* [PATCH 6.6.y] drm/i915/hdcp: Add encoder check in intel_hdcp_get_capability
@ 2026-09-29 3:17 Artem Dinaburg
2026-09-29 18:50 ` Sasha Levin
0 siblings, 1 reply; 2+ messages in thread
From: Artem Dinaburg @ 2026-09-29 3:17 UTC (permalink / raw)
To: stable
Cc: Artem Dinaburg, Greg Kroah-Hartman, Sasha Levin, Suraj Kandpal,
Dnyaneshwar Bhadane, Jani Nikula, Joonas Lahtinen, Rodrigo Vivi,
Tvrtko Ursulin, David Airlie, Daniel Vetter, intel-gfx,
dri-devel, linux-kernel, Tvrtko Ursulin, Simona Vetter, intel-xe
From: Suraj Kandpal <suraj.kandpal@intel.com>
[ Upstream commit 31b42af516afa1e184d1a9f9dd4096c54044269a ]
Sometimes during hotplug scenario or suspend/resume scenario encoder is
not always initialized when intel_hdcp_get_capability add
a check to avoid kernel null pointer dereference.
Signed-off-by: Suraj Kandpal <suraj.kandpal@intel.com>
Reviewed-by: Dnyaneshwar Bhadane <dnyaneshwar.bhadane@intel.com>
Link: https://patchwork.freedesktop.org/patch/msgid/20240722064451.3610512-2-suraj.kandpal@intel.com
Assisted-by: LLM
Signed-off-by: Artem Dinaburg <artem@trailofbits.com>
---
Hi Greg, Sasha, and drm i915 maintainers,
I am working through the small CVE backports still missing from 6.6.y.
This one addresses CVE-2024-53051. It rejects the HDCP capability query
when hotplug or resume left the encoder unset.
The fix is already present in 6.12.y, 6.18.y, and 7.2.y, but not in 6.6.y.
This fix also affects 6.1.y, which will need a separate backport; this
submission contains only the 6.6.y patch.
The code change is identical to upstream.
Could you please queue it for 6.6.y?
CVE: CVE-2024-53051
Upstream: 31b42af516afa1e184d1a9f9dd4096c54044269a
AI assistance: An LLM helped identify, adapt, and validate this backport; I
reviewed the resulting code and validation evidence.
Thanks,
Artem Dinaburg
drivers/gpu/drm/i915/display/intel_hdcp.c | 7 ++++++-
1 file changed, 6 insertions(+), 1 deletion(-)
diff --git a/drivers/gpu/drm/i915/display/intel_hdcp.c b/drivers/gpu/drm/i915/display/intel_hdcp.c
index f377c4484e1857..f7987fb90bb1ac 100644
--- a/drivers/gpu/drm/i915/display/intel_hdcp.c
+++ b/drivers/gpu/drm/i915/display/intel_hdcp.c
@@ -142,11 +142,16 @@ int intel_hdcp_read_valid_bksv(struct intel_digital_port *dig_port,
/* Is HDCP1.4 capable on Platform and Sink */
bool intel_hdcp_capable(struct intel_connector *connector)
{
- struct intel_digital_port *dig_port = intel_attached_dig_port(connector);
+ struct intel_digital_port *dig_port;
const struct intel_hdcp_shim *shim = connector->hdcp.shim;
bool capable = false;
u8 bksv[5];
+ if (!intel_attached_encoder(connector))
+ return capable;
+
+ dig_port = intel_attached_dig_port(connector);
+
if (!shim)
return capable;
--
2.39.5
^ permalink raw reply [flat|nested] 2+ messages in thread* Re: [PATCH 6.6.y] drm/i915/hdcp: Add encoder check in intel_hdcp_get_capability
2026-09-29 3:17 [PATCH 6.6.y] drm/i915/hdcp: Add encoder check in intel_hdcp_get_capability Artem Dinaburg
@ 2026-09-29 18:50 ` Sasha Levin
0 siblings, 0 replies; 2+ messages in thread
From: Sasha Levin @ 2026-09-29 18:50 UTC (permalink / raw)
To: stable
Cc: Sasha Levin, Artem Dinaburg, Greg Kroah-Hartman, Suraj Kandpal,
Dnyaneshwar Bhadane, Jani Nikula, Joonas Lahtinen, Rodrigo Vivi,
Tvrtko Ursulin, David Airlie, Daniel Vetter, intel-gfx,
dri-devel, linux-kernel, Tvrtko Ursulin, Simona Vetter, intel-xe
> bool intel_hdcp_capable(struct intel_connector *connector)
> {
> - struct intel_digital_port *dig_port = intel_attached_dig_port(connector);
> + struct intel_digital_port *dig_port;
[...]
> + if (!intel_attached_encoder(connector))
> + return capable;
On 6.6 this doesn't stop the oops. The debugfs intel_hdcp_info() calls
intel_hdcp2_capable() right after intel_hdcp_capable(), and
intel_hdcp2_capable() still starts with intel_attached_dig_port(connector)
without an encoder check, so the NULL deref just moves one call later.
Upstream fixed that half in d34f4f058edf ("drm/i915/hdcp: Add encoder
check in hdcp2_get_capability"), CVE-2024-53050. Its CVE record says the
bug arrived in 6.7, but 130849f8ec14 ("drm/i915/hdcp: Use intel_connector
as argument for hdcp_2_2_capable") only moved the deref into the DP/HDMI
shims. 6.6 still has it in intel_hdcp2_capable() itself.
Could you resend this as a 2-patch 6.6.y series: this backport plus a 6.6
adaptation of the hdcp2 fix that guards intel_hdcp2_capable()?
--
Thanks,
Sasha
^ permalink raw reply [flat|nested] 2+ messages in thread
end of thread, other threads:[~2026-09-29 18:51 UTC | newest]
Thread overview: 2+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-09-29 3:17 [PATCH 6.6.y] drm/i915/hdcp: Add encoder check in intel_hdcp_get_capability Artem Dinaburg
2026-09-29 18:50 ` Sasha Levin
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®