mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
* [PATCH v2 0/5] drm/gud: fix probe validation, shadow_buf UAF, and bulk_len divide-by-zero
@ 2026-09-30  6:59 Hui Peng
  2026-09-30  6:59 ` [PATCH v2 1/5] drm/gud: Fix probe failure on non-DMA devices by moving descriptor check Hui Peng
                   ` (4 more replies)
  0 siblings, 5 replies; 6+ messages in thread
From: Hui Peng @ 2026-09-30  6:59 UTC (permalink / raw)
  To: Noralf Trønnes, Maarten Lankhorst, Maxime Ripard,
	Thomas Zimmermann, David Airlie, Simona Vetter
  Cc: dri-devel, linux-kernel, stable, Hui Peng

This patch series addresses multiple memory safety, concurrency, and
validation bugs in drivers/gpu/drm/gud/:

- Patch 1 moves display descriptor validation in gud_probe() to after
  drmm_mode_config_init() and field assignments, preventing unconditional
  probe failure (-EINVAL) on non-DMA USB display devices.
- Patch 2 aligns both x1 and x2 coordinates to block_width in
  gud_flush_damage(), keeping rectangle width aligned for compressed
  block display formats.
- Patch 3 flushes pending background work (flush_work(&gdrm->work)) prior
  to freeing gdrm->shadow_buf on framebuffer resize, eliminating the
  Use-After-Free (UAF) race between queue_damage and gud_flush_work().
- Patch 4 guards lines = gdrm->bulk_len / pitch against zero pitch or
  lines in gud_flush_damage(), preventing divide-by-zero in DIV_ROUND_UP().
- Patch 5 resets damage state on vcalloc() ENOMEM failure in
  gud_fb_queue_damage(), preventing damage height underflow in subsequent
  flushes.

All 5 patches have been dynamically verified in QEMU against Linux 7.3.0-rc3
with KASAN enabled; detailed test methods and outcomes are documented in
each commit body.

Changes in v2:
- Split single monolithic patch into 5 distinct, single-purpose patches
  as requested by maintainers and reviewers.
- Included QEMU test methods, expected vs unfixed behaviors, and KASAN trace
  details in commit bodies.

Hui Peng (5):
  drm/gud: Fix probe failure on non-DMA devices by moving descriptor check
  drm/gud: Align both x1 and x2 to block_width in gud_flush_damage()
  drm/gud: Prevent shadow_buf UAF by flushing work before reallocating
  drm/gud: Fix bulk_len divide-by-zero in gud_flush_damage()
  drm/gud: Reset damage state on vcalloc ENOMEM failure

 drivers/gpu/drm/gud/gud_drv.c  |  6 ++++++
 drivers/gpu/drm/gud/gud_pipe.c | 22 +++++++++++++++++++++-
 2 files changed, 27 insertions(+), 1 deletion(-)

-- 
2.47.3

^ permalink raw reply	[flat|nested] 6+ messages in thread

end of thread, other threads:[~2026-09-30  6:59 UTC | newest]

Thread overview: 6+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-09-30  6:59 [PATCH v2 0/5] drm/gud: fix probe validation, shadow_buf UAF, and bulk_len divide-by-zero Hui Peng
2026-09-30  6:59 ` [PATCH v2 1/5] drm/gud: Fix probe failure on non-DMA devices by moving descriptor check Hui Peng
2026-09-30  6:59 ` [PATCH v2 2/5] drm/gud: Align both x1 and x2 to block_width in gud_flush_damage() Hui Peng
2026-09-30  6:59 ` [PATCH v2 3/5] drm/gud: Prevent shadow_buf UAF by flushing work before reallocating Hui Peng
2026-09-30  6:59 ` [PATCH v2 4/5] drm/gud: Fix bulk_len divide-by-zero in gud_flush_damage() Hui Peng
2026-09-30  6:59 ` [PATCH v2 5/5] drm/gud: Reset damage state on vcalloc ENOMEM failure Hui Peng

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®