* [PATCH] drm/amdgpu: fix NULL pointer dereference in amdgpu_vm_init error path
@ 2026-08-25 9:29 Yang Zi
2026-08-26 9:41 ` Christian König
0 siblings, 1 reply; 3+ messages in thread
From: Yang Zi @ 2026-08-25 9:29 UTC (permalink / raw)
To: alexander.deucher, christian.koenig
Cc: airlied, Simona Vetter, Sunil Khatri, Prike Liang,
Timur Kristóf, Pierre-Eric Pelloux-Prayer, Mikhail Gavrilov,
Srinivasan Shanmugam, Natalie Vock, amd-gfx, dri-devel,
linux-kernel
In amdgpu_vm_init(), the error_free_root cleanup label runs
amdgpu_vm_pt_free_root() before amdgpu_bo_unreserve(). However,
amdgpu_vm_pt_free_root() walks the page table tree and frees each
entry via amdgpu_vm_pt_free(), which calls amdgpu_bo_unref() on the
root BO and clears vm->root.bo to NULL. The subsequent
amdgpu_bo_unreserve(vm->root.bo) then dereferences a NULL pointer.
Swap the two statements so that the root BO is unreserved before it is
freed. This mirrors the success path at the end of the function, which
unreserves before releasing its reference.
Found by static analysis of the error handling path; the failure cases
(dma_resv_reserve_fences() or amdgpu_vm_pt_clear() returning an error)
trigger this path.
Signed-off-by: Yang Zi <2959243019@qq.com>
---
diff --git a/drivers/gpu/drm/amd/amdgpu/amdgpu_vm.c b/drivers/gpu/drm/amd/amdgpu/amdgpu_vm.c
index d2ad5b0e8759..dc72181ea0fa 100644
--- a/drivers/gpu/drm/amd/amdgpu/amdgpu_vm.c
+++ b/drivers/gpu/drm/amd/amdgpu/amdgpu_vm.c
@@ -2672,8 +2672,8 @@ int amdgpu_vm_init(struct amdgpu_device *adev, struct amdgpu_vm *vm,
return 0;
error_free_root:
- amdgpu_vm_pt_free_root(adev, vm);
amdgpu_bo_unreserve(vm->root.bo);
+ amdgpu_vm_pt_free_root(adev, vm);
amdgpu_bo_unref(&root_bo);
error_free_delayed:
^ permalink raw reply [flat|nested] 3+ messages in thread
* Re: [PATCH] drm/amdgpu: fix NULL pointer dereference in amdgpu_vm_init error path
2026-08-25 9:29 [PATCH] drm/amdgpu: fix NULL pointer dereference in amdgpu_vm_init error path Yang Zi
@ 2026-08-26 9:41 ` Christian König
0 siblings, 0 replies; 3+ messages in thread
From: Christian König @ 2026-08-26 9:41 UTC (permalink / raw)
To: Yang Zi, alexander.deucher
Cc: airlied, Simona Vetter, Sunil Khatri, Prike Liang,
Timur Kristóf, Pierre-Eric Pelloux-Prayer, Mikhail Gavrilov,
Srinivasan Shanmugam, Natalie Vock, amd-gfx, dri-devel,
linux-kernel
On 8/25/26 11:29, Yang Zi wrote:
> In amdgpu_vm_init(), the error_free_root cleanup label runs
> amdgpu_vm_pt_free_root() before amdgpu_bo_unreserve(). However,
> amdgpu_vm_pt_free_root() walks the page table tree and frees each
> entry via amdgpu_vm_pt_free(), which calls amdgpu_bo_unref() on the
> root BO and clears vm->root.bo to NULL. The subsequent
> amdgpu_bo_unreserve(vm->root.bo) then dereferences a NULL pointer.
>
> Swap the two statements so that the root BO is unreserved before it is
> freed. This mirrors the success path at the end of the function, which
> unreserves before releasing its reference.
>
> Found by static analysis of the error handling path; the failure cases
> (dma_resv_reserve_fences() or amdgpu_vm_pt_clear() returning an error)
> trigger this path.
>
> Signed-off-by: Yang Zi <2959243019@qq.com>
> ---
> diff --git a/drivers/gpu/drm/amd/amdgpu/amdgpu_vm.c b/drivers/gpu/drm/amd/amdgpu/amdgpu_vm.c
> index d2ad5b0e8759..dc72181ea0fa 100644
> --- a/drivers/gpu/drm/amd/amdgpu/amdgpu_vm.c
> +++ b/drivers/gpu/drm/amd/amdgpu/amdgpu_vm.c
> @@ -2672,8 +2672,8 @@ int amdgpu_vm_init(struct amdgpu_device *adev, struct amdgpu_vm *vm,
> return 0;
>
> error_free_root:
> - amdgpu_vm_pt_free_root(adev, vm);
> amdgpu_bo_unreserve(vm->root.bo);
> + amdgpu_vm_pt_free_root(adev, vm);
Clear NAK, that is just nonsense and will potentially trigger tons of warnings.
The amdgpu_bo_unreserve(() call just needs to use the local variable root_bo instead.
Regards,
Christian.
> amdgpu_bo_unref(&root_bo);
>
> error_free_delayed:
>
^ permalink raw reply [flat|nested] 3+ messages in thread
* [PATCH] drm/amdgpu: fix NULL pointer dereference in amdgpu_vm_init error path
@ 2026-08-25 9:36 Yang Zi
0 siblings, 0 replies; 3+ messages in thread
From: Yang Zi @ 2026-08-25 9:36 UTC (permalink / raw)
To: alexander.deucher, christian.koenig; +Cc: amd-gfx, dri-devel, linux-kernel
In amdgpu_vm_init(), the error_free_root cleanup label runs
amdgpu_vm_pt_free_root() before amdgpu_bo_unreserve(). However,
amdgpu_vm_pt_free_root() walks the page table tree and frees each
entry via amdgpu_vm_pt_free(), which calls amdgpu_bo_unref() on the
root BO and clears vm->root.bo to NULL. The subsequent
amdgpu_bo_unreserve(vm->root.bo) then dereferences a NULL pointer.
Swap the two statements so that the root BO is unreserved before it is
freed. This mirrors the success path at the end of the function, which
unreserves before releasing its reference.
Found by static analysis of the error handling path; the failure cases
(dma_resv_reserve_fences() or amdgpu_vm_pt_clear() returning an error)
trigger this path.
Signed-off-by: Yang Zi <2959243019@qq.com>
---
diff --git a/drivers/gpu/drm/amd/amdgpu/amdgpu_vm.c b/drivers/gpu/drm/amd/amdgpu/amdgpu_vm.c
index d2ad5b0e8759..dc72181ea0fa 100644
--- a/drivers/gpu/drm/amd/amdgpu/amdgpu_vm.c
+++ b/drivers/gpu/drm/amd/amdgpu/amdgpu_vm.c
@@ -2672,8 +2672,8 @@ int amdgpu_vm_init(struct amdgpu_device *adev, struct amdgpu_vm *vm,
return 0;
error_free_root:
- amdgpu_vm_pt_free_root(adev, vm);
amdgpu_bo_unreserve(vm->root.bo);
+ amdgpu_vm_pt_free_root(adev, vm);
amdgpu_bo_unref(&root_bo);
error_free_delayed:
^ permalink raw reply [flat|nested] 3+ messages in thread
end of thread, other threads:[~2026-08-26 9:41 UTC | newest]
Thread overview: 3+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-08-25 9:29 [PATCH] drm/amdgpu: fix NULL pointer dereference in amdgpu_vm_init error path Yang Zi
2026-08-26 9:41 ` Christian König
2026-08-25 9:36 Yang Zi
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®