Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
Pre-existing issues:
- [High] Allocating the DRM encoder with devm_kzalloc() causes a use-after-free on device unbind if userspace holds a DRM file descriptor open.
--
--- Patch [3]: [PATCH v3 03/11] drm/mxsfb/lcdif: use dev_err_probe() consistently in lcdif_attach_bridge ---
commit acad1a96fd5b86c6ee99f36bf8b226bbe0b10059
Author: Luca Ceresoli <[email protected]>
drm/mxsfb/lcdif: use dev_err_probe() consistently in lcdif_attach_bridge
This commit updates error paths in lcdif_attach_bridge() to consistently use
dev_err_probe() instead of dev_err(), simplifying the code and improving
error reporting.
> diff --git a/drivers/gpu/drm/mxsfb/lcdif_drv.c b/drivers/gpu/drm/mxsfb/lcdif_drv.c
> index 8da8a265c05c8..1c76709c4d94d 100644
> --- a/drivers/gpu/drm/mxsfb/lcdif_drv.c
> +++ b/drivers/gpu/drm/mxsfb/lcdif_drv.c
[ ... ]
> @@ -75,20 +73,18 @@ static int lcdif_attach_bridge(struct lcdif_drm_private *lcdif)
> of_ep.id);
>
> encoder = devm_kzalloc(dev, sizeof(*encoder), GFP_KERNEL);
[Severity: High]
This is a pre-existing issue, but could this devm_kzalloc() cause a
use-after-free on device unbind?
The DRM device is initialized with drmm_mode_config_init(), which ties
drm_mode_config_cleanup() to the drm_device lifetime. If userspace holds a DRM
file descriptor open during driver unbind, devres will free the encoder memory
tied to the physical device.
Later, when the last DRM file descriptor is closed, drm_mode_config_cleanup()
will iterate over the mode config's encoder list and access the already freed
encoder to call encoder->funcs->destroy(), leading to a use-after-free.
> - if (!encoder) {
> - dev_err(dev, "Failed to allocate encoder for endpoint%u\n",
> - of_ep.id);
> - return -ENOMEM;
> - }
> + if (!encoder)
> + return dev_err_probe(dev, -ENOMEM,
> + "Failed to allocate encoder for endpoint%u\n",
> + of_ep.id);
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260402-drm-lcdif-dbanc-v3-0-27cd247a0847-LDxbnhwyfcJBDgjK7y7TUQ@public.gmane.org?part=3
lmpx.com only provides a reader for public news (NNTP) servers. It is not
affiliated with the servers or forums shown here and is not responsible for
the content of articles, which is written by their respective authors.