* [PATCH 0/2] accel/amdxdna: fix two NULL-deref DoS paths reachable via AMDXDNA_EXEC_CMD
@ 2026-07-13 17:30 Doruk Tan Ozturk
2026-07-13 17:30 ` [PATCH 1/2] accel/amdxdna: reject user command submission without a command BO Doruk Tan Ozturk
2026-07-13 17:30 ` [PATCH 2/2] accel/amdxdna: reject command submission on devices without a submit op Doruk Tan Ozturk
0 siblings, 2 replies; 7+ messages in thread
From: Doruk Tan Ozturk @ 2026-07-13 17:30 UTC (permalink / raw)
To: Min Ma, Lizhi Hou, Oded Gabbay; +Cc: dri-devel, linux-kernel, Doruk Tan Ozturk
An unprivileged process with access to an AMD NPU accel node can oops the
kernel with a single AMDXDNA_EXEC_CMD ioctl. Two distinct NULL dereferences
are reachable on the command-submit path, both since the driver first gained
command execution:
1. cmd_handles = 0 (AMDXDNA_INVALID_BO_HANDLE) leaves job->cmd_bo NULL,
dereferenced later by the DRM scheduler.
2. On an AIE4 device (no .cmd_submit op) the ioctl calls a NULL function
pointer.
Both are availability-only (local DoS), no memory corruption. Found by static
analysis; verified against source, not runtime-reproduced (no NPU on hand).
Doruk Tan Ozturk (2):
accel/amdxdna: reject user command submission without a command BO
accel/amdxdna: reject command submission on devices without a submit
op
drivers/accel/amdxdna/amdxdna_ctx.c | 14 ++++++++++++++
1 file changed, 14 insertions(+)
--
2.43.0
^ permalink raw reply [flat|nested] 7+ messages in thread
* [PATCH 1/2] accel/amdxdna: reject user command submission without a command BO
2026-07-13 17:30 [PATCH 0/2] accel/amdxdna: fix two NULL-deref DoS paths reachable via AMDXDNA_EXEC_CMD Doruk Tan Ozturk
@ 2026-07-13 17:30 ` Doruk Tan Ozturk
2026-07-15 0:58 ` Lizhi Hou
2026-07-13 17:30 ` [PATCH 2/2] accel/amdxdna: reject command submission on devices without a submit op Doruk Tan Ozturk
1 sibling, 1 reply; 7+ messages in thread
From: Doruk Tan Ozturk @ 2026-07-13 17:30 UTC (permalink / raw)
To: Min Ma, Lizhi Hou, Oded Gabbay
Cc: dri-devel, linux-kernel, Doruk Tan Ozturk, stable
amdxdna_drm_submit_execbuf() passes the user-supplied command BO handle
straight into amdxdna_cmd_submit() with drv_cmd == NULL. When the handle
is AMDXDNA_INVALID_BO_HANDLE (0), the block that fetches job->cmd_bo is
skipped, leaving it NULL, and no check rejects it on the user path (the
!job->cmd_bo guard lives inside the != INVALID branch).
The job is then armed and pushed to the DRM scheduler.
aie2_sched_job_run() takes the drv_cmd == NULL path and calls
amdxdna_cmd_set_state(job->cmd_bo) -> amdxdna_gem_vmap(NULL) ->
to_gobj(NULL)->dev, a NULL pointer dereference in the drm_sched worker.
A process with access to the accel node on a system with a probed AMD NPU
can trigger a kernel oops with a single AMDXDNA_EXEC_CMD ioctl
(cmd_handles = 0).
Only internal driver commands (SYNC_DEBUG_BO / ATTACH_DEBUG_BO)
legitimately pass AMDXDNA_INVALID_BO_HANDLE, and they always set drv_cmd.
Reject the invalid handle for user submissions (drv_cmd == NULL) at the
submit choke point so every user path is covered.
Fixes: aac243092b70 ("accel/amdxdna: Add command execution")
Cc: stable@vger.kernel.org
Found by 0sec automated security-research tooling (https://0sec.ai).
Assisted-by: 0sec:claude-opus-4-8
Signed-off-by: Doruk Tan Ozturk <doruk@0sec.ai>
---
drivers/accel/amdxdna/amdxdna_ctx.c | 10 ++++++++++
1 file changed, 10 insertions(+)
diff --git a/drivers/accel/amdxdna/amdxdna_ctx.c b/drivers/accel/amdxdna/amdxdna_ctx.c
index 8f8df9d04ec5..a5c8c2c4de6d 100644
--- a/drivers/accel/amdxdna/amdxdna_ctx.c
+++ b/drivers/accel/amdxdna/amdxdna_ctx.c
@@ -603,6 +603,16 @@ int amdxdna_cmd_submit(struct amdxdna_client *client,
ret = -EINVAL;
goto free_job;
}
+ } else if (!drv_cmd) {
+ /*
+ * Only internal driver commands (drv_cmd != NULL) may omit a
+ * command BO. A user command submission with the invalid handle
+ * would leave job->cmd_bo NULL and later fault when the scheduler
+ * dereferences it in amdxdna_cmd_set_state().
+ */
+ XDNA_DBG(xdna, "Command BO handle required for user submission");
+ ret = -EINVAL;
+ goto free_job;
}
ret = amdxdna_arg_bos_lookup(client, job, arg_bo_hdls, arg_bo_cnt);
--
2.43.0
^ permalink raw reply [flat|nested] 7+ messages in thread
* [PATCH 2/2] accel/amdxdna: reject command submission on devices without a submit op
2026-07-13 17:30 [PATCH 0/2] accel/amdxdna: fix two NULL-deref DoS paths reachable via AMDXDNA_EXEC_CMD Doruk Tan Ozturk
2026-07-13 17:30 ` [PATCH 1/2] accel/amdxdna: reject user command submission without a command BO Doruk Tan Ozturk
@ 2026-07-13 17:30 ` Doruk Tan Ozturk
2026-07-15 1:00 ` Lizhi Hou
1 sibling, 1 reply; 7+ messages in thread
From: Doruk Tan Ozturk @ 2026-07-13 17:30 UTC (permalink / raw)
To: Min Ma, Lizhi Hou, Oded Gabbay
Cc: dri-devel, linux-kernel, Doruk Tan Ozturk, stable
amdxdna_cmd_submit() calls xdna->dev_info->ops->cmd_submit()
unconditionally, but only aie2_dev_ops defines that callback.
aie4_vf_ops (the AIE4 SR-IOV virtual function) does not, so a user
AMDXDNA_EXEC_CMD ioctl on an AIE4 device reaches a NULL function-pointer
call and oopses the kernel. AIE4 submits work through a mapped user queue
and doorbell, not this ioctl path.
Reject the submission early with -EOPNOTSUPP when the device provides no
cmd_submit op, so the shared EXEC ioctl is a clean no-op on such devices.
Fixes: aac243092b70 ("accel/amdxdna: Add command execution")
Cc: stable@vger.kernel.org
Found by 0sec automated security-research tooling (https://0sec.ai).
Assisted-by: 0sec:claude-opus-4-8
Signed-off-by: Doruk Tan Ozturk <doruk@0sec.ai>
---
drivers/accel/amdxdna/amdxdna_ctx.c | 4 ++++
1 file changed, 4 insertions(+)
diff --git a/drivers/accel/amdxdna/amdxdna_ctx.c b/drivers/accel/amdxdna/amdxdna_ctx.c
index a5c8c2c4de6d..bdbd3db12a6c 100644
--- a/drivers/accel/amdxdna/amdxdna_ctx.c
+++ b/drivers/accel/amdxdna/amdxdna_ctx.c
@@ -590,6 +590,10 @@ int amdxdna_cmd_submit(struct amdxdna_client *client,
int ret, idx;
XDNA_DBG(xdna, "Command BO hdl %d, Arg BO count %d", cmd_bo_hdl, arg_bo_cnt);
+
+ if (!xdna->dev_info->ops->cmd_submit)
+ return -EOPNOTSUPP;
+
job = kzalloc_flex(*job, bos, arg_bo_cnt);
if (!job)
return -ENOMEM;
--
2.43.0
^ permalink raw reply [flat|nested] 7+ messages in thread
* Re: [PATCH 1/2] accel/amdxdna: reject user command submission without a command BO
2026-07-13 17:30 ` [PATCH 1/2] accel/amdxdna: reject user command submission without a command BO Doruk Tan Ozturk
@ 2026-07-15 0:58 ` Lizhi Hou
2026-07-15 9:25 ` Lizhi Hou
0 siblings, 1 reply; 7+ messages in thread
From: Lizhi Hou @ 2026-07-15 0:58 UTC (permalink / raw)
To: Doruk Tan Ozturk, Min Ma, Oded Gabbay; +Cc: dri-devel, linux-kernel, stable
On 7/13/26 10:30, Doruk Tan Ozturk wrote:
> amdxdna_drm_submit_execbuf() passes the user-supplied command BO handle
> straight into amdxdna_cmd_submit() with drv_cmd == NULL. When the handle
> is AMDXDNA_INVALID_BO_HANDLE (0), the block that fetches job->cmd_bo is
> skipped, leaving it NULL, and no check rejects it on the user path (the
> !job->cmd_bo guard lives inside the != INVALID branch).
>
> The job is then armed and pushed to the DRM scheduler.
> aie2_sched_job_run() takes the drv_cmd == NULL path and calls
> amdxdna_cmd_set_state(job->cmd_bo) -> amdxdna_gem_vmap(NULL) ->
> to_gobj(NULL)->dev, a NULL pointer dereference in the drm_sched worker.
> A process with access to the accel node on a system with a probed AMD NPU
> can trigger a kernel oops with a single AMDXDNA_EXEC_CMD ioctl
> (cmd_handles = 0).
>
> Only internal driver commands (SYNC_DEBUG_BO / ATTACH_DEBUG_BO)
> legitimately pass AMDXDNA_INVALID_BO_HANDLE, and they always set drv_cmd.
> Reject the invalid handle for user submissions (drv_cmd == NULL) at the
> submit choke point so every user path is covered.
>
> Fixes: aac243092b70 ("accel/amdxdna: Add command execution")
> Cc: stable@vger.kernel.org
> Found by 0sec automated security-research tooling (https://0sec.ai).
> Assisted-by: 0sec:claude-opus-4-8
> Signed-off-by: Doruk Tan Ozturk <doruk@0sec.ai>
> ---
> drivers/accel/amdxdna/amdxdna_ctx.c | 10 ++++++++++
> 1 file changed, 10 insertions(+)
>
> diff --git a/drivers/accel/amdxdna/amdxdna_ctx.c b/drivers/accel/amdxdna/amdxdna_ctx.c
> index 8f8df9d04ec5..a5c8c2c4de6d 100644
> --- a/drivers/accel/amdxdna/amdxdna_ctx.c
> +++ b/drivers/accel/amdxdna/amdxdna_ctx.c
> @@ -603,6 +603,16 @@ int amdxdna_cmd_submit(struct amdxdna_client *client,
> ret = -EINVAL;
> goto free_job;
> }
> + } else if (!drv_cmd) {
> + /*
> + * Only internal driver commands (drv_cmd != NULL) may omit a
> + * command BO. A user command submission with the invalid handle
> + * would leave job->cmd_bo NULL and later fault when the scheduler
> + * dereferences it in amdxdna_cmd_set_state().
> + */
> + XDNA_DBG(xdna, "Command BO handle required for user submission");
> + ret = -EINVAL;
> + goto free_job;
Reviewed-by: Lizhi Hou <lizhi.hou@amd.com>
> }
>
> ret = amdxdna_arg_bos_lookup(client, job, arg_bo_hdls, arg_bo_cnt);
^ permalink raw reply [flat|nested] 7+ messages in thread
* Re: [PATCH 2/2] accel/amdxdna: reject command submission on devices without a submit op
2026-07-13 17:30 ` [PATCH 2/2] accel/amdxdna: reject command submission on devices without a submit op Doruk Tan Ozturk
@ 2026-07-15 1:00 ` Lizhi Hou
2026-07-15 9:25 ` Lizhi Hou
0 siblings, 1 reply; 7+ messages in thread
From: Lizhi Hou @ 2026-07-15 1:00 UTC (permalink / raw)
To: Doruk Tan Ozturk, Min Ma, Oded Gabbay; +Cc: dri-devel, linux-kernel, stable
On 7/13/26 10:30, Doruk Tan Ozturk wrote:
> amdxdna_cmd_submit() calls xdna->dev_info->ops->cmd_submit()
> unconditionally, but only aie2_dev_ops defines that callback.
> aie4_vf_ops (the AIE4 SR-IOV virtual function) does not, so a user
> AMDXDNA_EXEC_CMD ioctl on an AIE4 device reaches a NULL function-pointer
> call and oopses the kernel. AIE4 submits work through a mapped user queue
> and doorbell, not this ioctl path.
>
> Reject the submission early with -EOPNOTSUPP when the device provides no
> cmd_submit op, so the shared EXEC ioctl is a clean no-op on such devices.
>
> Fixes: aac243092b70 ("accel/amdxdna: Add command execution")
> Cc: stable@vger.kernel.org
> Found by 0sec automated security-research tooling (https://0sec.ai).
> Assisted-by: 0sec:claude-opus-4-8
> Signed-off-by: Doruk Tan Ozturk <doruk@0sec.ai>
> ---
> drivers/accel/amdxdna/amdxdna_ctx.c | 4 ++++
> 1 file changed, 4 insertions(+)
>
> diff --git a/drivers/accel/amdxdna/amdxdna_ctx.c b/drivers/accel/amdxdna/amdxdna_ctx.c
> index a5c8c2c4de6d..bdbd3db12a6c 100644
> --- a/drivers/accel/amdxdna/amdxdna_ctx.c
> +++ b/drivers/accel/amdxdna/amdxdna_ctx.c
> @@ -590,6 +590,10 @@ int amdxdna_cmd_submit(struct amdxdna_client *client,
> int ret, idx;
>
> XDNA_DBG(xdna, "Command BO hdl %d, Arg BO count %d", cmd_bo_hdl, arg_bo_cnt);
> +
> + if (!xdna->dev_info->ops->cmd_submit)
> + return -EOPNOTSUPP;
> +
Reviewed-by: Lizhi Hou <lizhi.hou@amd.com>
> job = kzalloc_flex(*job, bos, arg_bo_cnt);
> if (!job)
> return -ENOMEM;
^ permalink raw reply [flat|nested] 7+ messages in thread
* Re: [PATCH 1/2] accel/amdxdna: reject user command submission without a command BO
2026-07-15 0:58 ` Lizhi Hou
@ 2026-07-15 9:25 ` Lizhi Hou
0 siblings, 0 replies; 7+ messages in thread
From: Lizhi Hou @ 2026-07-15 9:25 UTC (permalink / raw)
To: Doruk Tan Ozturk, Min Ma, Oded Gabbay; +Cc: dri-devel, linux-kernel, stable
Applied to drm-misc-fixes
On 7/14/26 17:58, Lizhi Hou wrote:
>
> On 7/13/26 10:30, Doruk Tan Ozturk wrote:
>> amdxdna_drm_submit_execbuf() passes the user-supplied command BO handle
>> straight into amdxdna_cmd_submit() with drv_cmd == NULL. When the handle
>> is AMDXDNA_INVALID_BO_HANDLE (0), the block that fetches job->cmd_bo is
>> skipped, leaving it NULL, and no check rejects it on the user path (the
>> !job->cmd_bo guard lives inside the != INVALID branch).
>>
>> The job is then armed and pushed to the DRM scheduler.
>> aie2_sched_job_run() takes the drv_cmd == NULL path and calls
>> amdxdna_cmd_set_state(job->cmd_bo) -> amdxdna_gem_vmap(NULL) ->
>> to_gobj(NULL)->dev, a NULL pointer dereference in the drm_sched worker.
>> A process with access to the accel node on a system with a probed AMD
>> NPU
>> can trigger a kernel oops with a single AMDXDNA_EXEC_CMD ioctl
>> (cmd_handles = 0).
>>
>> Only internal driver commands (SYNC_DEBUG_BO / ATTACH_DEBUG_BO)
>> legitimately pass AMDXDNA_INVALID_BO_HANDLE, and they always set
>> drv_cmd.
>> Reject the invalid handle for user submissions (drv_cmd == NULL) at the
>> submit choke point so every user path is covered.
>>
>> Fixes: aac243092b70 ("accel/amdxdna: Add command execution")
>> Cc: stable@vger.kernel.org
>> Found by 0sec automated security-research tooling (https://0sec.ai).
>> Assisted-by: 0sec:claude-opus-4-8
>> Signed-off-by: Doruk Tan Ozturk <doruk@0sec.ai>
>> ---
>> drivers/accel/amdxdna/amdxdna_ctx.c | 10 ++++++++++
>> 1 file changed, 10 insertions(+)
>>
>> diff --git a/drivers/accel/amdxdna/amdxdna_ctx.c
>> b/drivers/accel/amdxdna/amdxdna_ctx.c
>> index 8f8df9d04ec5..a5c8c2c4de6d 100644
>> --- a/drivers/accel/amdxdna/amdxdna_ctx.c
>> +++ b/drivers/accel/amdxdna/amdxdna_ctx.c
>> @@ -603,6 +603,16 @@ int amdxdna_cmd_submit(struct amdxdna_client
>> *client,
>> ret = -EINVAL;
>> goto free_job;
>> }
>> + } else if (!drv_cmd) {
>> + /*
>> + * Only internal driver commands (drv_cmd != NULL) may omit a
>> + * command BO. A user command submission with the invalid
>> handle
>> + * would leave job->cmd_bo NULL and later fault when the
>> scheduler
>> + * dereferences it in amdxdna_cmd_set_state().
>> + */
>> + XDNA_DBG(xdna, "Command BO handle required for user
>> submission");
>> + ret = -EINVAL;
>> + goto free_job;
> Reviewed-by: Lizhi Hou <lizhi.hou@amd.com>
>> }
>> ret = amdxdna_arg_bos_lookup(client, job, arg_bo_hdls,
>> arg_bo_cnt);
^ permalink raw reply [flat|nested] 7+ messages in thread
* Re: [PATCH 2/2] accel/amdxdna: reject command submission on devices without a submit op
2026-07-15 1:00 ` Lizhi Hou
@ 2026-07-15 9:25 ` Lizhi Hou
0 siblings, 0 replies; 7+ messages in thread
From: Lizhi Hou @ 2026-07-15 9:25 UTC (permalink / raw)
To: Doruk Tan Ozturk, Min Ma, Oded Gabbay; +Cc: dri-devel, linux-kernel, stable
Applied to drm-misc-fixes
On 7/14/26 18:00, Lizhi Hou wrote:
>
> On 7/13/26 10:30, Doruk Tan Ozturk wrote:
>> amdxdna_cmd_submit() calls xdna->dev_info->ops->cmd_submit()
>> unconditionally, but only aie2_dev_ops defines that callback.
>> aie4_vf_ops (the AIE4 SR-IOV virtual function) does not, so a user
>> AMDXDNA_EXEC_CMD ioctl on an AIE4 device reaches a NULL function-pointer
>> call and oopses the kernel. AIE4 submits work through a mapped user
>> queue
>> and doorbell, not this ioctl path.
>>
>> Reject the submission early with -EOPNOTSUPP when the device provides no
>> cmd_submit op, so the shared EXEC ioctl is a clean no-op on such
>> devices.
>>
>> Fixes: aac243092b70 ("accel/amdxdna: Add command execution")
>> Cc: stable@vger.kernel.org
>> Found by 0sec automated security-research tooling (https://0sec.ai).
>> Assisted-by: 0sec:claude-opus-4-8
>> Signed-off-by: Doruk Tan Ozturk <doruk@0sec.ai>
>> ---
>> drivers/accel/amdxdna/amdxdna_ctx.c | 4 ++++
>> 1 file changed, 4 insertions(+)
>>
>> diff --git a/drivers/accel/amdxdna/amdxdna_ctx.c
>> b/drivers/accel/amdxdna/amdxdna_ctx.c
>> index a5c8c2c4de6d..bdbd3db12a6c 100644
>> --- a/drivers/accel/amdxdna/amdxdna_ctx.c
>> +++ b/drivers/accel/amdxdna/amdxdna_ctx.c
>> @@ -590,6 +590,10 @@ int amdxdna_cmd_submit(struct amdxdna_client
>> *client,
>> int ret, idx;
>> XDNA_DBG(xdna, "Command BO hdl %d, Arg BO count %d",
>> cmd_bo_hdl, arg_bo_cnt);
>> +
>> + if (!xdna->dev_info->ops->cmd_submit)
>> + return -EOPNOTSUPP;
>> +
> Reviewed-by: Lizhi Hou <lizhi.hou@amd.com>
>> job = kzalloc_flex(*job, bos, arg_bo_cnt);
>> if (!job)
>> return -ENOMEM;
^ permalink raw reply [flat|nested] 7+ messages in thread
end of thread, other threads:[~2026-07-15 9:26 UTC | newest]
Thread overview: 7+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-07-13 17:30 [PATCH 0/2] accel/amdxdna: fix two NULL-deref DoS paths reachable via AMDXDNA_EXEC_CMD Doruk Tan Ozturk
2026-07-13 17:30 ` [PATCH 1/2] accel/amdxdna: reject user command submission without a command BO Doruk Tan Ozturk
2026-07-15 0:58 ` Lizhi Hou
2026-07-15 9:25 ` Lizhi Hou
2026-07-13 17:30 ` [PATCH 2/2] accel/amdxdna: reject command submission on devices without a submit op Doruk Tan Ozturk
2026-07-15 1:00 ` Lizhi Hou
2026-07-15 9:25 ` Lizhi Hou
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®