[PATCH] drm/gem-dma: fix double GEM object put on the mmap error path

Baul Lee <[email protected]> Wed, 5 Aug 2026 21:44:42 +0900
Newsgroups gmane.linux.kernel.stable,gmane.comp.video.dri.devel,gmane.linux.kernel
Message-ID <[email protected]>
drm_gem_dma_mmap() drops a GEM reference when the DMA mapping fails:

	if (ret)
		drm_gem_vm_close(vma);

drm_gem_vm_close() puts vma->vm_private_data.  drm_gem_mmap_obj() has
already pointed that at the object, and puts it again when the callback
returns an error:

	drm_gem_object_get(obj);
	vma->vm_private_data = obj;
	...
	ret = obj->funcs->mmap(obj, vma);
	if (ret)
		goto err_drm_gem_object_put;

One get, two puts: a failing dma_mmap_wc() or dma_mmap_pages() underflows
the reference count and can free the object while the caller still holds
it.

The callee does not own that reference.  drm_gem_shmem_mmap() returns the
error and leaves the put to the caller, and both callers do it,
drm_gem_mmap_obj() as above and drm_gem_prime_mmap() from its own error
path.  Drop the call.

It was harmless until commit f49a51bfdc8e ("drm/shme-helpers: Fix
dma_buf_mmap forwarding bug") moved the vm_private_data assignment ahead
of the callback; before that the field was still NULL when the callback
ran and drm_gem_vm_close() put nothing.

exynos_drm_gem_mmap() and __tegra_gem_mmap() have the same error path.

Fixes: f49a51bfdc8e ("drm/shme-helpers: Fix dma_buf_mmap forwarding bug")
Cc: [email protected]
Signed-off-by: Baul Lee <[email protected]>
---
 drivers/gpu/drm/drm_gem_dma_helper.c | 2 --
 1 file changed, 2 deletions(-)

diff --git a/drivers/gpu/drm/drm_gem_dma_helper.c b/drivers/gpu/drm/drm_gem_dma_helper.c
index 1c00a71ab3c9..a34561efd1ae 100644
--- a/drivers/gpu/drm/drm_gem_dma_helper.c
+++ b/drivers/gpu/drm/drm_gem_dma_helper.c
@@ -550,8 +550,6 @@ int drm_gem_dma_mmap(struct drm_gem_dma_object *dma_obj, struct vm_area_struct *
 				  dma_obj->vaddr, dma_obj->dma_addr,
 				  vma->vm_end - vma->vm_start);
 	}
-	if (ret)
-		drm_gem_vm_close(vma);
 
 	return ret;
 }
-- 
2.50.1 (Apple Git-155)