All of lore.kernel.org
 help / color / mirror / Atom feed
* [PATCH] drm: use atomic helper function to get crtc_state of crtc
@ 2018-06-19 14:45 mikita.lipski
  2018-06-19 14:58 ` Michel Dänzer
  2018-06-19 15:27 ` Daniel Vetter
  0 siblings, 2 replies; 4+ messages in thread
From: mikita.lipski @ 2018-06-19 14:45 UTC (permalink / raw)
  To: boris.brezillon, daniel.vetter, dri-devel
  Cc: alexander.deucher, Mikita Lipski

From: Mikita Lipski <mikita.lipski@amd.com>

Use drm_atomic_get_crtc_state to get the crtc state in case
it has been previously freed, that might prevent use-after-free issue.

This patch fixes the bugzilla bug:
Bug 199425 - BUG: KASAN: use-after-free in drm_atomic_helper_wait_for_flip_done+0x247/0x260

Signed-off-by: Mikita Lipski <mikita.lipski@amd.com>
---
 drivers/gpu/drm/drm_atomic_helper.c | 4 +++-
 1 file changed, 3 insertions(+), 1 deletion(-)

diff --git a/drivers/gpu/drm/drm_atomic_helper.c b/drivers/gpu/drm/drm_atomic_helper.c
index e8c2493..e083f85 100644
--- a/drivers/gpu/drm/drm_atomic_helper.c
+++ b/drivers/gpu/drm/drm_atomic_helper.c
@@ -1276,9 +1276,11 @@ void drm_atomic_helper_wait_for_flip_done(struct drm_device *dev,
 	int i;
 
 	for_each_new_crtc_in_state(old_state, crtc, new_crtc_state, i) {
-		struct drm_crtc_commit *commit = new_crtc_state->commit;
+		struct drm_crtc_commit *commit;
 		int ret;
 
+		new_crtc_state = drm_atomic_get_crtc_state(old_state, crtc);
+		commit = new_crtc_state->commit;
 		if (!commit)
 			continue;
 
-- 
2.7.4

_______________________________________________
dri-devel mailing list
dri-devel@lists.freedesktop.org
https://lists.freedesktop.org/mailman/listinfo/dri-devel

^ permalink raw reply related	[flat|nested] 4+ messages in thread

end of thread, other threads:[~2018-06-19 15:48 UTC | newest]

Thread overview: 4+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2018-06-19 14:45 [PATCH] drm: use atomic helper function to get crtc_state of crtc mikita.lipski
2018-06-19 14:58 ` Michel Dänzer
2018-06-19 15:27 ` Daniel Vetter
2018-06-19 15:48   ` Ville Syrjälä

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.