On Tue, 2026-09-22 at 09:11 +0300, Alexandru Dadu wrote: > Fix parameter validation to avoid possible NULL pointer dereference from > pvr_fw_object_destroy() when handling allocation failures. > > Sashiko report: > If pvr_gem_object_create() fails in > pvr_fw_object_create_and_map_common(), fw_obj->gem is explicitly set to > NULL before jumping to the error cleanup path. > The cleanup path then calls pvr_fw_object_destroy(). > > Reported-by: Sashiko <[email protected]> > Link: > https://lore.kernel.org/dri-devel/[email protected]/ > Fixes: cc1aeedb98ad ("drm/imagination: Implement firmware infrastructure and > META FW support") > Signed-off-by: Alexandru Dadu <[email protected]> > --- > Changes in v4: > - Move the structs declarations after the early return to fix V3. > - Added kfree() to the early return path. > - Link to v3: > https://patch.msgid.link/20260922-fix-null-pointer-dereference-v3-1-f099763ed...@imgtec.com > > Changes in v3: > - Skimed the commit message removing redundant information. > - Refactored the parameter validation to return early. > - Link to v2: > https://patch.msgid.link/20260903-fix-null-pointer-dereference-v2-1-138ff9b6f...@imgtec.com > > Changes in v2: > - Commit message and cover letter updates. > - Link to v1: > https://patch.msgid.link/20260812-fix-null-pointer-dereference-v1-1-f69b2ffe9...@imgtec.com > > To: Alessio Belle <[email protected]> > To: Luigi Santivetti <[email protected]> > To: Maarten Lankhorst <[email protected]> > To: Maxime Ripard <[email protected]> > To: Thomas Zimmermann <[email protected]> > To: David Airlie <[email protected]> > To: Simona Vetter <[email protected]> > To: Donald Robson <[email protected]> > To: Sarah Walker <[email protected]> > Cc: [email protected] > Cc: [email protected] > Cc: [email protected] > --- > drivers/gpu/drm/imagination/pvr_fw.c | 11 +++++++++-- > 1 file changed, 9 insertions(+), 2 deletions(-) > > diff --git a/drivers/gpu/drm/imagination/pvr_fw.c > b/drivers/gpu/drm/imagination/pvr_fw.c > index 850a3ec8e775..39d70f51f126 100644 > --- a/drivers/gpu/drm/imagination/pvr_fw.c > +++ b/drivers/gpu/drm/imagination/pvr_fw.c > @@ -1425,6 +1425,14 @@ pvr_fw_object_create_and_map_offset(struct pvr_device > *pvr_dev, > */ > void pvr_fw_object_destroy(struct pvr_fw_object *fw_obj) > { > + if (!fw_obj) > + return; > + > + if (!fw_obj->gem) { > + kfree(fw_obj); > + return; > + } > + > struct pvr_gem_object *pvr_obj = fw_obj->gem; > struct drm_gem_object *gem_obj = gem_from_pvr_gem(pvr_obj); > struct pvr_device *pvr_dev = to_pvr_device(gem_obj->dev);
I have a preference for variable declarations at the top, then checks, then assignments, but don't feel strongly about it, so: Reviewed-by: Alessio Belle <[email protected]> Thanks, Alessio > @@ -1439,8 +1447,7 @@ void pvr_fw_object_destroy(struct pvr_fw_object *fw_obj) > return; > } > > - if (fw_obj->gem) > - pvr_gem_object_put(fw_obj->gem); > + pvr_gem_object_put(fw_obj->gem); > > kfree(fw_obj); > } > > --- > base-commit: bd4f284df04d76fd65e57141cb1e6e7a49e4c3cb > change-id: 20260812-fix-null-pointer-dereference-2c891142d988 > > Best regards, > -- > Alexandru Dadu <[email protected]> >
