From: sashiko-bot@kernel.org
To: "Thomas Zimmermann" <tzimmermann@suse.de>
Cc: intel-xe@lists.freedesktop.org, linux-hyperv@vger.kernel.org,
gary@garyguo.net, intel-gfx@lists.freedesktop.org,
wsa+renesas@sang-engineering.com,
"Eugenio Perez" <eperezma@redhat.com>,
imx@lists.linux.dev, virtualization@lists.linux.dev,
"Michael S. Tsirkin" <mst@redhat.com>,
ojeda@kernel.org, dri-devel@lists.freedesktop.org,
Frank.Li@kernel.org
Subject: Re: [PATCH v4 01/14] drm/panic: Do not use un-escaped URL as format string
Date: Wed, 09 Sep 2026 09:09:07 +0000 [thread overview]
Message-ID: <20260909090908.43D6A1F00A3D@smtp.kernel.org> (raw)
In-Reply-To: <20260909085826.64529-2-tzimmermann@suse.de>
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
Pre-existing issues:
- [High] NULL pointer dereference in the DRM panic handler via `utsname()` if the system panics during task exit.
--
commit 5f4f34c2248e13bf1786a1ff3cbb5f0cbb86fc3d
Author: Thomas Zimmermann <tzimmermann@suse.de>
drm/panic: Do not use un-escaped URL as format string
This commit replaces the direct use of DRM_PANIC_SCREEN_QR_CODE_URL in
snprintf() with a %s conversion specifier. This change avoids a potential
vulnerability from a crafted URL string.
> diff --git a/drivers/gpu/drm/drm_panic.c b/drivers/gpu/drm/drm_panic.c
> index e576c4791861d..ba21df4be3380 100644
> --- a/drivers/gpu/drm/drm_panic.c
> +++ b/drivers/gpu/drm/drm_panic.c
> @@ -658,7 +658,8 @@ static int drm_panic_get_qr_code_url(u8 **qr_image)
> char *kmsg;
> int max_qr_data_size, url_len;
>
> - url_len = snprintf(url, sizeof(url), CONFIG_DRM_PANIC_SCREEN_QR_CODE_URL "?a=%s&v=%s&z=",
> + url_len = snprintf(url, sizeof(url), "%s?a=%s&v=%s&z=",
> + CONFIG_DRM_PANIC_SCREEN_QR_CODE_URL,
> utsname()->machine, utsname()->release);
[Severity: High]
This is a pre-existing issue, but can dereferencing utsname() here cause a
NULL pointer dereference if the system panics during task exit?
The utsname() macro expands to (¤t->nsproxy->uts_ns->name). If a panic
occurs while the current task is exiting (for example, after
exit_task_namespaces() has set current->nsproxy to NULL), dereferencing
current->nsproxy will cause a nested oops.
This would abort the panic screen rendering and prevent the QR code or kmsg
from being displayed, defeating the purpose of the DRM panic handler.
Would it be safer to use init_utsname() instead of utsname() here in
drm_panic_get_qr_code_url(), similar to how the standard kernel panic and dump
code handles this edge case?
>
> max_qr_data_size = drm_panic_qr_max_data_size(panic_qr_version, url_len);
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260909085826.64529-1-tzimmermann@suse.de?part=1
next prev parent reply other threads:[~2026-09-09 9:09 UTC|newest]
Thread overview: 29+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-09 8:55 [PATCH v4 00/14] drm/panic: Split into core and helpers Thomas Zimmermann
2026-09-09 8:55 ` [PATCH v4 01/14] drm/panic: Do not use un-escaped URL as format string Thomas Zimmermann
2026-09-09 9:09 ` sashiko-bot [this message]
2026-09-09 8:55 ` [PATCH v4 02/14] drm/panic: Test address from kmap op for NULL Thomas Zimmermann
2026-09-09 9:15 ` sashiko-bot
2026-09-09 8:55 ` [PATCH v4 03/14] drm/panic: Return -EINVAL if font is not available Thomas Zimmermann
2026-09-09 9:08 ` sashiko-bot
2026-09-09 8:55 ` [PATCH v4 04/14] drm/panic: Return errno codes if panic output fails Thomas Zimmermann
2026-09-09 9:13 ` sashiko-bot
2026-09-09 8:55 ` [PATCH v4 05/14] drm/panic: Pass colors to draw_panic_dispatch() Thomas Zimmermann
2026-09-09 9:13 ` sashiko-bot
2026-09-09 8:55 ` [PATCH v4 06/14] drm/panic: Pass global module parameters to drm_panic_dispatch() Thomas Zimmermann
2026-09-09 9:22 ` sashiko-bot
2026-09-09 8:55 ` [PATCH v4 07/14] drm/panic: Return from screen_user if display is too small Thomas Zimmermann
2026-09-09 9:18 ` sashiko-bot
2026-09-09 8:55 ` [PATCH v4 08/14] drm/panic: Retry in dispatch function if panic output fails Thomas Zimmermann
2026-09-09 9:17 ` sashiko-bot
2026-09-09 8:55 ` [PATCH v4 09/14] drm/panic: Split draw_panic_plane() Thomas Zimmermann
2026-09-09 9:20 ` sashiko-bot
2026-09-09 8:55 ` [PATCH v4 10/14] drm/panic: Restrict to primary planes Thomas Zimmermann
2026-09-09 9:22 ` sashiko-bot
2026-09-09 8:55 ` [PATCH v4 11/14] drm/panic: Display panic screen via per-plane callback Thomas Zimmermann
2026-09-09 9:29 ` sashiko-bot
2026-09-09 8:55 ` [PATCH v4 12/14] drm/panic: Internalize panic locking in DRM core and helpers Thomas Zimmermann
2026-09-09 9:28 ` sashiko-bot
2026-09-09 8:55 ` [PATCH v4 13/14] drm/panic: Move panic display code into helper library Thomas Zimmermann
2026-09-09 9:32 ` sashiko-bot
2026-09-09 8:55 ` [PATCH v4 14/14] drm/panic: Compile KUnit tests as module Thomas Zimmermann
2026-09-09 9:37 ` sashiko-bot
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260909090908.43D6A1F00A3D@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=Frank.Li@kernel.org \
--cc=dri-devel@lists.freedesktop.org \
--cc=eperezma@redhat.com \
--cc=gary@garyguo.net \
--cc=imx@lists.linux.dev \
--cc=intel-gfx@lists.freedesktop.org \
--cc=intel-xe@lists.freedesktop.org \
--cc=linux-hyperv@vger.kernel.org \
--cc=mst@redhat.com \
--cc=ojeda@kernel.org \
--cc=sashiko-reviews@lists.linux.dev \
--cc=tzimmermann@suse.de \
--cc=virtualization@lists.linux.dev \
--cc=wsa+renesas@sang-engineering.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox