mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
* [PATCH] drm/nouveau: Fix NULL pointer dereference in nouveau_fence_sync() when prev->cli == NULL
@ 2026-07-23 10:06 Emmanuel Fleury
  2026-10-06  9:58 ` Beomseok Kim
  0 siblings, 1 reply; 2+ messages in thread
From: Emmanuel Fleury @ 2026-07-23 10:06 UTC (permalink / raw)
  To: dri-devel, linux-kernel, nouveau
  Cc: Danilo Krummrich, David Airlie, Maarten Lankhorst, Maxime Ripard,
	Simona Vetter

I ran several times into a kernel oops caused by a NULL pointer dereference
in nouveau_fence_sync(). The variable "prev" may be non-NULL while
"prev->cli" is NULL, leading to an unconditional dereference of
"prev->cli->drm".

Prevent the dereference by checking "prev->cli" before accessing
its "drm" field while preserving the existing logic.

Fixes: 1f9910b41c857 ("nouveau/fence: handle cross device fences properly")
Signed-off-by: Emmanuel Fleury <emmanuel.fleury@u-bordeaux.fr>
---
  drivers/gpu/drm/nouveau/nouveau_fence.c | 2 +-
  1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/drivers/gpu/drm/nouveau/nouveau_fence.c 
b/drivers/gpu/drm/nouveau/nouveau_fence.c
index edbe9e08ba0f..90e6e89c0911 100644
--- a/drivers/gpu/drm/nouveau/nouveau_fence.c
+++ b/drivers/gpu/drm/nouveau/nouveau_fence.c
@@ -374,7 +374,7 @@ nouveau_fence_sync(struct nouveau_bo *nvbo, struct 
nouveau_channel *chan,

  				rcu_read_lock();
  				prev = rcu_dereference(f->channel);
-				local = prev && prev->cli->drm == chan->cli->drm;
+				local = prev && prev->cli && prev->cli->drm == chan->cli->drm;
  				if (local && (prev == chan ||
  					      fctx->sync(f, prev, chan) == 0))
  					must_wait = false;
-- 
2.53.0


^ permalink raw reply	[flat|nested] 2+ messages in thread

end of thread, other threads:[~2026-10-06  9:59 UTC | newest]

Thread overview: 2+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-07-23 10:06 [PATCH] drm/nouveau: Fix NULL pointer dereference in nouveau_fence_sync() when prev->cli == NULL Emmanuel Fleury
2026-10-06  9:58 ` Beomseok Kim

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®