From nobody Mon Sep 28 07:17:43 2026 Received: from wxsgout04.xfusion.com (wxsgout03.xfusion.com [36.139.52.80]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id AC7BF3DDB0E for ; Tue, 25 Aug 2026 09:03:38 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=36.139.52.80 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787648622; cv=none; b=YqUELGntBGSjAzvbNJqMVQ7RkdPckgBlonULgysT6Ac0Yvv/AwYpm2UdJNjCNHaXh0fRMZe1FLd0dcrvi1kTPuLpTourhJpUpzvb3DW+ysZiL1Ic7jg0055DrdBJOuh7wHKX3ppb5Sl7MQa/T8NfyTc/vlxosKxp5uUOyLyOtj4= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787648622; c=relaxed/simple; bh=2be+1a+B9cqDhxFVPdWFjvzFhvDyqHiZK6y8geI0Qgg=; h=From:To:CC:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version:Content-Type; b=ruFiKyjpetl/d5UfXe42PdwkUN08Y8g3dniNcw9yQQ8/0r/lXYXPBr5s5L1KjJYmcFh2H+ppCkYiPNczpv0Yry1uoTiPvZaG1R0uVykWVq3VLhA4GEPGKyQ0k4B1xc2kjeJTEscKTEHNuQZaQKgrDBIxRc8q386UAzDUxiVvfZ8= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=xfusion.com; spf=pass smtp.mailfrom=xfusion.com; arc=none smtp.client-ip=36.139.52.80 Authentication-Results: smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=xfusion.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=xfusion.com Received: from wuxpheds03048.xfusion.com (unknown [10.32.143.30]) by wxsgout04.xfusion.com (SkyGuard) with ESMTPS id 4hTh8s1djqzBQssm; Tue, 25 Aug 2026 16:41:49 +0800 (CST) Received: from DESKTOP-Q8I2N5U.xfusion.com (10.82.130.100) by wuxpheds03048.xfusion.com (10.32.143.30) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_RSA_WITH_AES_128_CBC_SHA256) id 15.2.2562.20; Tue, 25 Aug 2026 16:44:18 +0800 From: shechenglong To: Maarten Lankhorst , Maxime Ripard , Thomas Zimmermann , David Airlie , Simona Vetter , Sam Ravnborg CC: , , , , shechenglong Subject: [RESEND PATCH] drm: Fix NULL pointer dereference in drm_minor_alloc() on error path Date: Tue, 25 Aug 2026 16:44:10 +0800 Message-ID: <20260825084410.1306-1-shechenglong@xfusion.com> X-Mailer: git-send-email 2.37.1.windows.1 In-Reply-To: <20260810120509.784-1-shechenglong@xfusion.com> References: <20260810120509.784-1-shechenglong@xfusion.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-ClientProxiedBy: wuxpheds03048.xfusion.com (10.32.143.30) To wuxpheds03048.xfusion.com (10.32.143.30) Content-Type: text/plain; charset="utf-8" When drm_sysfs_minor_alloc() fails (e.g., due to -ENOMEM), the following Oops occurs because an ERR_PTR is passed to put_device(): BUG: kernel NULL pointer dereference, address: 0000000000000030 #PF: supervisor read access in kernel mode #PF: error_code(0x0000) - not-present page RIP: 0010:kobject_put+0xd/0x60 Call Trace: drm_minor_alloc_release+0x1c/0x50 [drm] drm_managed_release+0x96/0x160 [drm] drm_dev_init+0x269/0x330 [drm] drm_dev_alloc+0x3f/0x80 [drm] virtio_gpu_probe+0x40/0x180 [virtio_gpu] virtio_dev_probe+0x1fd/0x360 ... do_syscall_64+0xaf/0x500 entry_SYSCALL_64_after_hwframe+0x76/0x7e The call path that leads to this crash is: virtio_gpu_probe() drm_dev_alloc() drm_dev_init() drm_minor_alloc() // allocates minor drm_sysfs_minor_alloc() // returns ERR_PTR(-ENOMEM) minor->kdev =3D ERR_PTR(-ENOMEM) // stored directly return -ENOMEM // drm_dev_init() fails, triggers cleanup: drm_managed_release() drm_minor_alloc_release(dev, minor) put_device(minor->kdev) // ERR_PTR(-ENOMEM) dereferenced kobject_put() // crashes at address 0x30 drm_minor_alloc() assigns the return value of drm_sysfs_minor_alloc() directly to minor->kdev, even when it is an error pointer. The subsequent cleanup unconditionally calls put_device(minor->kdev), which dereferences the error pointer and causes a NULL-pointer dereference (offset 0x30 into a non-page-mapped area). Fix this by using a temporary variable to hold the result of drm_sysfs_minor_alloc(). If the allocation fails, we return the error immediately, leaving minor->kdev as NULL (the whole minor structure is zero-allocated). put_device(NULL) is explicitly allowed and safe. Fixes: f96306f9892b ("drm: manage drm_minor cleanup with drmm_") Signed-off-by: shechenglong Reviewed-by: Thomas Zimmermann --- drivers/gpu/drm/drm_drv.c | 9 ++++++--- 1 file changed, 6 insertions(+), 3 deletions(-) diff --git a/drivers/gpu/drm/drm_drv.c b/drivers/gpu/drm/drm_drv.c index 675675480..2348fbb21 100644 --- a/drivers/gpu/drm/drm_drv.c +++ b/drivers/gpu/drm/drm_drv.c @@ -143,6 +143,7 @@ static void drm_minor_alloc_release(struct drm_device *= dev, void *data) static int drm_minor_alloc(struct drm_device *dev, enum drm_minor_type typ= e) { struct drm_minor *minor; + struct device *kdev; int r; =20 minor =3D drmm_kzalloc(dev, sizeof(*minor), GFP_KERNEL); @@ -164,9 +165,11 @@ static int drm_minor_alloc(struct drm_device *dev, enu= m drm_minor_type type) if (r) return r; =20 - minor->kdev =3D drm_sysfs_minor_alloc(minor); - if (IS_ERR(minor->kdev)) - return PTR_ERR(minor->kdev); + kdev =3D drm_sysfs_minor_alloc(minor); + if (IS_ERR(kdev)) + return PTR_ERR(kdev); + + minor->kdev =3D kdev; =20 *drm_minor_get_slot(dev, type) =3D minor; return 0; --=20 2.43.0