From nobody Tue Sep 29 09:09:00 2026 Received: from wxsgout04.xfusion.com (wxsgout04.xfusion.com [36.139.87.180]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id DCB043C1D7C for ; Mon, 10 Aug 2026 12:21:43 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=36.139.87.180 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786364510; cv=none; b=nl6pnCS4VhD78yED0vPBABXc7YzCbULFoxYvxc6nVo1/rmh1A6DFfSHEITu/v+VHyDeS5BULpIVRQoe71ogBE3c6V7LlIVoB0uyQDYSrXVRIFQB0cjJahCYP398Kl4ZaVRxpctRdqqJ5FGu/OsuO1NqFn133xxb3lZkvW/gNR/M= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786364510; c=relaxed/simple; bh=2be+1a+B9cqDhxFVPdWFjvzFhvDyqHiZK6y8geI0Qgg=; h=From:To:CC:Subject:Date:Message-ID:MIME-Version:Content-Type; b=trB5cloeOGJpENUKJVInHaS7siHVQdOS8Jbs2uFBtGcuhEIQnj+7UcGtb+lSwqGConinlLXgWLiuUJ4wp7Vw5+/7BD9ou8Qgvi270hf2qdkWtPmx5gUWqDjIZabn5hTj+ciYewgFu/E2ouyjw/SRm5VTmVDIYB3ECKRrfPHGBn0= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=xfusion.com; spf=pass smtp.mailfrom=xfusion.com; arc=none smtp.client-ip=36.139.87.180 Authentication-Results: smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=xfusion.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=xfusion.com Received: from wuxpheds03048.xfusion.com (unknown [10.32.143.30]) by wxsgout04.xfusion.com (SkyGuard) with ESMTPS id 4hJYKZ3QBdzBGV5D; Mon, 10 Aug 2026 20:02:42 +0800 (CST) Received: from DESKTOP-Q8I2N5U.xfusion.com (10.82.130.100) by wuxpheds03048.xfusion.com (10.32.143.30) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_RSA_WITH_AES_128_CBC_SHA256) id 15.2.2562.20; Mon, 10 Aug 2026 20:05:21 +0800 From: shechenglong To: Maarten Lankhorst , Maxime Ripard , Thomas Zimmermann , David Airlie , Simona Vetter , Sam Ravnborg CC: , , , , shechenglong Subject: [PATCH] drm: Fix NULL pointer dereference in drm_minor_alloc() on error path Date: Mon, 10 Aug 2026 20:05:09 +0800 Message-ID: <20260810120509.784-1-shechenglong@xfusion.com> X-Mailer: git-send-email 2.37.1.windows.1 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-ClientProxiedBy: wuxpheds03048.xfusion.com (10.32.143.30) To wuxpheds03048.xfusion.com (10.32.143.30) Content-Type: text/plain; charset="utf-8" When drm_sysfs_minor_alloc() fails (e.g., due to -ENOMEM), the following Oops occurs because an ERR_PTR is passed to put_device(): BUG: kernel NULL pointer dereference, address: 0000000000000030 #PF: supervisor read access in kernel mode #PF: error_code(0x0000) - not-present page RIP: 0010:kobject_put+0xd/0x60 Call Trace: drm_minor_alloc_release+0x1c/0x50 [drm] drm_managed_release+0x96/0x160 [drm] drm_dev_init+0x269/0x330 [drm] drm_dev_alloc+0x3f/0x80 [drm] virtio_gpu_probe+0x40/0x180 [virtio_gpu] virtio_dev_probe+0x1fd/0x360 ... do_syscall_64+0xaf/0x500 entry_SYSCALL_64_after_hwframe+0x76/0x7e The call path that leads to this crash is: virtio_gpu_probe() drm_dev_alloc() drm_dev_init() drm_minor_alloc() // allocates minor drm_sysfs_minor_alloc() // returns ERR_PTR(-ENOMEM) minor->kdev =3D ERR_PTR(-ENOMEM) // stored directly return -ENOMEM // drm_dev_init() fails, triggers cleanup: drm_managed_release() drm_minor_alloc_release(dev, minor) put_device(minor->kdev) // ERR_PTR(-ENOMEM) dereferenced kobject_put() // crashes at address 0x30 drm_minor_alloc() assigns the return value of drm_sysfs_minor_alloc() directly to minor->kdev, even when it is an error pointer. The subsequent cleanup unconditionally calls put_device(minor->kdev), which dereferences the error pointer and causes a NULL-pointer dereference (offset 0x30 into a non-page-mapped area). Fix this by using a temporary variable to hold the result of drm_sysfs_minor_alloc(). If the allocation fails, we return the error immediately, leaving minor->kdev as NULL (the whole minor structure is zero-allocated). put_device(NULL) is explicitly allowed and safe. Fixes: f96306f9892b ("drm: manage drm_minor cleanup with drmm_") Signed-off-by: shechenglong --- drivers/gpu/drm/drm_drv.c | 9 ++++++--- 1 file changed, 6 insertions(+), 3 deletions(-) diff --git a/drivers/gpu/drm/drm_drv.c b/drivers/gpu/drm/drm_drv.c index 675675480..2348fbb21 100644 --- a/drivers/gpu/drm/drm_drv.c +++ b/drivers/gpu/drm/drm_drv.c @@ -143,6 +143,7 @@ static void drm_minor_alloc_release(struct drm_device *= dev, void *data) static int drm_minor_alloc(struct drm_device *dev, enum drm_minor_type typ= e) { struct drm_minor *minor; + struct device *kdev; int r; =20 minor =3D drmm_kzalloc(dev, sizeof(*minor), GFP_KERNEL); @@ -164,9 +165,11 @@ static int drm_minor_alloc(struct drm_device *dev, enu= m drm_minor_type type) if (r) return r; =20 - minor->kdev =3D drm_sysfs_minor_alloc(minor); - if (IS_ERR(minor->kdev)) - return PTR_ERR(minor->kdev); + kdev =3D drm_sysfs_minor_alloc(minor); + if (IS_ERR(kdev)) + return PTR_ERR(kdev); + + minor->kdev =3D kdev; =20 *drm_minor_get_slot(dev, type) =3D minor; return 0; --=20 2.43.0