* [PATCH 6.6.y] drm/mediatek: Fix potential NULL dereference in mtk_crtc_destroy()
@ 2026-09-29 3:19 Artem Dinaburg
0 siblings, 0 replies; only message in thread
From: Artem Dinaburg @ 2026-09-29 3:19 UTC (permalink / raw)
To: stable
Cc: Artem Dinaburg, Greg Kroah-Hartman, Sasha Levin, Dan Carpenter,
AngeloGioacchino Del Regno, CK Hu, Chun-Kuang Hu, Philipp Zabel,
David Airlie, Daniel Vetter, Matthias Brugger, dri-devel,
linux-mediatek, linux-kernel, linux-arm-kernel, Simona Vetter,
jason-jh.lin
From: Dan Carpenter <dan.carpenter@linaro.org>
[ Upstream commit 4018651ba5c409034149f297d3dd3328b91561fd ]
In mtk_crtc_create(), if the call to mbox_request_channel() fails then we
set the "mtk_crtc->cmdq_client.chan" pointer to NULL. In that situation,
we do not call cmdq_pkt_create().
During the cleanup, we need to check if the "mtk_crtc->cmdq_client.chan"
is NULL first before calling cmdq_pkt_destroy(). Calling
cmdq_pkt_destroy() is unnecessary if we didn't call cmdq_pkt_create() and
it will result in a NULL pointer dereference.
[ Backport to 6.6.y: used the older Mediatek CRTC file and helper names. ]
Fixes: 7627122fd1c0 ("drm/mediatek: Add cmdq_handle in mtk_crtc")
Signed-off-by: Dan Carpenter <dan.carpenter@linaro.org>
Reviewed-by: AngeloGioacchino Del Regno <angelogioacchino.delregno@collabora.com>
Reviewed-by: CK Hu <ck.hu@mediatek.com>
Link: https://patchwork.kernel.org/project/dri-devel/patch/cc537bd6-837f-4c85-a37b-1a007e268310@stanley.mountain/
Signed-off-by: Chun-Kuang Hu <chunkuang.hu@kernel.org>
Assisted-by: LLM
Signed-off-by: Artem Dinaburg <artem@trailofbits.com>
---
Hi Greg, Sasha, and drm mediatek maintainers,
I am working through the small CVE backports still missing from 6.6.y.
This one addresses CVE-2024-53056. It skips command-packet destruction when
channel setup failed before packet creation.
The fix is already present in 6.12.y, 6.18.y, and 7.2.y, but not in 6.6.y.
This fix also affects 6.1.y, which will need a separate backport; this
submission contains only the 6.6.y patch.
The target-specific adjustment is recorded in the bracketed note above.
Could you please queue it for 6.6.y?
CVE: CVE-2024-53056
Upstream: 4018651ba5c409034149f297d3dd3328b91561fd
AI assistance: An LLM helped identify, adapt, and validate this backport; I
reviewed the resulting code and validation evidence.
Thanks,
Artem Dinaburg
drivers/gpu/drm/mediatek/mtk_drm_crtc.c | 3 +--
1 file changed, 1 insertion(+), 2 deletions(-)
diff --git a/drivers/gpu/drm/mediatek/mtk_drm_crtc.c b/drivers/gpu/drm/mediatek/mtk_drm_crtc.c
index 859dffe4513722..1e8052a0425ee5 100644
--- a/drivers/gpu/drm/mediatek/mtk_drm_crtc.c
+++ b/drivers/gpu/drm/mediatek/mtk_drm_crtc.c
@@ -163,9 +163,8 @@ static void mtk_drm_crtc_destroy(struct drm_crtc *crtc)
mtk_mutex_put(mtk_crtc->mutex);
#if IS_REACHABLE(CONFIG_MTK_CMDQ)
- mtk_drm_cmdq_pkt_destroy(&mtk_crtc->cmdq_handle);
-
if (mtk_crtc->cmdq_client.chan) {
+ mtk_drm_cmdq_pkt_destroy(&mtk_crtc->cmdq_handle);
mbox_free_channel(mtk_crtc->cmdq_client.chan);
mtk_crtc->cmdq_client.chan = NULL;
}
--
2.39.5
^ permalink raw reply [flat|nested] only message in thread
only message in thread, other threads:[~2026-09-29 3:19 UTC | newest]
Thread overview: (only message) (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-09-29 3:19 [PATCH 6.6.y] drm/mediatek: Fix potential NULL dereference in mtk_crtc_destroy() Artem Dinaburg
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®