Re: [PATCH] drm: logicvc: fix device_node refcount leak in logicvc_layers_init()

manushprajwal <[email protected]>
Newsgroups org.freedesktop.lists.dri-devel
Message-ID <[email protected]>
From: Manush Prajwal <[email protected]>

Thanks for the review. I traced this through and the UAF is real,
though it's independent of this patch, as noted:

- logicvc_layer_init() embeds drm_plane in a devm_kzalloc()'d struct
  and registers it with the unmanaged drm_universal_plane_init(), so
  the plane stays linked into drm_dev->mode_config.plane_list.
- On a later layer's init failure, logicvc_layers_init()'s error path
  calls logicvc_layer_fini() on every already-succeeded layer, which
  does list_del() + devm_kfree() immediately, but never calls
  drm_plane_cleanup() first, so the freed layer's plane is still
  linked in mode_config.plane_list.
- drmm_mode_config_init() (drivers/gpu/drm/logicvc/logicvc_drm.c)
  registers drm_mode_config_cleanup() as a drmm action tied to
  drm_dev's own refcount, which is only dropped via
  devm_drm_dev_alloc()'s devres release on the parent device, i.e.
  later than the explicit devm_kfree() above, not before it.
- So drm_mode_config_cleanup() later walks plane_list and dereferences
  the already-freed layer/plane.

The same devm_kzalloc() plus unmanaged-DRM-object pattern exists in
logicvc_crtc_init() and logicvc_interface_init(), so this looks
driver-wide rather than layer-specific.

That's a separate, pre-existing bug in the error-unwind path and out
of scope for this one-line of_node_put() fix. A real fix would need
either drm_plane_cleanup()/drm_encoder_cleanup()/drm_connector_cleanup()
calls added to the _fini() helpers before devm_kfree(), or switching
these to drmm-managed allocations. Happy to send that as a follow-up
patch if there's interest.

Signed-off-by: Manush Prajwal <[email protected]>
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.