]> git.baikalelectronics.ru Git - kernel.git/commit
drm/vmwgfx: Stop accessing buffer objects which failed init
authorZack Rusin <zackr@vmware.com>
Wed, 8 Feb 2023 18:00:50 +0000 (13:00 -0500)
committerGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Wed, 22 Feb 2023 11:59:47 +0000 (12:59 +0100)
commit6ae9f64400d5e5a28b2a53e9365c7da1a2b7cee9
treeb6f3d15528944855cafa5523bc102bb8f3f7e233
parenta4044044d76fd4d76f2a2d5de7dfb8fc96338886
drm/vmwgfx: Stop accessing buffer objects which failed init

commit 45e98eec76a60191c5ec49ddafba48e083702378 upstream.

ttm_bo_init_reserved on failure puts the buffer object back which
causes it to be deleted, but kfree was still being called on the same
buffer in vmw_bo_create leading to a double free.

After the double free the vmw_gem_object_create_with_handle was
setting the gem function objects before checking the return status
of vmw_bo_create leading to null pointer access.

Fix the entire path by relaying on ttm_bo_init_reserved to delete the
buffer objects on failure and making sure the return status is checked
before setting the gem function objects on the buffer object.

Signed-off-by: Zack Rusin <zackr@vmware.com>
Fixes: fa65112d703e ("drm/vmwgfx: Implement DRIVER_GEM")
Reviewed-by: Maaz Mombasawala <mombasawalam@vmware.com>
Reviewed-by: Martin Krastev <krastevm@vmware.com>
Link: https://patchwork.freedesktop.org/patch/msgid/20230208180050.2093426-1-zack@kde.org
(cherry picked from commit 89ab519cd7784a7026c5dfad10edc7485760092f)
Cc: <stable@vger.kernel.org> # v5.17+
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
drivers/gpu/drm/vmwgfx/vmwgfx_bo.c
drivers/gpu/drm/vmwgfx/vmwgfx_gem.c