From: Artem Dinaburg <artem@trailofbits.com>
To: stable@vger.kernel.org
Cc: Artem Dinaburg <artem@trailofbits.com>,
Greg Kroah-Hartman <gregkh@linuxfoundation.org>,
Sasha Levin <sashal@kernel.org>,
Suraj Kandpal <suraj.kandpal@intel.com>,
Dnyaneshwar Bhadane <dnyaneshwar.bhadane@intel.com>,
Jani Nikula <jani.nikula@linux.intel.com>,
Joonas Lahtinen <joonas.lahtinen@linux.intel.com>,
Rodrigo Vivi <rodrigo.vivi@intel.com>,
Tvrtko Ursulin <tvrtko.ursulin@linux.intel.com>,
Tvrtko Ursulin <tursulin@ursulin.net>,
David Airlie <airlied@gmail.com>, Daniel Vetter <daniel@ffwll.ch>,
Simona Vetter <simona@ffwll.ch>,
intel-gfx@lists.freedesktop.org, intel-xe@lists.freedesktop.org,
dri-devel@lists.freedesktop.org, linux-kernel@vger.kernel.org
Subject: [PATCH 6.6.y v2 2/2] drm/i915/hdcp: Add encoder check in hdcp2_get_capability
Date: Tue, 29 Sep 2026 21:03:21 -0400 [thread overview]
Message-ID: <20260930010323.93999-3-artem@trailofbits.com> (raw)
In-Reply-To: <20260930010323.93999-1-artem@trailofbits.com>
From: Suraj Kandpal <suraj.kandpal@intel.com>
[ Upstream commit d34f4f058edf1235c103ca9c921dc54820d14d40 ]
Add encoder check in intel_hdcp2_get_capability to avoid
null pointer error.
[ Backport to 6.6.y: this tree predates the later intel_connector
conversion, so the unsafe intel_attached_dig_port() call is still in
intel_hdcp2_capable() rather than the DP and HDMI shims.
Put the same encoder guard before that common dereference and return
false through the bool API when no encoder is attached. ]
Signed-off-by: Suraj Kandpal <suraj.kandpal@intel.com>
Reviewed-by: Dnyaneshwar Bhadane <dnyaneshwar.bhadane@intel.com>
Link: https://patchwork.freedesktop.org/patch/msgid/20240722064451.3610512-3-suraj.kandpal@intel.com
Assisted-by: LLM
Signed-off-by: Artem Dinaburg <artem@trailofbits.com>
---
CVE: CVE-2024-53050
Upstream: d34f4f058edf1235c103ca9c921dc54820d14d40
Backport: guard the common 6.6.y bool helper because the later DP/HDMI
split is not present in this tree.
Review: https://lore.kernel.org/r/2026-09-29-daily-reply-0012-re-i915-hdcp-encoder-check-v2-6-6@kernel.org
drivers/gpu/drm/i915/display/intel_hdcp.c | 7 ++++++-
1 file changed, 6 insertions(+), 1 deletion(-)
diff --git a/drivers/gpu/drm/i915/display/intel_hdcp.c b/drivers/gpu/drm/i915/display/intel_hdcp.c
index f7987fb90bb1..89e378f71d67 100644
--- a/drivers/gpu/drm/i915/display/intel_hdcp.c
+++ b/drivers/gpu/drm/i915/display/intel_hdcp.c
@@ -168,11 +168,16 @@ bool intel_hdcp_capable(struct intel_connector *connector)
/* Is HDCP2.2 capable on Platform and Sink */
bool intel_hdcp2_capable(struct intel_connector *connector)
{
- struct intel_digital_port *dig_port = intel_attached_dig_port(connector);
+ struct intel_digital_port *dig_port;
struct drm_i915_private *i915 = to_i915(connector->base.dev);
struct intel_hdcp *hdcp = &connector->hdcp;
bool capable = false;
+ if (!intel_attached_encoder(connector))
+ return capable;
+
+ dig_port = intel_attached_dig_port(connector);
+
/* I915 support for HDCP2.2 */
if (!hdcp->hdcp2_supported)
return false;
--
2.39.5
next prev parent reply other threads:[~2026-09-30 13:49 UTC|newest]
Thread overview: 6+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-30 1:03 [PATCH 6.6.y v2 0/2] drm/i915/hdcp: guard both capability checks Artem Dinaburg
2026-09-30 1:03 ` [PATCH 6.6.y v2 1/2] drm/i915/hdcp: Add encoder check in intel_hdcp_get_capability Artem Dinaburg
2026-09-30 1:03 ` Artem Dinaburg [this message]
2026-09-30 14:37 ` ✗ LGCI.VerificationFailed: failure for drm/i915/hdcp: guard both capability checks Patchwork
2026-09-30 17:23 ` Patchwork
2026-10-01 13:52 ` [PATCH 6.6.y v2 0/2] " Sasha Levin
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260930010323.93999-3-artem@trailofbits.com \
--to=artem@trailofbits.com \
--cc=airlied@gmail.com \
--cc=daniel@ffwll.ch \
--cc=dnyaneshwar.bhadane@intel.com \
--cc=dri-devel@lists.freedesktop.org \
--cc=gregkh@linuxfoundation.org \
--cc=intel-gfx@lists.freedesktop.org \
--cc=intel-xe@lists.freedesktop.org \
--cc=jani.nikula@linux.intel.com \
--cc=joonas.lahtinen@linux.intel.com \
--cc=linux-kernel@vger.kernel.org \
--cc=rodrigo.vivi@intel.com \
--cc=sashal@kernel.org \
--cc=simona@ffwll.ch \
--cc=stable@vger.kernel.org \
--cc=suraj.kandpal@intel.com \
--cc=tursulin@ursulin.net \
--cc=tvrtko.ursulin@linux.intel.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.