* [PATCH 6.6.y v2 0/2] drm/i915/hdcp: guard both capability checks
@ 2026-09-30 1:03 Artem Dinaburg
2026-09-30 1:03 ` [PATCH 6.6.y v2 1/2] drm/i915/hdcp: Add encoder check in intel_hdcp_get_capability Artem Dinaburg
2026-09-30 1:03 ` [PATCH 6.6.y v2 2/2] drm/i915/hdcp: Add encoder check in hdcp2_get_capability Artem Dinaburg
0 siblings, 2 replies; 3+ messages in thread
From: Artem Dinaburg @ 2026-09-30 1:03 UTC (permalink / raw)
To: stable
Cc: Artem Dinaburg, Greg Kroah-Hartman, Sasha Levin, Suraj Kandpal,
Dnyaneshwar Bhadane, Jani Nikula, Joonas Lahtinen, Rodrigo Vivi,
Tvrtko Ursulin, Tvrtko Ursulin, David Airlie, Daniel Vetter,
Simona Vetter, intel-gfx, intel-xe, dri-devel, linux-kernel
Hi Greg, Sasha, and i915 maintainers,
Thanks for catching the second dereference.
The code in patch 1 is unchanged from v1.
As Sasha pointed out, on 6.6.y, however, intel_hdcp_info()
calls intel_hdcp_capable() and then intel_hdcp2_capable(). Guarding only
the first helper therefore moves the debugfs NULL dereference to the next
call.
Patch 2 adapts upstream commit d34f4f058edf ("drm/i915/hdcp: Add encoder
check in hdcp2_get_capability") to the older layout. The 6.6.y tree
predates commit 130849f8ec14 ("drm/i915/hdcp: Use intel_connector as
argument for hdcp_2_2_capable"), so its dereference is still in the common
intel_hdcp2_capable() helper rather than the DP and HDMI shims. The
adaptation puts the encoder guard before that dereference and returns
false through the older bool interface.
The CNA record for CVE-2024-53050 starts its affected range at 6.7, but
that range follows the later shim layout. The same unsafe conversion is
already present in the common helper in 6.6.y.
Together, the two patches make both debugfs capability checks return
false before converting the missing encoder to a digital port. Both fixes
entered mainline before v6.12, so every newer supported stable tree
already contains them. The same common HDCP2 dereference is present in
6.1.y and needs separate handling; this series is only for 6.6.y.
Could you please queue both patches for 6.6.y?
An LLM helped adapt and validate both patches; I reviewed the resulting code
and validation evidence.
Changes in v2:
- add the adapted HDCP2 guard identified during review;
- send the two guards as one series because both are required for the
debugfs path.
v1: https://lore.kernel.org/r/20260929031728.88004-1-artem@trailofbits.com
Review: https://lore.kernel.org/r/2026-09-29-daily-reply-0012-re-i915-hdcp-encoder-check-v2-6-6@kernel.org
Thanks,
Artem Dinaburg
Suraj Kandpal (2):
drm/i915/hdcp: Add encoder check in intel_hdcp_get_capability
drm/i915/hdcp: Add encoder check in hdcp2_get_capability
drivers/gpu/drm/i915/display/intel_hdcp.c | 14 ++++++++++++--
1 file changed, 12 insertions(+), 2 deletions(-)
base-commit: 79643295eba17affbd16ca97f3ef04c90266b28c
--
2.39.5
^ permalink raw reply [flat|nested] 3+ messages in thread
* [PATCH 6.6.y v2 1/2] drm/i915/hdcp: Add encoder check in intel_hdcp_get_capability
2026-09-30 1:03 [PATCH 6.6.y v2 0/2] drm/i915/hdcp: guard both capability checks Artem Dinaburg
@ 2026-09-30 1:03 ` Artem Dinaburg
2026-09-30 1:03 ` [PATCH 6.6.y v2 2/2] drm/i915/hdcp: Add encoder check in hdcp2_get_capability Artem Dinaburg
1 sibling, 0 replies; 3+ messages in thread
From: Artem Dinaburg @ 2026-09-30 1:03 UTC (permalink / raw)
To: stable
Cc: Artem Dinaburg, Greg Kroah-Hartman, Sasha Levin, Suraj Kandpal,
Dnyaneshwar Bhadane, Jani Nikula, Joonas Lahtinen, Rodrigo Vivi,
Tvrtko Ursulin, Tvrtko Ursulin, David Airlie, Daniel Vetter,
Simona Vetter, intel-gfx, intel-xe, dri-devel, linux-kernel
From: Suraj Kandpal <suraj.kandpal@intel.com>
[ Upstream commit 31b42af516afa1e184d1a9f9dd4096c54044269a ]
Sometimes during hotplug scenario or suspend/resume scenario encoder is
not always initialized when intel_hdcp_get_capability add
a check to avoid kernel null pointer dereference.
[ Backport to 6.6.y: this tree uses the older intel_hdcp_capable()
helper name. Apply the same guard there; the code change is otherwise
unchanged. ]
Signed-off-by: Suraj Kandpal <suraj.kandpal@intel.com>
Reviewed-by: Dnyaneshwar Bhadane <dnyaneshwar.bhadane@intel.com>
Link: https://patchwork.freedesktop.org/patch/msgid/20240722064451.3610512-2-suraj.kandpal@intel.com
Assisted-by: LLM
Signed-off-by: Artem Dinaburg <artem@trailofbits.com>
---
CVE: CVE-2024-53051
Upstream: 31b42af516afa1e184d1a9f9dd4096c54044269a
Code change unchanged from v1; only the retained backport note was added.
v1: https://lore.kernel.org/r/20260929031728.88004-1-artem@trailofbits.com
drivers/gpu/drm/i915/display/intel_hdcp.c | 7 ++++++-
1 file changed, 6 insertions(+), 1 deletion(-)
diff --git a/drivers/gpu/drm/i915/display/intel_hdcp.c b/drivers/gpu/drm/i915/display/intel_hdcp.c
index f377c4484e18..f7987fb90bb1 100644
--- a/drivers/gpu/drm/i915/display/intel_hdcp.c
+++ b/drivers/gpu/drm/i915/display/intel_hdcp.c
@@ -142,11 +142,16 @@ int intel_hdcp_read_valid_bksv(struct intel_digital_port *dig_port,
/* Is HDCP1.4 capable on Platform and Sink */
bool intel_hdcp_capable(struct intel_connector *connector)
{
- struct intel_digital_port *dig_port = intel_attached_dig_port(connector);
+ struct intel_digital_port *dig_port;
const struct intel_hdcp_shim *shim = connector->hdcp.shim;
bool capable = false;
u8 bksv[5];
+ if (!intel_attached_encoder(connector))
+ return capable;
+
+ dig_port = intel_attached_dig_port(connector);
+
if (!shim)
return capable;
--
2.39.5
^ permalink raw reply [flat|nested] 3+ messages in thread
* [PATCH 6.6.y v2 2/2] drm/i915/hdcp: Add encoder check in hdcp2_get_capability
2026-09-30 1:03 [PATCH 6.6.y v2 0/2] drm/i915/hdcp: guard both capability checks Artem Dinaburg
2026-09-30 1:03 ` [PATCH 6.6.y v2 1/2] drm/i915/hdcp: Add encoder check in intel_hdcp_get_capability Artem Dinaburg
@ 2026-09-30 1:03 ` Artem Dinaburg
1 sibling, 0 replies; 3+ messages in thread
From: Artem Dinaburg @ 2026-09-30 1:03 UTC (permalink / raw)
To: stable
Cc: Artem Dinaburg, Greg Kroah-Hartman, Sasha Levin, Suraj Kandpal,
Dnyaneshwar Bhadane, Jani Nikula, Joonas Lahtinen, Rodrigo Vivi,
Tvrtko Ursulin, Tvrtko Ursulin, David Airlie, Daniel Vetter,
Simona Vetter, intel-gfx, intel-xe, dri-devel, linux-kernel
From: Suraj Kandpal <suraj.kandpal@intel.com>
[ Upstream commit d34f4f058edf1235c103ca9c921dc54820d14d40 ]
Add encoder check in intel_hdcp2_get_capability to avoid
null pointer error.
[ Backport to 6.6.y: this tree predates the later intel_connector
conversion, so the unsafe intel_attached_dig_port() call is still in
intel_hdcp2_capable() rather than the DP and HDMI shims.
Put the same encoder guard before that common dereference and return
false through the bool API when no encoder is attached. ]
Signed-off-by: Suraj Kandpal <suraj.kandpal@intel.com>
Reviewed-by: Dnyaneshwar Bhadane <dnyaneshwar.bhadane@intel.com>
Link: https://patchwork.freedesktop.org/patch/msgid/20240722064451.3610512-3-suraj.kandpal@intel.com
Assisted-by: LLM
Signed-off-by: Artem Dinaburg <artem@trailofbits.com>
---
CVE: CVE-2024-53050
Upstream: d34f4f058edf1235c103ca9c921dc54820d14d40
Backport: guard the common 6.6.y bool helper because the later DP/HDMI
split is not present in this tree.
Review: https://lore.kernel.org/r/2026-09-29-daily-reply-0012-re-i915-hdcp-encoder-check-v2-6-6@kernel.org
drivers/gpu/drm/i915/display/intel_hdcp.c | 7 ++++++-
1 file changed, 6 insertions(+), 1 deletion(-)
diff --git a/drivers/gpu/drm/i915/display/intel_hdcp.c b/drivers/gpu/drm/i915/display/intel_hdcp.c
index f7987fb90bb1..89e378f71d67 100644
--- a/drivers/gpu/drm/i915/display/intel_hdcp.c
+++ b/drivers/gpu/drm/i915/display/intel_hdcp.c
@@ -168,11 +168,16 @@ bool intel_hdcp_capable(struct intel_connector *connector)
/* Is HDCP2.2 capable on Platform and Sink */
bool intel_hdcp2_capable(struct intel_connector *connector)
{
- struct intel_digital_port *dig_port = intel_attached_dig_port(connector);
+ struct intel_digital_port *dig_port;
struct drm_i915_private *i915 = to_i915(connector->base.dev);
struct intel_hdcp *hdcp = &connector->hdcp;
bool capable = false;
+ if (!intel_attached_encoder(connector))
+ return capable;
+
+ dig_port = intel_attached_dig_port(connector);
+
/* I915 support for HDCP2.2 */
if (!hdcp->hdcp2_supported)
return false;
--
2.39.5
^ permalink raw reply [flat|nested] 3+ messages in thread
end of thread, other threads:[~2026-09-30 1:03 UTC | newest]
Thread overview: 3+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-09-30 1:03 [PATCH 6.6.y v2 0/2] drm/i915/hdcp: guard both capability checks Artem Dinaburg
2026-09-30 1:03 ` [PATCH 6.6.y v2 1/2] drm/i915/hdcp: Add encoder check in intel_hdcp_get_capability Artem Dinaburg
2026-09-30 1:03 ` [PATCH 6.6.y v2 2/2] drm/i915/hdcp: Add encoder check in hdcp2_get_capability Artem Dinaburg
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®