* Re: [PATCH] drm/tegra: Fix bo reference leak in host1x_reloc_copy_from_user()
2026-09-16 18:25 [PATCH] drm/tegra: Fix bo reference leak in host1x_reloc_copy_from_user() Wentao Liang
@ 2026-09-16 18:37 ` sashiko-bot
2026-09-17 7:35 ` kernel test robot
2026-09-17 8:41 ` kernel test robot
2 siblings, 0 replies; 4+ messages in thread
From: sashiko-bot @ 2026-09-16 18:37 UTC (permalink / raw)
To: Wentao Liang; +Cc: dri-devel
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [High] drm/tegra: type confusion and memory corruption in host1x_reloc_copy_from_user
--
commit 6284447bfe9e49ad17b9df316519006595821f25
Author: Wentao Liang <vulab@iscas.ac.cn>
drm/tegra: Fix bo reference leak in host1x_reloc_copy_from_user()
This commit fixes a reference leak on the command buffer object when the
subsequent lookup for the relocation target fails. It drops the reference
before returning the error.
> diff --git a/drivers/gpu/drm/tegra/drm.c b/drivers/gpu/drm/tegra/drm.c
> index 324480c87fb1f..1a70d37b8c1f3 100644
> --- a/drivers/gpu/drm/tegra/drm.c
> +++ b/drivers/gpu/drm/tegra/drm.c
> @@ -159,8 +159,10 @@ static int host1x_reloc_copy_from_user(struct host1x_reloc *dest,
> return -ENOENT;
>
> dest->target.bo = tegra_gem_lookup(file, target);
> - if (!dest->target.bo)
> + if (!dest->target.bo) {
> + drm_gem_object_put(dest->cmdbuf.bo);
[Severity: High]
Does this cause memory corruption due to a type mismatch?
Looking at host1x_reloc_copy_from_user(), dest->cmdbuf.bo is a struct
host1x_bo pointer. Passing it to drm_gem_object_put(), which expects a
struct drm_gem_object pointer, appears to lead to type confusion.
When tegra_gem_lookup(file, target) fails and this error path is taken,
drm_gem_object_put() will attempt to decrement the reference count by
treating the struct host1x_bo as a struct drm_gem_object. This is likely
to decrement the first member of struct host1x_bo, which is its ops vtable
pointer, instead of an actual kref.
Since this is reachable from userspace via the DRM_IOCTL_TEGRA_SUBMIT ioctl
by supplying a valid cmdbuf but an invalid target BO, could this corrupt
the vtable pointer and lead to crashes or potential control-flow hijacking
when the ops are later used?
> return -ENOENT;
> + }
>
> return 0;
> }
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260916182550.2091797-1-vulab@iscas.ac.cn?part=1
^ permalink raw reply [flat|nested] 4+ messages in thread* Re: [PATCH] drm/tegra: Fix bo reference leak in host1x_reloc_copy_from_user()
2026-09-16 18:25 [PATCH] drm/tegra: Fix bo reference leak in host1x_reloc_copy_from_user() Wentao Liang
2026-09-16 18:37 ` sashiko-bot
@ 2026-09-17 7:35 ` kernel test robot
2026-09-17 8:41 ` kernel test robot
2 siblings, 0 replies; 4+ messages in thread
From: kernel test robot @ 2026-09-17 7:35 UTC (permalink / raw)
To: Wentao Liang, airlied
Cc: oe-kbuild-all, dri-devel, jonathanh, linux-kernel, linux-tegra,
mperttunen, simona, thierry.reding, Wentao Liang, stable
Hi Wentao,
kernel test robot noticed the following build errors:
[auto build test ERROR on tegra/for-next]
[also build test ERROR on daeinki-drm-exynos/exynos-drm-next drm/drm-next drm-i915/for-linux-next drm-i915/for-linux-next-fixes drm-misc/drm-misc-next drm-tip/drm-tip linus/master v7.3-rc3 next-20260916]
[If your patch is applied to the wrong git tree, kindly drop us a note.
And when submitting patch, we suggest to use '--base' as documented in
https://git-scm.com/docs/git-format-patch#_base_tree_information]
url: https://github.com/intel-lab-lkp/linux/commits/Wentao-Liang/drm-tegra-Fix-bo-reference-leak-in-host1x_reloc_copy_from_user/20260916-182550
base: https://git.kernel.org/pub/scm/linux/kernel/git/tegra/linux.git for-next
patch link: https://lore.kernel.org/r/20260916182550.2091797-1-vulab%40iscas.ac.cn
patch subject: [PATCH] drm/tegra: Fix bo reference leak in host1x_reloc_copy_from_user()
config: arc-randconfig-1001-20260917 (https://download.01.org/0day-ci/archive/20260917/202609171531.CIG2e49k-lkp@intel.com/config)
compiler: arc-linux-gcc (GCC) 15.2.0
reproduce (this is a W=1 build): (https://download.01.org/0day-ci/archive/20260917/202609171531.CIG2e49k-lkp@intel.com/reproduce)
If you fix the issue in a separate patch/commit (i.e. not just a new version of
the same patch/commit), kindly add following tags
| Reported-by: kernel test robot <lkp@intel.com>
| Closes: https://lore.kernel.org/oe-kbuild-all/202609171531.CIG2e49k-lkp@intel.com/
All errors (new ones prefixed by >>):
drivers/gpu/drm/tegra/drm.c: In function 'host1x_reloc_copy_from_user':
>> drivers/gpu/drm/tegra/drm.c:163:48: error: passing argument 1 of 'drm_gem_object_put' from incompatible pointer type [-Wincompatible-pointer-types]
163 | drm_gem_object_put(dest->cmdbuf.bo);
| ~~~~~~~~~~~~^~~
| |
| struct host1x_bo *
In file included from include/drm/drm_gpuvm.h:35,
from include/drm/drm_debugfs.h:38,
from drivers/gpu/drm/tegra/drm.c:19:
include/drm/drm_gem.h:572:43: note: expected 'struct drm_gem_object *' but argument is of type 'struct host1x_bo *'
572 | drm_gem_object_put(struct drm_gem_object *obj)
| ~~~~~~~~~~~~~~~~~~~~~~~^~~
vim +/drm_gem_object_put +163 drivers/gpu/drm/tegra/drm.c
126
127 static int host1x_reloc_copy_from_user(struct host1x_reloc *dest,
128 struct drm_tegra_reloc __user *src,
129 struct drm_device *drm,
130 struct drm_file *file)
131 {
132 u32 cmdbuf, target;
133 int err;
134
135 err = get_user(cmdbuf, &src->cmdbuf.handle);
136 if (err < 0)
137 return err;
138
139 err = get_user(dest->cmdbuf.offset, &src->cmdbuf.offset);
140 if (err < 0)
141 return err;
142
143 err = get_user(target, &src->target.handle);
144 if (err < 0)
145 return err;
146
147 err = get_user(dest->target.offset, &src->target.offset);
148 if (err < 0)
149 return err;
150
151 err = get_user(dest->shift, &src->shift);
152 if (err < 0)
153 return err;
154
155 dest->flags = HOST1X_RELOC_READ | HOST1X_RELOC_WRITE;
156
157 dest->cmdbuf.bo = tegra_gem_lookup(file, cmdbuf);
158 if (!dest->cmdbuf.bo)
159 return -ENOENT;
160
161 dest->target.bo = tegra_gem_lookup(file, target);
162 if (!dest->target.bo) {
> 163 drm_gem_object_put(dest->cmdbuf.bo);
164 return -ENOENT;
165 }
166
167 return 0;
168 }
169
--
0-DAY CI Kernel Test Service
https://github.com/intel/lkp-tests/wiki
^ permalink raw reply [flat|nested] 4+ messages in thread* Re: [PATCH] drm/tegra: Fix bo reference leak in host1x_reloc_copy_from_user()
2026-09-16 18:25 [PATCH] drm/tegra: Fix bo reference leak in host1x_reloc_copy_from_user() Wentao Liang
2026-09-16 18:37 ` sashiko-bot
2026-09-17 7:35 ` kernel test robot
@ 2026-09-17 8:41 ` kernel test robot
2 siblings, 0 replies; 4+ messages in thread
From: kernel test robot @ 2026-09-17 8:41 UTC (permalink / raw)
To: Wentao Liang, airlied
Cc: llvm, oe-kbuild-all, dri-devel, jonathanh, linux-kernel,
linux-tegra, mperttunen, simona, thierry.reding, Wentao Liang,
stable
Hi Wentao,
kernel test robot noticed the following build errors:
[auto build test ERROR on tegra/for-next]
[also build test ERROR on daeinki-drm-exynos/exynos-drm-next drm/drm-next drm-i915/for-linux-next drm-i915/for-linux-next-fixes drm-misc/drm-misc-next drm-tip/drm-tip linus/master drm-tegra/drm/tegra/for-next v7.3-rc3 next-20260916]
[If your patch is applied to the wrong git tree, kindly drop us a note.
And when submitting patch, we suggest to use '--base' as documented in
https://git-scm.com/docs/git-format-patch#_base_tree_information]
url: https://github.com/intel-lab-lkp/linux/commits/Wentao-Liang/drm-tegra-Fix-bo-reference-leak-in-host1x_reloc_copy_from_user/20260916-182550
base: https://git.kernel.org/pub/scm/linux/kernel/git/tegra/linux.git for-next
patch link: https://lore.kernel.org/r/20260916182550.2091797-1-vulab%40iscas.ac.cn
patch subject: [PATCH] drm/tegra: Fix bo reference leak in host1x_reloc_copy_from_user()
config: hexagon-randconfig-1000-20260917 (https://download.01.org/0day-ci/archive/20260917/202609171640.8lyJYO2E-lkp@intel.com/config)
compiler: clang version 20.1.8 (https://github.com/llvm/llvm-project 87f0227cb60147a26a1eeb4fb06e3b505e9c7261)
reproduce (this is a W=1 build): (https://download.01.org/0day-ci/archive/20260917/202609171640.8lyJYO2E-lkp@intel.com/reproduce)
If you fix the issue in a separate patch/commit (i.e. not just a new version of
the same patch/commit), kindly add following tags
| Reported-by: kernel test robot <lkp@intel.com>
| Closes: https://lore.kernel.org/oe-kbuild-all/202609171640.8lyJYO2E-lkp@intel.com/
All errors (new ones prefixed by >>):
>> drivers/gpu/drm/tegra/drm.c:163:22: error: incompatible pointer types passing 'struct host1x_bo *' to parameter of type 'struct drm_gem_object *' [-Werror,-Wincompatible-pointer-types]
163 | drm_gem_object_put(dest->cmdbuf.bo);
| ^~~~~~~~~~~~~~~
include/drm/drm_gem.h:572:43: note: passing argument to parameter 'obj' here
572 | drm_gem_object_put(struct drm_gem_object *obj)
| ^
1 error generated.
vim +163 drivers/gpu/drm/tegra/drm.c
126
127 static int host1x_reloc_copy_from_user(struct host1x_reloc *dest,
128 struct drm_tegra_reloc __user *src,
129 struct drm_device *drm,
130 struct drm_file *file)
131 {
132 u32 cmdbuf, target;
133 int err;
134
135 err = get_user(cmdbuf, &src->cmdbuf.handle);
136 if (err < 0)
137 return err;
138
139 err = get_user(dest->cmdbuf.offset, &src->cmdbuf.offset);
140 if (err < 0)
141 return err;
142
143 err = get_user(target, &src->target.handle);
144 if (err < 0)
145 return err;
146
147 err = get_user(dest->target.offset, &src->target.offset);
148 if (err < 0)
149 return err;
150
151 err = get_user(dest->shift, &src->shift);
152 if (err < 0)
153 return err;
154
155 dest->flags = HOST1X_RELOC_READ | HOST1X_RELOC_WRITE;
156
157 dest->cmdbuf.bo = tegra_gem_lookup(file, cmdbuf);
158 if (!dest->cmdbuf.bo)
159 return -ENOENT;
160
161 dest->target.bo = tegra_gem_lookup(file, target);
162 if (!dest->target.bo) {
> 163 drm_gem_object_put(dest->cmdbuf.bo);
164 return -ENOENT;
165 }
166
167 return 0;
168 }
169
--
0-DAY CI Kernel Test Service
https://github.com/intel/lkp-tests/wiki
^ permalink raw reply [flat|nested] 4+ messages in thread