* [PATCH] drm/tegra: Fix bo reference leak in host1x_reloc_copy_from_user()
@ 2026-09-16 18:25 Wentao Liang
2026-09-16 18:37 ` sashiko-bot
` (2 more replies)
0 siblings, 3 replies; 4+ messages in thread
From: Wentao Liang @ 2026-09-16 18:25 UTC (permalink / raw)
To: airlied
Cc: dri-devel, jonathanh, linux-kernel, linux-tegra, mperttunen,
simona, thierry.reding, Wentao Liang, stable
If the lookup of the relocation target fails after the command buffer
object has been looked up, the reference taken for the latter is not
recorded in the caller's refs[] array and is never released. Drop it
before returning.
Fixes: 961e3beae3b2 ("drm/tegra: Make job submission 64-bit safe")
Cc: stable@vger.kernel.org
Signed-off-by: Wentao Liang <vulab@iscas.ac.cn>
---
drivers/gpu/drm/tegra/drm.c | 4 +++-
1 file changed, 3 insertions(+), 1 deletion(-)
diff --git a/drivers/gpu/drm/tegra/drm.c b/drivers/gpu/drm/tegra/drm.c
index 1dcef4e7d104..4e4d41c527c6 100644
--- a/drivers/gpu/drm/tegra/drm.c
+++ b/drivers/gpu/drm/tegra/drm.c
@@ -159,8 +159,10 @@ static int host1x_reloc_copy_from_user(struct host1x_reloc *dest,
return -ENOENT;
dest->target.bo = tegra_gem_lookup(file, target);
- if (!dest->target.bo)
+ if (!dest->target.bo) {
+ drm_gem_object_put(dest->cmdbuf.bo);
return -ENOENT;
+ }
return 0;
}
--
2.34.1
^ permalink raw reply related [flat|nested] 4+ messages in thread
* Re: [PATCH] drm/tegra: Fix bo reference leak in host1x_reloc_copy_from_user()
2026-09-16 18:25 [PATCH] drm/tegra: Fix bo reference leak in host1x_reloc_copy_from_user() Wentao Liang
@ 2026-09-16 18:37 ` sashiko-bot
2026-09-17 7:35 ` kernel test robot
2026-09-17 8:41 ` kernel test robot
2 siblings, 0 replies; 4+ messages in thread
From: sashiko-bot @ 2026-09-16 18:37 UTC (permalink / raw)
To: Wentao Liang; +Cc: dri-devel
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [High] drm/tegra: type confusion and memory corruption in host1x_reloc_copy_from_user
--
commit 6284447bfe9e49ad17b9df316519006595821f25
Author: Wentao Liang <vulab@iscas.ac.cn>
drm/tegra: Fix bo reference leak in host1x_reloc_copy_from_user()
This commit fixes a reference leak on the command buffer object when the
subsequent lookup for the relocation target fails. It drops the reference
before returning the error.
> diff --git a/drivers/gpu/drm/tegra/drm.c b/drivers/gpu/drm/tegra/drm.c
> index 324480c87fb1f..1a70d37b8c1f3 100644
> --- a/drivers/gpu/drm/tegra/drm.c
> +++ b/drivers/gpu/drm/tegra/drm.c
> @@ -159,8 +159,10 @@ static int host1x_reloc_copy_from_user(struct host1x_reloc *dest,
> return -ENOENT;
>
> dest->target.bo = tegra_gem_lookup(file, target);
> - if (!dest->target.bo)
> + if (!dest->target.bo) {
> + drm_gem_object_put(dest->cmdbuf.bo);
[Severity: High]
Does this cause memory corruption due to a type mismatch?
Looking at host1x_reloc_copy_from_user(), dest->cmdbuf.bo is a struct
host1x_bo pointer. Passing it to drm_gem_object_put(), which expects a
struct drm_gem_object pointer, appears to lead to type confusion.
When tegra_gem_lookup(file, target) fails and this error path is taken,
drm_gem_object_put() will attempt to decrement the reference count by
treating the struct host1x_bo as a struct drm_gem_object. This is likely
to decrement the first member of struct host1x_bo, which is its ops vtable
pointer, instead of an actual kref.
Since this is reachable from userspace via the DRM_IOCTL_TEGRA_SUBMIT ioctl
by supplying a valid cmdbuf but an invalid target BO, could this corrupt
the vtable pointer and lead to crashes or potential control-flow hijacking
when the ops are later used?
> return -ENOENT;
> + }
>
> return 0;
> }
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260916182550.2091797-1-vulab@iscas.ac.cn?part=1
^ permalink raw reply [flat|nested] 4+ messages in thread
* Re: [PATCH] drm/tegra: Fix bo reference leak in host1x_reloc_copy_from_user()
2026-09-16 18:25 [PATCH] drm/tegra: Fix bo reference leak in host1x_reloc_copy_from_user() Wentao Liang
2026-09-16 18:37 ` sashiko-bot
@ 2026-09-17 7:35 ` kernel test robot
2026-09-17 8:41 ` kernel test robot
2 siblings, 0 replies; 4+ messages in thread
From: kernel test robot @ 2026-09-17 7:35 UTC (permalink / raw)
To: Wentao Liang, airlied
Cc: oe-kbuild-all, dri-devel, jonathanh, linux-kernel, linux-tegra,
mperttunen, simona, thierry.reding, Wentao Liang, stable
Hi Wentao,
kernel test robot noticed the following build errors:
[auto build test ERROR on tegra/for-next]
[also build test ERROR on daeinki-drm-exynos/exynos-drm-next drm/drm-next drm-i915/for-linux-next drm-i915/for-linux-next-fixes drm-misc/drm-misc-next drm-tip/drm-tip linus/master v7.3-rc3 next-20260916]
[If your patch is applied to the wrong git tree, kindly drop us a note.
And when submitting patch, we suggest to use '--base' as documented in
https://git-scm.com/docs/git-format-patch#_base_tree_information]
url: https://github.com/intel-lab-lkp/linux/commits/Wentao-Liang/drm-tegra-Fix-bo-reference-leak-in-host1x_reloc_copy_from_user/20260916-182550
base: https://git.kernel.org/pub/scm/linux/kernel/git/tegra/linux.git for-next
patch link: https://lore.kernel.org/r/20260916182550.2091797-1-vulab%40iscas.ac.cn
patch subject: [PATCH] drm/tegra: Fix bo reference leak in host1x_reloc_copy_from_user()
config: arc-randconfig-1001-20260917 (https://download.01.org/0day-ci/archive/20260917/202609171531.CIG2e49k-lkp@intel.com/config)
compiler: arc-linux-gcc (GCC) 15.2.0
reproduce (this is a W=1 build): (https://download.01.org/0day-ci/archive/20260917/202609171531.CIG2e49k-lkp@intel.com/reproduce)
If you fix the issue in a separate patch/commit (i.e. not just a new version of
the same patch/commit), kindly add following tags
| Reported-by: kernel test robot <lkp@intel.com>
| Closes: https://lore.kernel.org/oe-kbuild-all/202609171531.CIG2e49k-lkp@intel.com/
All errors (new ones prefixed by >>):
drivers/gpu/drm/tegra/drm.c: In function 'host1x_reloc_copy_from_user':
>> drivers/gpu/drm/tegra/drm.c:163:48: error: passing argument 1 of 'drm_gem_object_put' from incompatible pointer type [-Wincompatible-pointer-types]
163 | drm_gem_object_put(dest->cmdbuf.bo);
| ~~~~~~~~~~~~^~~
| |
| struct host1x_bo *
In file included from include/drm/drm_gpuvm.h:35,
from include/drm/drm_debugfs.h:38,
from drivers/gpu/drm/tegra/drm.c:19:
include/drm/drm_gem.h:572:43: note: expected 'struct drm_gem_object *' but argument is of type 'struct host1x_bo *'
572 | drm_gem_object_put(struct drm_gem_object *obj)
| ~~~~~~~~~~~~~~~~~~~~~~~^~~
vim +/drm_gem_object_put +163 drivers/gpu/drm/tegra/drm.c
126
127 static int host1x_reloc_copy_from_user(struct host1x_reloc *dest,
128 struct drm_tegra_reloc __user *src,
129 struct drm_device *drm,
130 struct drm_file *file)
131 {
132 u32 cmdbuf, target;
133 int err;
134
135 err = get_user(cmdbuf, &src->cmdbuf.handle);
136 if (err < 0)
137 return err;
138
139 err = get_user(dest->cmdbuf.offset, &src->cmdbuf.offset);
140 if (err < 0)
141 return err;
142
143 err = get_user(target, &src->target.handle);
144 if (err < 0)
145 return err;
146
147 err = get_user(dest->target.offset, &src->target.offset);
148 if (err < 0)
149 return err;
150
151 err = get_user(dest->shift, &src->shift);
152 if (err < 0)
153 return err;
154
155 dest->flags = HOST1X_RELOC_READ | HOST1X_RELOC_WRITE;
156
157 dest->cmdbuf.bo = tegra_gem_lookup(file, cmdbuf);
158 if (!dest->cmdbuf.bo)
159 return -ENOENT;
160
161 dest->target.bo = tegra_gem_lookup(file, target);
162 if (!dest->target.bo) {
> 163 drm_gem_object_put(dest->cmdbuf.bo);
164 return -ENOENT;
165 }
166
167 return 0;
168 }
169
--
0-DAY CI Kernel Test Service
https://github.com/intel/lkp-tests/wiki
^ permalink raw reply [flat|nested] 4+ messages in thread
* Re: [PATCH] drm/tegra: Fix bo reference leak in host1x_reloc_copy_from_user()
2026-09-16 18:25 [PATCH] drm/tegra: Fix bo reference leak in host1x_reloc_copy_from_user() Wentao Liang
2026-09-16 18:37 ` sashiko-bot
2026-09-17 7:35 ` kernel test robot
@ 2026-09-17 8:41 ` kernel test robot
2 siblings, 0 replies; 4+ messages in thread
From: kernel test robot @ 2026-09-17 8:41 UTC (permalink / raw)
To: Wentao Liang, airlied
Cc: llvm, oe-kbuild-all, dri-devel, jonathanh, linux-kernel,
linux-tegra, mperttunen, simona, thierry.reding, Wentao Liang,
stable
Hi Wentao,
kernel test robot noticed the following build errors:
[auto build test ERROR on tegra/for-next]
[also build test ERROR on daeinki-drm-exynos/exynos-drm-next drm/drm-next drm-i915/for-linux-next drm-i915/for-linux-next-fixes drm-misc/drm-misc-next drm-tip/drm-tip linus/master drm-tegra/drm/tegra/for-next v7.3-rc3 next-20260916]
[If your patch is applied to the wrong git tree, kindly drop us a note.
And when submitting patch, we suggest to use '--base' as documented in
https://git-scm.com/docs/git-format-patch#_base_tree_information]
url: https://github.com/intel-lab-lkp/linux/commits/Wentao-Liang/drm-tegra-Fix-bo-reference-leak-in-host1x_reloc_copy_from_user/20260916-182550
base: https://git.kernel.org/pub/scm/linux/kernel/git/tegra/linux.git for-next
patch link: https://lore.kernel.org/r/20260916182550.2091797-1-vulab%40iscas.ac.cn
patch subject: [PATCH] drm/tegra: Fix bo reference leak in host1x_reloc_copy_from_user()
config: hexagon-randconfig-1000-20260917 (https://download.01.org/0day-ci/archive/20260917/202609171640.8lyJYO2E-lkp@intel.com/config)
compiler: clang version 20.1.8 (https://github.com/llvm/llvm-project 87f0227cb60147a26a1eeb4fb06e3b505e9c7261)
reproduce (this is a W=1 build): (https://download.01.org/0day-ci/archive/20260917/202609171640.8lyJYO2E-lkp@intel.com/reproduce)
If you fix the issue in a separate patch/commit (i.e. not just a new version of
the same patch/commit), kindly add following tags
| Reported-by: kernel test robot <lkp@intel.com>
| Closes: https://lore.kernel.org/oe-kbuild-all/202609171640.8lyJYO2E-lkp@intel.com/
All errors (new ones prefixed by >>):
>> drivers/gpu/drm/tegra/drm.c:163:22: error: incompatible pointer types passing 'struct host1x_bo *' to parameter of type 'struct drm_gem_object *' [-Werror,-Wincompatible-pointer-types]
163 | drm_gem_object_put(dest->cmdbuf.bo);
| ^~~~~~~~~~~~~~~
include/drm/drm_gem.h:572:43: note: passing argument to parameter 'obj' here
572 | drm_gem_object_put(struct drm_gem_object *obj)
| ^
1 error generated.
vim +163 drivers/gpu/drm/tegra/drm.c
126
127 static int host1x_reloc_copy_from_user(struct host1x_reloc *dest,
128 struct drm_tegra_reloc __user *src,
129 struct drm_device *drm,
130 struct drm_file *file)
131 {
132 u32 cmdbuf, target;
133 int err;
134
135 err = get_user(cmdbuf, &src->cmdbuf.handle);
136 if (err < 0)
137 return err;
138
139 err = get_user(dest->cmdbuf.offset, &src->cmdbuf.offset);
140 if (err < 0)
141 return err;
142
143 err = get_user(target, &src->target.handle);
144 if (err < 0)
145 return err;
146
147 err = get_user(dest->target.offset, &src->target.offset);
148 if (err < 0)
149 return err;
150
151 err = get_user(dest->shift, &src->shift);
152 if (err < 0)
153 return err;
154
155 dest->flags = HOST1X_RELOC_READ | HOST1X_RELOC_WRITE;
156
157 dest->cmdbuf.bo = tegra_gem_lookup(file, cmdbuf);
158 if (!dest->cmdbuf.bo)
159 return -ENOENT;
160
161 dest->target.bo = tegra_gem_lookup(file, target);
162 if (!dest->target.bo) {
> 163 drm_gem_object_put(dest->cmdbuf.bo);
164 return -ENOENT;
165 }
166
167 return 0;
168 }
169
--
0-DAY CI Kernel Test Service
https://github.com/intel/lkp-tests/wiki
^ permalink raw reply [flat|nested] 4+ messages in thread
end of thread, other threads:[~2026-09-17 8:42 UTC | newest]
Thread overview: 4+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-16 18:25 [PATCH] drm/tegra: Fix bo reference leak in host1x_reloc_copy_from_user() Wentao Liang
2026-09-16 18:37 ` sashiko-bot
2026-09-17 7:35 ` kernel test robot
2026-09-17 8:41 ` kernel test robot
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox