Fix parameter validation to avoid possible NULL pointer dereference from pvr_fw_object_destroy() when handling allocation failures.
Sashiko report: If pvr_gem_object_create() fails in pvr_fw_object_create_and_map_common(), fw_obj->gem is explicitly set to NULL before jumping to the error cleanup path. The cleanup path then calls pvr_fw_object_destroy(). Reported-by: Sashiko <[email protected]> Link: https://lore.kernel.org/dri-devel/[email protected]/ Fixes: cc1aeedb98ad ("drm/imagination: Implement firmware infrastructure and META FW support") Signed-off-by: Alexandru Dadu <[email protected]> --- Changes in v4: - Move the structs declarations after the early return to fix V3. - Added kfree() to the early return path. - Link to v3: https://patch.msgid.link/20260922-fix-null-pointer-dereference-v3-1-f099763ed...@imgtec.com Changes in v3: - Skimed the commit message removing redundant information. - Refactored the parameter validation to return early. - Link to v2: https://patch.msgid.link/20260903-fix-null-pointer-dereference-v2-1-138ff9b6f...@imgtec.com Changes in v2: - Commit message and cover letter updates. - Link to v1: https://patch.msgid.link/20260812-fix-null-pointer-dereference-v1-1-f69b2ffe9...@imgtec.com To: Alessio Belle <[email protected]> To: Luigi Santivetti <[email protected]> To: Maarten Lankhorst <[email protected]> To: Maxime Ripard <[email protected]> To: Thomas Zimmermann <[email protected]> To: David Airlie <[email protected]> To: Simona Vetter <[email protected]> To: Donald Robson <[email protected]> To: Sarah Walker <[email protected]> Cc: [email protected] Cc: [email protected] Cc: [email protected] --- drivers/gpu/drm/imagination/pvr_fw.c | 11 +++++++++-- 1 file changed, 9 insertions(+), 2 deletions(-) diff --git a/drivers/gpu/drm/imagination/pvr_fw.c b/drivers/gpu/drm/imagination/pvr_fw.c index 850a3ec8e775..39d70f51f126 100644 --- a/drivers/gpu/drm/imagination/pvr_fw.c +++ b/drivers/gpu/drm/imagination/pvr_fw.c @@ -1425,6 +1425,14 @@ pvr_fw_object_create_and_map_offset(struct pvr_device *pvr_dev, */ void pvr_fw_object_destroy(struct pvr_fw_object *fw_obj) { + if (!fw_obj) + return; + + if (!fw_obj->gem) { + kfree(fw_obj); + return; + } + struct pvr_gem_object *pvr_obj = fw_obj->gem; struct drm_gem_object *gem_obj = gem_from_pvr_gem(pvr_obj); struct pvr_device *pvr_dev = to_pvr_device(gem_obj->dev); @@ -1439,8 +1447,7 @@ void pvr_fw_object_destroy(struct pvr_fw_object *fw_obj) return; } - if (fw_obj->gem) - pvr_gem_object_put(fw_obj->gem); + pvr_gem_object_put(fw_obj->gem); kfree(fw_obj); } --- base-commit: bd4f284df04d76fd65e57141cb1e6e7a49e4c3cb change-id: 20260812-fix-null-pointer-dereference-2c891142d988 Best regards, -- Alexandru Dadu <[email protected]>
