From: sashiko-bot@kernel.org
To: "Guangshuo Li" <lgs201920130244@gmail.com>
Cc: dri-devel@lists.freedesktop.org
Subject: Re: [PATCH] drm/panel: novatek-nt35950: fix potential use-after-free on attach failure
Date: Sun, 13 Sep 2026 13:31:36 +0000 [thread overview]
Message-ID: <20260913133137.0036E1F000FF@smtp.kernel.org> (raw)
In-Reply-To: <20260913131849.1561742-1-lgs201920130244@gmail.com>
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
Pre-existing issues:
- [High] Panel is published globally before initialization is complete, exposing a race condition that leads to Use-After-Free of DSI devices and devm-managed resources if an error occurs.
--
commit 06a7a4ea81475e17e3e167d525f0a49d30e5896a
Author: Guangshuo Li <lgs201920130244@gmail.com>
drm/panel: novatek-nt35950: fix potential use-after-free on attach failure
This commit attempts to fix a potential use-after-free issue by detaching
DSI hosts and removing the panel from the DRM panel registry if
mipi_dsi_attach() fails during probe.
> diff --git a/drivers/gpu/drm/panel/panel-novatek-nt35950.c b/drivers/gpu/drm/panel/panel-novatek-nt35950.c
> index 94aa6489d99fc..8edd0aa363cec 100644
> --- a/drivers/gpu/drm/panel/panel-novatek-nt35950.c
> +++ b/drivers/gpu/drm/panel/panel-novatek-nt35950.c
> @@ -514,12 +514,19 @@ static int nt35950_probe(struct mipi_dsi_device *dsi)
>
> ret = mipi_dsi_attach(nt->dsi[i]);
> if (ret < 0) {
> - /* If we fail to attach to either host, we're done */
> + dev_err_probe(dev, ret,
> + "Cannot attach to DSI%d host.\n", i);
> +
> + /* Detach from all previously attached DSI hosts */
> + while (i--)
> + mipi_dsi_detach(nt->dsi[i]);
> +
> if (num_dsis == 2)
> mipi_dsi_device_unregister(nt->dsi[1]);
>
> - return dev_err_probe(dev, ret,
> - "Cannot attach to DSI%d host.\n", i);
> + drm_panel_remove(&nt->panel);
> +
> + return ret;
[Severity: High]
This is a pre-existing issue, but does this still leave a race condition since
the panel is published globally before mipi_dsi_attach() is called?
Earlier in nt35950_probe(), the panel is published globally:
drm_panel_add(&nt->panel);
If a concurrent thread (like a display controller) discovers the panel via
of_drm_find_panel() and acquires a reference, and then mipi_dsi_attach()
fails, this error path executes:
if (num_dsis == 2)
mipi_dsi_device_unregister(nt->dsi[1]);
drm_panel_remove(&nt->panel);
The concurrent thread will keep the panel structure alive. If that thread
subsequently initiates a display modeset, it will call drm_panel_prepare()
which invokes nt35950_on() and dereferences the now-freed secondary DSI
device:
nt->dsi[1]->mode_flags |= MIPI_DSI_MODE_LPM;
Could drm_panel_add() be moved to the very end of the probe function, after
all initializations (including mipi_dsi_attach) have successfully completed?
> }
> }
>
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260913131849.1561742-1-lgs201920130244@gmail.com?part=1
prev parent reply other threads:[~2026-09-13 13:31 UTC|newest]
Thread overview: 2+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-13 13:18 [PATCH] drm/panel: novatek-nt35950: fix potential use-after-free on attach failure Guangshuo Li
2026-09-13 13:31 ` sashiko-bot [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260913133137.0036E1F000FF@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=dri-devel@lists.freedesktop.org \
--cc=lgs201920130244@gmail.com \
--cc=sashiko-reviews@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.