[PATCH 2/2] drm/nouveau: prevent NULL deref of gr in GETPARAM_GRAPH_UNITS
Zhenhao Wan <[email protected]>
| Newsgroups | org.freedesktop.lists.nouveau,org.freedesktop.lists.dri-devel,org.kernel.vger.linux-kernel,org.kernel.vger.stable |
|---|---|
| Message-ID | <20260812-nouveau-nvkm-absent-subdev-null-deref-v1-2-7e057f6aeba0@gmail.com> |
nouveau_abi16_ioctl_getparam() fetches the graphics engine with gr = nvxx_gr(drm) (i.e. drm->nvkm->gr) and, for the NOUVEAU_GETPARAM_GRAPH_UNITS parameter, passes it straight to nvkm_gr_units(), which dereferences gr->func with no NULL check. When graphics-engine construction returns -ENODEV, NVKM treats it as an optional absent engine: the NVKM_LAYOUT_ONCE device constructor deletes the subdevice, leaves device->gr == NULL and continues probing, and Nouveau still registers a render node. An unprivileged client holding a /dev/dri/renderD* fd can then issue DRM_IOCTL_NOUVEAU_GETPARAM with NOUVEAU_GETPARAM_GRAPH_UNITS and oops the kernel on the NULL gr. Report 0 units when gr is absent. This matches nvkm_gr_units() itself, which already returns 0 when the engine exposes no units callback. Reported-by: Yuhao Jiang <[email protected]> Assisted-by: Claude:claude-opus-5 Cc: [email protected] Signed-off-by: Zhenhao Wan <[email protected]> --- drivers/gpu/drm/nouveau/nouveau_abi16.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/drivers/gpu/drm/nouveau/nouveau_abi16.c b/drivers/gpu/drm/nouveau/nouveau_abi16.c index 291203121f0c..dd3f8d386377 100644 --- a/drivers/gpu/drm/nouveau/nouveau_abi16.c +++ b/drivers/gpu/drm/nouveau/nouveau_abi16.c @@ -306,7 +306,7 @@ nouveau_abi16_ioctl_getparam(ABI16_IOCTL_ARGS) getparam->value = 1; break; case NOUVEAU_GETPARAM_GRAPH_UNITS: - getparam->value = nvkm_gr_units(gr); + getparam->value = gr ? nvkm_gr_units(gr) : 0; break; case NOUVEAU_GETPARAM_EXEC_PUSH_MAX: { int ib_max = getparam_dma_ib_max(device); -- 2.34.1