mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
* [PATCH next] drm/msm/adreno: fix use after free on error path in a6xx_gpu_init()
@ 2026-06-11 10:27 Dan Carpenter
  2026-06-11 10:29 ` Konrad Dybcio
  2026-06-12  0:27 ` Dmitry Baryshkov
  0 siblings, 2 replies; 3+ messages in thread
From: Dan Carpenter @ 2026-06-11 10:27 UTC (permalink / raw)
  To: Konrad Dybcio
  Cc: Rob Clark, Sean Paul, Konrad Dybcio, Akhil P Oommen,
	Dmitry Baryshkov, Abhinav Kumar, Jessica Zhang, Marijn Suijten,
	David Airlie, Simona Vetter, linux-arm-msm, dri-devel, freedreno,
	linux-kernel, kernel-janitors, Harshit Mogalapalli

The a6xx_destroy() function frees "a6xx_gpu" and so "adreno_gpu" points
to freed memory.  Preserve the error code before freeing the memory to
avoid a use after free.

Fixes: d158886cba08 ("drm/msm/adreno: Trust the SSoT UBWC config")
Signed-off-by: Dan Carpenter <error27@gmail.com>
---
 drivers/gpu/drm/msm/adreno/a6xx_gpu.c | 3 ++-
 1 file changed, 2 insertions(+), 1 deletion(-)

diff --git a/drivers/gpu/drm/msm/adreno/a6xx_gpu.c b/drivers/gpu/drm/msm/adreno/a6xx_gpu.c
index 8b3bb2fd433b..a44380316aaa 100644
--- a/drivers/gpu/drm/msm/adreno/a6xx_gpu.c
+++ b/drivers/gpu/drm/msm/adreno/a6xx_gpu.c
@@ -2770,8 +2770,9 @@ static struct msm_gpu *a6xx_gpu_init(struct drm_device *dev)
 
 	adreno_gpu->ubwc_config = qcom_ubwc_config_get_data();
 	if (IS_ERR(adreno_gpu->ubwc_config)) {
+		ret = PTR_ERR(adreno_gpu->ubwc_config);
 		a6xx_destroy(&(a6xx_gpu->base.base));
-		return ERR_CAST(adreno_gpu->ubwc_config);
+		return ERR_PTR(ret);
 	}
 
 	/* Set up the preemption specific bits and pieces for each ringbuffer */
-- 
2.53.0


^ permalink raw reply	[flat|nested] 3+ messages in thread

* Re: [PATCH next] drm/msm/adreno: fix use after free on error path in a6xx_gpu_init()
  2026-06-11 10:27 [PATCH next] drm/msm/adreno: fix use after free on error path in a6xx_gpu_init() Dan Carpenter
@ 2026-06-11 10:29 ` Konrad Dybcio
  2026-06-12  0:27 ` Dmitry Baryshkov
  1 sibling, 0 replies; 3+ messages in thread
From: Konrad Dybcio @ 2026-06-11 10:29 UTC (permalink / raw)
  To: Dan Carpenter
  Cc: Rob Clark, Sean Paul, Konrad Dybcio, Akhil P Oommen,
	Dmitry Baryshkov, Abhinav Kumar, Jessica Zhang, Marijn Suijten,
	David Airlie, Simona Vetter, linux-arm-msm, dri-devel, freedreno,
	linux-kernel, kernel-janitors, Harshit Mogalapalli

On 6/11/26 12:27 PM, Dan Carpenter wrote:
> The a6xx_destroy() function frees "a6xx_gpu" and so "adreno_gpu" points
> to freed memory.  Preserve the error code before freeing the memory to
> avoid a use after free.
> 
> Fixes: d158886cba08 ("drm/msm/adreno: Trust the SSoT UBWC config")
> Signed-off-by: Dan Carpenter <error27@gmail.com>
> ---

Reviewed-by: Konrad Dybcio <konrad.dybcio@oss.qualcomm.com>

Konrad

^ permalink raw reply	[flat|nested] 3+ messages in thread

* Re: [PATCH next] drm/msm/adreno: fix use after free on error path in a6xx_gpu_init()
  2026-06-11 10:27 [PATCH next] drm/msm/adreno: fix use after free on error path in a6xx_gpu_init() Dan Carpenter
  2026-06-11 10:29 ` Konrad Dybcio
@ 2026-06-12  0:27 ` Dmitry Baryshkov
  1 sibling, 0 replies; 3+ messages in thread
From: Dmitry Baryshkov @ 2026-06-12  0:27 UTC (permalink / raw)
  To: Dan Carpenter
  Cc: Konrad Dybcio, Rob Clark, Sean Paul, Konrad Dybcio,
	Akhil P Oommen, Dmitry Baryshkov, Abhinav Kumar, Jessica Zhang,
	Marijn Suijten, David Airlie, Simona Vetter, linux-arm-msm,
	dri-devel, freedreno, linux-kernel, kernel-janitors,
	Harshit Mogalapalli

On Thu, Jun 11, 2026 at 01:27:30PM +0300, Dan Carpenter wrote:
> The a6xx_destroy() function frees "a6xx_gpu" and so "adreno_gpu" points
> to freed memory.  Preserve the error code before freeing the memory to
> avoid a use after free.
> 
> Fixes: d158886cba08 ("drm/msm/adreno: Trust the SSoT UBWC config")
> Signed-off-by: Dan Carpenter <error27@gmail.com>
> ---
>  drivers/gpu/drm/msm/adreno/a6xx_gpu.c | 3 ++-
>  1 file changed, 2 insertions(+), 1 deletion(-)
> 

Reviewed-by: Dmitry Baryshkov <dmitry.baryshkov@oss.qualcomm.com>


-- 
With best wishes
Dmitry

^ permalink raw reply	[flat|nested] 3+ messages in thread

end of thread, other threads:[~2026-06-12  0:28 UTC | newest]

Thread overview: 3+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-06-11 10:27 [PATCH next] drm/msm/adreno: fix use after free on error path in a6xx_gpu_init() Dan Carpenter
2026-06-11 10:29 ` Konrad Dybcio
2026-06-12  0:27 ` Dmitry Baryshkov

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®