Applied to drm-misc-fixes

On 7/14/26 17:58, Lizhi Hou wrote:

On 7/13/26 10:30, Doruk Tan Ozturk wrote:
amdxdna_drm_submit_execbuf() passes the user-supplied command BO handle
straight into amdxdna_cmd_submit() with drv_cmd == NULL. When the handle
is AMDXDNA_INVALID_BO_HANDLE (0), the block that fetches job->cmd_bo is
skipped, leaving it NULL, and no check rejects it on the user path (the
!job->cmd_bo guard lives inside the != INVALID branch).

The job is then armed and pushed to the DRM scheduler.
aie2_sched_job_run() takes the drv_cmd == NULL path and calls
amdxdna_cmd_set_state(job->cmd_bo) -> amdxdna_gem_vmap(NULL) ->
to_gobj(NULL)->dev, a NULL pointer dereference in the drm_sched worker.
A process with access to the accel node on a system with a probed AMD NPU
can trigger a kernel oops with a single AMDXDNA_EXEC_CMD ioctl
(cmd_handles = 0).

Only internal driver commands (SYNC_DEBUG_BO / ATTACH_DEBUG_BO)
legitimately pass AMDXDNA_INVALID_BO_HANDLE, and they always set drv_cmd.
Reject the invalid handle for user submissions (drv_cmd == NULL) at the
submit choke point so every user path is covered.

Fixes: aac243092b70 ("accel/amdxdna: Add command execution")
Cc: [email protected]
Found by 0sec automated security-research tooling (https://0sec.ai).
Assisted-by: 0sec:claude-opus-4-8
Signed-off-by: Doruk Tan Ozturk <[email protected]>
---
  drivers/accel/amdxdna/amdxdna_ctx.c | 10 ++++++++++
  1 file changed, 10 insertions(+)

diff --git a/drivers/accel/amdxdna/amdxdna_ctx.c b/drivers/accel/amdxdna/amdxdna_ctx.c
index 8f8df9d04ec5..a5c8c2c4de6d 100644
--- a/drivers/accel/amdxdna/amdxdna_ctx.c
+++ b/drivers/accel/amdxdna/amdxdna_ctx.c
@@ -603,6 +603,16 @@ int amdxdna_cmd_submit(struct amdxdna_client *client,
              ret = -EINVAL;
              goto free_job;
          }
+    } else if (!drv_cmd) {
+        /*
+         * Only internal driver commands (drv_cmd != NULL) may omit a
+         * command BO. A user command submission with the invalid handle +         * would leave job->cmd_bo NULL and later fault when the scheduler
+         * dereferences it in amdxdna_cmd_set_state().
+         */
+        XDNA_DBG(xdna, "Command BO handle required for user submission");
+        ret = -EINVAL;
+        goto free_job;
Reviewed-by: Lizhi Hou <[email protected]>
      }
        ret = amdxdna_arg_bos_lookup(client, job, arg_bo_hdls, arg_bo_cnt);

Reply via email to