From: Dan Carpenter <[email protected]>
[ Upstream commit 4018651ba5c409034149f297d3dd3328b91561fd ]
In mtk_crtc_create(), if the call to mbox_request_channel() fails then we
set the "mtk_crtc->cmdq_client.chan" pointer to NULL. In that situation,
we do not call cmdq_pkt_create().
During the cleanup, we need to check if the "mtk_crtc->cmdq_client.chan"
is NULL first before calling cmdq_pkt_destroy(). Calling
cmdq_pkt_destroy() is unnecessary if we didn't call cmdq_pkt_create() and
it will result in a NULL pointer dereference.
[ Backport to 6.6.y: used the older Mediatek CRTC file and helper names. ]
Fixes: 7627122fd1c0 ("drm/mediatek: Add cmdq_handle in mtk_crtc")
Signed-off-by: Dan Carpenter <[email protected]>
Reviewed-by: AngeloGioacchino Del Regno
<[email protected]>
Reviewed-by: CK Hu <[email protected]>
Link:
https://patchwork.kernel.org/project/dri-devel/patch/[email protected]/
Signed-off-by: Chun-Kuang Hu <[email protected]>
Assisted-by: LLM
Signed-off-by: Artem Dinaburg <[email protected]>
---
Hi Greg, Sasha, and drm mediatek maintainers,
I am working through the small CVE backports still missing from 6.6.y.
This one addresses CVE-2024-53056. It skips command-packet destruction when
channel setup failed before packet creation.
The fix is already present in 6.12.y, 6.18.y, and 7.2.y, but not in 6.6.y.
This fix also affects 6.1.y, which will need a separate backport; this
submission contains only the 6.6.y patch.
The target-specific adjustment is recorded in the bracketed note above.
Could you please queue it for 6.6.y?
CVE: CVE-2024-53056
Upstream: 4018651ba5c409034149f297d3dd3328b91561fd
AI assistance: An LLM helped identify, adapt, and validate this backport; I
reviewed the resulting code and validation evidence.
Thanks,
Artem Dinaburg
drivers/gpu/drm/mediatek/mtk_drm_crtc.c | 3 +--
1 file changed, 1 insertion(+), 2 deletions(-)
diff --git a/drivers/gpu/drm/mediatek/mtk_drm_crtc.c
b/drivers/gpu/drm/mediatek/mtk_drm_crtc.c
index 859dffe4513722..1e8052a0425ee5 100644
--- a/drivers/gpu/drm/mediatek/mtk_drm_crtc.c
+++ b/drivers/gpu/drm/mediatek/mtk_drm_crtc.c
@@ -163,9 +163,8 @@ static void mtk_drm_crtc_destroy(struct drm_crtc *crtc)
mtk_mutex_put(mtk_crtc->mutex);
#if IS_REACHABLE(CONFIG_MTK_CMDQ)
- mtk_drm_cmdq_pkt_destroy(&mtk_crtc->cmdq_handle);
-
if (mtk_crtc->cmdq_client.chan) {
+ mtk_drm_cmdq_pkt_destroy(&mtk_crtc->cmdq_handle);
mbox_free_channel(mtk_crtc->cmdq_client.chan);
mtk_crtc->cmdq_client.chan = NULL;
}
--
2.39.5