Patch "drm/msm: Fix null ptr access msm_ioctl_gem_submit()" has been added to the 5.15-stable tree

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



This is a note to let you know that I've just added the patch titled

    drm/msm: Fix null ptr access msm_ioctl_gem_submit()

to the 5.15-stable tree which can be found at:
    http://www.kernel.org/git/?p=linux/kernel/git/stable/stable-queue.git;a=summary

The filename of the patch is:
     drm-msm-fix-null-ptr-access-msm_ioctl_gem_submit.patch
and it can be found in the queue-5.15 subdirectory.

If you, or anyone else, feels it should not be added to the stable tree,
please let <stable@xxxxxxxxxxxxxxx> know about it.



commit 5a5296f489f07b09ec402decb275e0ef40397551
Author: Akhil P Oommen <akhilpo@xxxxxxxxxxxxxx>
Date:   Thu Nov 18 15:50:30 2021 +0530

    drm/msm: Fix null ptr access msm_ioctl_gem_submit()
    
    [ Upstream commit 26d776fd0f79f093a5d0ce1a4c7c7a992bc3264c ]
    
    Fix the below null pointer dereference in msm_ioctl_gem_submit():
    
     26545.260705:   Call trace:
     26545.263223:    kref_put+0x1c/0x60
     26545.266452:    msm_ioctl_gem_submit+0x254/0x744
     26545.270937:    drm_ioctl_kernel+0xa8/0x124
     26545.274976:    drm_ioctl+0x21c/0x33c
     26545.278478:    drm_compat_ioctl+0xdc/0xf0
     26545.282428:    __arm64_compat_sys_ioctl+0xc8/0x100
     26545.287169:    el0_svc_common+0xf8/0x250
     26545.291025:    do_el0_svc_compat+0x28/0x54
     26545.295066:    el0_svc_compat+0x10/0x1c
     26545.298838:    el0_sync_compat_handler+0xa8/0xcc
     26545.303403:    el0_sync_compat+0x188/0x1c0
     26545.307445:   Code: d503201f d503201f 52800028 4b0803e8 (b8680008)
     26545.318799:   Kernel panic - not syncing: Oops: Fatal exception
    
    Signed-off-by: Akhil P Oommen <akhilpo@xxxxxxxxxxxxxx>
    Link: https://lore.kernel.org/r/20211118154903.2.I3ae019673a0cc45d83a193a7858748dd03dbb820@changeid
    Signed-off-by: Rob Clark <robdclark@xxxxxxxxxxxx>
    Signed-off-by: Sasha Levin <sashal@xxxxxxxxxx>

diff --git a/drivers/gpu/drm/msm/msm_gem_submit.c b/drivers/gpu/drm/msm/msm_gem_submit.c
index a38f23be497d8..d9aef97eb93ad 100644
--- a/drivers/gpu/drm/msm/msm_gem_submit.c
+++ b/drivers/gpu/drm/msm/msm_gem_submit.c
@@ -780,6 +780,7 @@ int msm_ioctl_gem_submit(struct drm_device *dev, void *data,
 		args->nr_cmds);
 	if (IS_ERR(submit)) {
 		ret = PTR_ERR(submit);
+		submit = NULL;
 		goto out_unlock;
 	}
 



[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[Index of Archives]     [Linux USB Devel]     [Linux Audio Users]     [Yosemite News]     [Linux Kernel]     [Linux SCSI]

  Powered by Linux