Re: [PATCH] drm/vkms: Fix use after free and double free on init error

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



On 12/02/25 - 15:06, Louis Chauvet wrote:
> 
> 
> Le 12/02/2025 à 09:53, Thomas Zimmermann a écrit :
> > 
> > 
> > Am 12.02.25 um 09:49 schrieb José Expósito:
> > > If the driver initialization fails, the vkms_exit() function might
> > > access an uninitialized or freed default_config pointer and it might
> > > double free it.
> > > 
> > > Fix both possible errors by initializing default_config only when the
> > > driver initialization succeeded.
> > > 
> > > Reported-by: Louis Chauvet <louis.chauvet@xxxxxxxxxxx>
> > > Link: https://lore.kernel.org/all/Z5uDHcCmAwiTsGte@louis-chauvet-laptop/
> > > Fixes: 2df7af93fdad ("drm/vkms: Add vkms_config type")
> > > Signed-off-by: José Expósito <jose.exposito89@xxxxxxxxx>
> > 
> > Reviewed-by: Thomas Zimmermann <tzimmremann@xxxxxxx>
> 
> Reviewed-by: Louis Chauvet <louis.chauvet@xxxxxxxxxxx>
> 
> lore.kernel.org is broken currently, to avoid doing mistakes, I will wait
> for it to be working again so I can apply your patch using dim+b4.
> 
> (I removed danvet.vetter@xxxxxxx from CC, the mail server rejected the mail)
> 
> Thanks!
> Louis Chauvet

Hello,

I tried to apply the commit, but I have a strange issue:

	$ dim push
	Enumerating objects: 13, done.
	Counting objects: 100% (13/13), done.
	Delta compression using up to 20 threads
	Compressing objects: 100% (7/7), done.
	Writing objects: 100% (7/7), 1.67 KiB | 113.00 KiB/s, done.
	Total 7 (delta 6), reused 0 (delta 0), pack-reused 0 (from 0)
	remote:
	remote: ========================================================================
	remote:
	remote:    Equinix is shutting down its operations with us on April 30, 2025.
	remote:    They have graciously supported us for almost 5 years, but all good
	remote:    things come to an end. Given the time frame, it's going to be hard
	remote:       to make a smooth transition of the cluster to somewhere else
	remote: ([TBD](https://gitlab.freedesktop.org/freedesktop/freedesktop/-/issues/2011)).
	remote:     Please expect in the next months some hiccups in the service and
	remote:    probably at least a full week of downtime to transfer gitlab to a
	remote:                different place. All help is appreciated.
	remote:
	remote: ========================================================================
	remote:
	To gitlab.freedesktop.org:drm/misc/kernel.git
	   ff3881cc6a58..ed15511a773d  drm-misc-next -> drm-misc-next
	Pushing drm-misc-fixes to for-linux-next-fixes... Everything up-to-date
	Done.
	Out of merge window. Pushing drm-misc-next to for-linux-next... 
	remote:
	remote: ========================================================================
	remote:
	remote: ERROR: Internal API unreachable
	
	remote:
	remote: ========================================================================
	remote:
	fatal: Could not read from remote repository.
	
	Please make sure you have the correct access rights
	and the repository exists.

Is this expected?

Thanks,
Louis Chauvet

> > Thanks for posting this patch separately.
> > 
> > Best regards
> > Thomas
> > 
> > > ---
> > >    drivers/gpu/drm/vkms/vkms_drv.c | 15 +++++++++------
> > >    1 file changed, 9 insertions(+), 6 deletions(-)
> > > 
> > > diff --git a/drivers/gpu/drm/vkms/vkms_drv.c b/drivers/gpu/drm/vkms/vkms_drv.c
> > > index 7c142bfc3bd9..b6de91134a22 100644
> > > --- a/drivers/gpu/drm/vkms/vkms_drv.c
> > > +++ b/drivers/gpu/drm/vkms/vkms_drv.c
> > > @@ -235,17 +235,19 @@ static int __init vkms_init(void)
> > >    	if (!config)
> > >    		return -ENOMEM;
> > > -	default_config = config;
> > > -
> > >    	config->cursor = enable_cursor;
> > >    	config->writeback = enable_writeback;
> > >    	config->overlay = enable_overlay;
> > >    	ret = vkms_create(config);
> > > -	if (ret)
> > > +	if (ret) {
> > >    		kfree(config);
> > > +		return ret;
> > > +	}
> > > -	return ret;
> > > +	default_config = config;
> > > +
> > > +	return 0;
> > >    }
> > >    static void vkms_destroy(struct vkms_config *config)
> > > @@ -269,9 +271,10 @@ static void vkms_destroy(struct vkms_config *config)
> > >    static void __exit vkms_exit(void)
> > >    {
> > > -	if (default_config->dev)
> > > -		vkms_destroy(default_config);
> > > +	if (!default_config)
> > > +		return;
> > > +	vkms_destroy(default_config);
> > >    	kfree(default_config);
> > >    }
> > 
> 
> -- 
> Louis Chauvet, Bootlin
> Embedded Linux and Kernel engineering
> https://bootlin.com
> 



[Index of Archives]     [Linux DRI Users]     [Linux Intel Graphics]     [Linux USB Devel]     [Video for Linux]     [Linux Audio Users]     [Yosemite News]     [Linux Kernel]     [Linux SCSI]     [XFree86]     [Linux USB Devel]     [Video for Linux]     [Linux Audio Users]     [Linux Kernel]     [Linux SCSI]     [XFree86]
  Powered by Linux