Hi Krzysztof,
On Fri, Sep 11, 2026 at 06:11:45AM +0000, Krzysztof Karas wrote:
> It is possible for eb_relocate_parse_slow() to call kvfree() on
> entries outside the original exec array during following
> scenario inside eb_relocate_parse_slow():
>
> 1) eb_copy_relocations() allocates as many as eb->buffer_count
> copies for exec entries;
> 2) eb_parse() appends up to two VMAs, right after incrementing
> eb->buffer_count;
> 3) cleanup under "out" label uses this incremented buffer_count
> to release relocation pointers from exec array via kvfree(),
> not from VMA array.
>
> To amend this problem, ensure that relocation cleanup uses the
> original exec object count, excluding the VMAs appended by the
> command parser.
>
> Fixes: 8e4ba491b0ba ("drm/i915: Parse command buffer earlier in
> eb_relocate(slow)")
> Cc: [email protected] # 5.10+
> Assisted-by: GitHub-Copilot:gpt-6-astra
> Signed-off-by: Krzysztof Karas <[email protected]>
pushed to drm-intel-gt-next.
Thanks,
Andi