* [PATCH next] drm/msm/adreno: fix use after free on error path in a6xx_gpu_init()
@ 2026-06-11 10:27 Dan Carpenter
2026-06-11 10:29 ` Konrad Dybcio
2026-06-12 0:27 ` Dmitry Baryshkov
0 siblings, 2 replies; 3+ messages in thread
From: Dan Carpenter @ 2026-06-11 10:27 UTC (permalink / raw)
To: Konrad Dybcio
Cc: Rob Clark, Sean Paul, Konrad Dybcio, Akhil P Oommen,
Dmitry Baryshkov, Abhinav Kumar, Jessica Zhang, Marijn Suijten,
David Airlie, Simona Vetter, linux-arm-msm, dri-devel, freedreno,
linux-kernel, kernel-janitors, Harshit Mogalapalli
The a6xx_destroy() function frees "a6xx_gpu" and so "adreno_gpu" points
to freed memory. Preserve the error code before freeing the memory to
avoid a use after free.
Fixes: d158886cba08 ("drm/msm/adreno: Trust the SSoT UBWC config")
Signed-off-by: Dan Carpenter <error27@gmail.com>
---
drivers/gpu/drm/msm/adreno/a6xx_gpu.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/drivers/gpu/drm/msm/adreno/a6xx_gpu.c b/drivers/gpu/drm/msm/adreno/a6xx_gpu.c
index 8b3bb2fd433b..a44380316aaa 100644
--- a/drivers/gpu/drm/msm/adreno/a6xx_gpu.c
+++ b/drivers/gpu/drm/msm/adreno/a6xx_gpu.c
@@ -2770,8 +2770,9 @@ static struct msm_gpu *a6xx_gpu_init(struct drm_device *dev)
adreno_gpu->ubwc_config = qcom_ubwc_config_get_data();
if (IS_ERR(adreno_gpu->ubwc_config)) {
+ ret = PTR_ERR(adreno_gpu->ubwc_config);
a6xx_destroy(&(a6xx_gpu->base.base));
- return ERR_CAST(adreno_gpu->ubwc_config);
+ return ERR_PTR(ret);
}
/* Set up the preemption specific bits and pieces for each ringbuffer */
--
2.53.0
^ permalink raw reply [flat|nested] 3+ messages in thread
* Re: [PATCH next] drm/msm/adreno: fix use after free on error path in a6xx_gpu_init()
2026-06-11 10:27 [PATCH next] drm/msm/adreno: fix use after free on error path in a6xx_gpu_init() Dan Carpenter
@ 2026-06-11 10:29 ` Konrad Dybcio
2026-06-12 0:27 ` Dmitry Baryshkov
1 sibling, 0 replies; 3+ messages in thread
From: Konrad Dybcio @ 2026-06-11 10:29 UTC (permalink / raw)
To: Dan Carpenter
Cc: Rob Clark, Sean Paul, Konrad Dybcio, Akhil P Oommen,
Dmitry Baryshkov, Abhinav Kumar, Jessica Zhang, Marijn Suijten,
David Airlie, Simona Vetter, linux-arm-msm, dri-devel, freedreno,
linux-kernel, kernel-janitors, Harshit Mogalapalli
On 6/11/26 12:27 PM, Dan Carpenter wrote:
> The a6xx_destroy() function frees "a6xx_gpu" and so "adreno_gpu" points
> to freed memory. Preserve the error code before freeing the memory to
> avoid a use after free.
>
> Fixes: d158886cba08 ("drm/msm/adreno: Trust the SSoT UBWC config")
> Signed-off-by: Dan Carpenter <error27@gmail.com>
> ---
Reviewed-by: Konrad Dybcio <konrad.dybcio@oss.qualcomm.com>
Konrad
^ permalink raw reply [flat|nested] 3+ messages in thread
* Re: [PATCH next] drm/msm/adreno: fix use after free on error path in a6xx_gpu_init()
2026-06-11 10:27 [PATCH next] drm/msm/adreno: fix use after free on error path in a6xx_gpu_init() Dan Carpenter
2026-06-11 10:29 ` Konrad Dybcio
@ 2026-06-12 0:27 ` Dmitry Baryshkov
1 sibling, 0 replies; 3+ messages in thread
From: Dmitry Baryshkov @ 2026-06-12 0:27 UTC (permalink / raw)
To: Dan Carpenter
Cc: Konrad Dybcio, Rob Clark, Sean Paul, Konrad Dybcio,
Akhil P Oommen, Dmitry Baryshkov, Abhinav Kumar, Jessica Zhang,
Marijn Suijten, David Airlie, Simona Vetter, linux-arm-msm,
dri-devel, freedreno, linux-kernel, kernel-janitors,
Harshit Mogalapalli
On Thu, Jun 11, 2026 at 01:27:30PM +0300, Dan Carpenter wrote:
> The a6xx_destroy() function frees "a6xx_gpu" and so "adreno_gpu" points
> to freed memory. Preserve the error code before freeing the memory to
> avoid a use after free.
>
> Fixes: d158886cba08 ("drm/msm/adreno: Trust the SSoT UBWC config")
> Signed-off-by: Dan Carpenter <error27@gmail.com>
> ---
> drivers/gpu/drm/msm/adreno/a6xx_gpu.c | 3 ++-
> 1 file changed, 2 insertions(+), 1 deletion(-)
>
Reviewed-by: Dmitry Baryshkov <dmitry.baryshkov@oss.qualcomm.com>
--
With best wishes
Dmitry
^ permalink raw reply [flat|nested] 3+ messages in thread
end of thread, other threads:[~2026-06-12 0:28 UTC | newest]
Thread overview: 3+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-06-11 10:27 [PATCH next] drm/msm/adreno: fix use after free on error path in a6xx_gpu_init() Dan Carpenter
2026-06-11 10:29 ` Konrad Dybcio
2026-06-12 0:27 ` Dmitry Baryshkov
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®