu/amdgpu_connectors.c
index 9caba10315a8..6cf946adb6fe 100644
--- a/drivers/gpu/drm/amd/amdgpu/amdgpu_connectors.c
+++ b/drivers/gpu/drm/amd/amdgpu/amdgpu_connectors.c
@@ -458,6 +458,8 @@ static void amdgpu_connector_add_common_modes(struct drm_encoder *encoder,
continue;
mode = drm_cvt_mode(dev, common_modes[i].w, common_modes[i].h, 60, false, false, false);
+ if (!mode)
+ continue;
drm_mode_probed_add(connector, mode);
}
}
--
2.25.1
^ permalink raw reply [flat|nested] 3+ messages in thread
* Re: [PATCH] drm/amdgpu: fix a possible null pointer dereference
2024-06-22 8:22 [PATCH] drm/amdgpu: fix a possible null pointer dereference Ma Ke
@ 2024-06-22 14:26 ` Markus Elfring
2024-06-23 9:20 ` Joshua Ashton
1 sibling, 0 replies; 3+ messages in thread
From: Markus Elfring @ 2024-06-22 14:26 UTC (permalink / raw)
To: Ma Ke, amd-gfx, dri-devel, Alex Deucher, Aurabindo Pillai,
Chen Jiahao, Christian König, Daniel Vetter, David Airlie,
Guchun Chen, Srinivasan Shanmugam, Xinhui Pan
Cc: LKML
> In amdgpu_connector_add_common_modes(), the return value of drm_cvt_mode()
> is assigned to mode, which will lead to a NULL pointer dereference on
> failure of drm_cvt_mode(). Add a check to avoid npd.
Can a wording approach (like the following) be a better change description?
A null pointer is stored in the local variable “mode” after a call
of the function “drm_cvt_mode” failed. This pointer was passed to
a subsequent call of the function “drm_mode_probed_add” where an undesirable
dereference will be performed then.
Thus add a corresponding return value check.
Would you like to add any tags (like “Fixes”) accordingly?
How do you think about to use a summary phrase like “Avoid null pointer dereference
in amdgpu_connector_add_common_modes()”?
Regards,
Markus
^ permalink raw reply [flat|nested] 3+ messages in thread
* Re: [PATCH] drm/amdgpu: fix a possible null pointer dereference
2024-06-22 8:22 [PATCH] drm/amdgpu: fix a possible null pointer dereference Ma Ke
2024-06-22 14:26 ` Markus Elfring
@ 2024-06-23 9:20 ` Joshua Ashton
1 sibling, 0 replies; 3+ messages in thread
From: Joshua Ashton @ 2024-06-23 9:20 UTC (permalink / raw)
To: amd-gfx, Ma Ke, alexander.deucher, christian.koenig, Xinhui.Pan,
airlied, daniel, srinivasan.shanmugam, aurabindo.pillai, make24,
guchun.chen, chenjiahao16
Cc: dri-devel, linux-kernel
Are you planning on submitting a bogus CVE for this patch too?
- Joshie 🐸✨
On June 22, 2024 9:22:19 AM GMT+01:00, Ma Ke <make24@iscas.ac.cn> wrote:
>In amdgpu_connector_add_common_modes(), the return value of drm_cvt_mode()
>is assigned to mode, which will lead to a NULL pointer dereference on
>failure of drm_cvt_mode(). Add a check to avoid npd.
>
>Signed-off-by: Ma Ke <make24@iscas.ac.cn>
>---
> drivers/gpu/drm/amd/amdgpu/amdgpu_connectors.c | 2 ++
> 1 file changed, 2 insertions(+)
>
>diff --git a/drivers/gpu/drm/amd/amdgpu/amdgpu_connectors.c b/drivers/gpu/drm/amd/amdgpu/amdgpu_connectors.c
>index 9caba10315a8..6cf946adb6fe 100644
>--- a/drivers/gpu/drm/amd/amdgpu/amdgpu_connectors.c
>+++ b/drivers/gpu/drm/amd/amdgpu/amdgpu_connectors.c
>@@ -458,6 +458,8 @@ static void amdgpu_connector_add_common_modes(struct drm_encoder *encoder,
> continue;
>
> mode = drm_cvt_mode(dev, common_modes[i].w, common_modes[i].h, 60, false, false, false);
>+ if (!mode)
>+ continue;
> drm_mode_probed_add(connector, mode);
> }
> }
^ permalink raw reply [flat|nested] 3+ messages in thread
end of thread, other threads:[~2024-06-23 9:21 UTC | newest]
Thread overview: 3+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2024-06-22 8:22 [PATCH] drm/amdgpu: fix a possible null pointer dereference Ma Ke
2024-06-22 14:26 ` Markus Elfring
2024-06-23 9:20 ` Joshua Ashton
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®