From nobody Fri Sep 25 07:56:19 2026 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-1.web.codeaurora.org [10.30.226.201]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 9AF25456DE9; Tue, 15 Sep 2026 07:39:48 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=10.30.226.201 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789457988; cv=none; b=bcBabjsD1dCA8prtpz+lnD7kV99wLmgSW8NR2dXQTuuSYOno27KBj6tj6plWTSpvXZhAgmiCc6j0FZbM9eWWzBvZVwK6QqTtPwHwLPj+wCXYBoLVejCqqcNDUMA41DtRtWGsGzFUjQW547iPqAmDlXN+nFykmfAXjq5ZU7WeYPc= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789457988; c=relaxed/simple; bh=+ZvUBVLlnhme8yqiJiZGAghhi2ab0L3qh0DBTz3gBa8=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=jmnlHZEWI5LD5JXVxRGtCcOrZjYb8zavNpsqfWhFxSex6W2QA7lz+xEZ0Bieh0fW7OqHxN2DkUPiEOMLA3mpdduP6o4hGx9Qyi9/P/jAc6aBzVfi8Z1qP/k39iC9chXpGbo/W1kubaMrA4LcNUpONmg+NY7FwQYcu+fzubfTJq4= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=B0+E1yHH; arc=none smtp.client-ip=10.30.226.201 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="B0+E1yHH" Received: by smtp.kernel.org (Postfix) with ESMTPS id 3D6B4C2BCF6; Tue, 15 Sep 2026 07:39:48 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=kernel.org; s=k20201202; t=1789457988; bh=+ZvUBVLlnhme8yqiJiZGAghhi2ab0L3qh0DBTz3gBa8=; h=From:Date:Subject:References:In-Reply-To:To:Cc:Reply-To:From; b=B0+E1yHH48qchnNwHAAiruot/yaYCnDDcg4y30hw7e9uIYrXz3wkWnNssapl8E+/W StenjhKwFr2urjYijKuft8ZuEmg2tLQyouhD9hOroVdIU/DvfPG27L+g3UxTcAal4R 80SkZuRnvV8DfNS7VghLTsGmV94EqnQ2wFnkoMjJJeayFWTnCiOG4od0NdMurjWmT7 0OofXkRlemfzzPUhU9y9JKu13rCd/kUnxiEzdcE5RvGwt2dJu5q1SGuWyawbaT+4tJ rbOSkf1EbAxE3rB7qA94ootxLiwYqUtjvhXGfneQ+Rcbe6Tn5oWEA2lLhhZ+D/X1R0 E2IFjlm/ryN4A== Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 1A72BC88E7D; Tue, 15 Sep 2026 07:39:48 +0000 (UTC) From: Junrui Luo via B4 Relay Date: Tue, 15 Sep 2026 15:39:10 +0800 Subject: [PATCH v2 1/4] drm/virtio: fix object leak when drm_gem_handle_create() fails Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260915-fixes-v2-1-a0d799e4db66@outlook.com> References: <20260915-fixes-v2-0-a0d799e4db66@outlook.com> In-Reply-To: <20260915-fixes-v2-0-a0d799e4db66@outlook.com> To: David Airlie , Gerd Hoffmann , Dmitry Osipenko , Gurchetan Singh , Chia-I Wu , Maarten Lankhorst , Maxime Ripard , Thomas Zimmermann , Simona Vetter , "Michael S. Tsirkin" , Dave Airlie Cc: dri-devel@lists.freedesktop.org, virtualization@lists.linux.dev, linux-kernel@vger.kernel.org, Junrui Luo , Yuhao Jiang X-Mailer: b4 0.14.3 X-Developer-Signature: v=1; a=openpgp-sha256; l=1755; i=moonafterrain@outlook.com; h=from:subject:message-id; bh=IqwDkc74tOO8lL0END3OA/+gXOd16vqiITrIyypWgKA=; b=owJ4nJvAy8zAJVb4wiKgu++DA+NptSSGrBXfHLs+KjxL9dt8d+0PB7/+Evm4I+b64b5Kl+9wp hxdaLFCIKOjlIVBjItBVkyR5XjBpW8Wvlt0t/hsSYaZw8oEMoSBi1MAJjLrAsNf6TO1WakrPQrn L5mwUmC7vvTxoltXQrRSNm7+1/7/p7SCESPDnNQNBzzsWTZG1sdf9RE7w/n7vq2zRUjo/eAjE5u WlRUzAgAcwkvq X-Developer-Key: i=moonafterrain@outlook.com; a=openpgp; fpr=C770D2F6384DB42DB44CB46371E838508B8EF040 X-Endpoint-Received: by B4 Relay for moonafterrain@outlook.com/default with auth_id=909 X-Original-From: Junrui Luo Reply-To: moonafterrain@outlook.com From: Junrui Luo virtio_gpu_gem_create() owns the reference taken by virtio_gpu_object_create(). On the drm_gem_handle_create() error path it calls drm_gem_object_release() instead of dropping that reference. drm_gem_object_release() is the inverse of drm_gem_object_init() and does not touch the reference count or call obj->funcs->free(), so it is only correct as the last step of a destructor, as in virtio_gpu_cleanup_object(). Using it here leaves the bo at refcount 1 with no remaining reference, so virtio_gpu_free_object() never runs and the shmem pages, sg table and virtio_gpu_object are leaked. Since virtio_gpu_object_create() has already set bo->created, VIRTIO_GPU_CMD_RESOURCE_UNREF is not queued either, leaking the host-side resource and the resource id. drm_gem_handle_create_tail() drops the handle reference on all of its internal error paths, so the caller only has to drop its own. Use drm_gem_object_put(), matching the success path below. Fixes: dc5698e80cf7 ("Add virtio gpu driver.") Reported-by: Yuhao Jiang Assisted-by: Claude:claude-opus-5 Signed-off-by: Junrui Luo --- drivers/gpu/drm/virtio/virtgpu_gem.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/drivers/gpu/drm/virtio/virtgpu_gem.c b/drivers/gpu/drm/virtio/= virtgpu_gem.c index 66c3f6f74e9c..d2f0b8a3f172 100644 --- a/drivers/gpu/drm/virtio/virtgpu_gem.c +++ b/drivers/gpu/drm/virtio/virtgpu_gem.c @@ -45,7 +45,7 @@ static int virtio_gpu_gem_create(struct drm_file *file, =20 ret =3D drm_gem_handle_create(file, &obj->base.base, &handle); if (ret) { - drm_gem_object_release(&obj->base.base); + drm_gem_object_put(&obj->base.base); return ret; } =20 --=20 2.51.2 From nobody Fri Sep 25 07:56:19 2026 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-1.web.codeaurora.org [10.30.226.201]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 9AE6F450403; Tue, 15 Sep 2026 07:39:48 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=10.30.226.201 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789457988; cv=none; b=DYKE8AFuMw+9ggLDSiLEJrYjGjHJ5AdmQjZIgWdHSUWXv/FMQoQpcTYl6mcW1oiYIJYzou/4f63fS9HxXl8ILPvlPUs5EfCpdKZwbgJ2bSqdoKFsfl2meqrhvRIEB4H7QDuAaSjmzxYR4KFWtPDSCoTOHTn08ZL885AIeeqqMgg= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789457988; c=relaxed/simple; bh=6fo5j/URbptwFWsGgDE9ZiP3GKDoDXqEGDTugblfI/w=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=Fblj+HjSMVSARfJkmXbwS3rGhn4R0g3F48mP2xhT5iiK5KTaY4gwGHueOu2UqUIp1Gi5UlVQ69gOy3qK1367iKbev/moMM3Mqy8goBCjc9Y+9TxPGV6jJ1qUeJfgMqbVbaKgGM6hiYVGJAsIgcjz3629qYZIo/uWXY2bNooNEYk= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=iFev8jtx; arc=none smtp.client-ip=10.30.226.201 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="iFev8jtx" Received: by smtp.kernel.org (Postfix) with ESMTPS id 4CFACC2BCFD; Tue, 15 Sep 2026 07:39:48 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=kernel.org; s=k20201202; t=1789457988; bh=6fo5j/URbptwFWsGgDE9ZiP3GKDoDXqEGDTugblfI/w=; h=From:Date:Subject:References:In-Reply-To:To:Cc:Reply-To:From; b=iFev8jtxhxc8Jd6+QKIOAd5Wboh+WFTneCKnHnWlETKyK4JQqqKOqsZ//9fbwE4GI kST6h16G5tda7RVRM0qHSBDvxEUmEmeosWc1v/okSjTHQknIIpLFea6O5SKspDQuDX TRGF13j0UXVqu++E55v65AbpIMjEL4b0cthhwyzSzRi+MYW5vYM16CJz/yqPUWGfym Eeqs3fFti4PAFY8kFfXEXBK98yXC8sbyeDGeRV0Vk5pXUDOqnG/r14j1g9lKj+rifN R0CgUJTrGdMCobJqKPGghMjY+JRfBqXEYPpqHopnOa3l5kYR1zXHftAWYwSFo0UPF/ zXlvsp1cwcW9w== Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 2A8A1C88E7F; Tue, 15 Sep 2026 07:39:48 +0000 (UTC) From: Junrui Luo via B4 Relay Date: Tue, 15 Sep 2026 15:39:11 +0800 Subject: [PATCH v2 2/4] drm/virtio: fix object leak in virtio_gpu_resource_create_ioctl() Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260915-fixes-v2-2-a0d799e4db66@outlook.com> References: <20260915-fixes-v2-0-a0d799e4db66@outlook.com> In-Reply-To: <20260915-fixes-v2-0-a0d799e4db66@outlook.com> To: David Airlie , Gerd Hoffmann , Dmitry Osipenko , Gurchetan Singh , Chia-I Wu , Maarten Lankhorst , Maxime Ripard , Thomas Zimmermann , Simona Vetter , "Michael S. Tsirkin" , Dave Airlie Cc: dri-devel@lists.freedesktop.org, virtualization@lists.linux.dev, linux-kernel@vger.kernel.org, Junrui Luo X-Mailer: b4 0.14.3 X-Developer-Signature: v=1; a=openpgp-sha256; l=1083; i=moonafterrain@outlook.com; h=from:subject:message-id; bh=m9jMk2dRPc6AaiI3AVPl+UojmE+4LGbux5+Vah67Nqs=; b=owJ4nJvAy8zAJVb4wiKgu++DA+NptSSGrBXfHBPs65bwXWR+u6xj6uQVj7za7fo/TU8pbY++L GwfU3TLeUNHKQuDGBeDrJgiy/GCS98sfLfobvHZkgwzh5UJZAgDF6cATKROmOGvAEfF0y4mk+Tt SgoMc04u8JrP8+qRptWDX8Fml8KSHp7jY2T4+K5N6a3YDpFmx9xnDXd37RG7uv5fu3rx0uzMHwl zt6bzAgADT0zZ X-Developer-Key: i=moonafterrain@outlook.com; a=openpgp; fpr=C770D2F6384DB42DB44CB46371E838508B8EF040 X-Endpoint-Received: by B4 Relay for moonafterrain@outlook.com/default with auth_id=909 X-Original-From: Junrui Luo Reply-To: moonafterrain@outlook.com From: Junrui Luo virtio_gpu_resource_create_ioctl() calls drm_gem_object_release() on the drm_gem_handle_create() error path instead of dropping the reference it owns, so obj->funcs->free() never runs and the virtio_gpu_object, its pages and sg table, the resource id and the host-side resource are leaked. Use drm_gem_object_put() instead. Fixes: 62fb7a5e1096 ("virtio-gpu: add 3d/virgl support") Assisted-by: Claude:claude-opus-5 Signed-off-by: Junrui Luo --- drivers/gpu/drm/virtio/virtgpu_ioctl.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/drivers/gpu/drm/virtio/virtgpu_ioctl.c b/drivers/gpu/drm/virti= o/virtgpu_ioctl.c index 3d8e4ccdb7c1..d16f07abb266 100644 --- a/drivers/gpu/drm/virtio/virtgpu_ioctl.c +++ b/drivers/gpu/drm/virtio/virtgpu_ioctl.c @@ -185,7 +185,7 @@ static int virtio_gpu_resource_create_ioctl(struct drm_= device *dev, void *data, =20 ret =3D drm_gem_handle_create(file, obj, &handle); if (ret) { - drm_gem_object_release(obj); + drm_gem_object_put(obj); return ret; } =20 --=20 2.51.2 From nobody Fri Sep 25 07:56:19 2026 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-1.web.codeaurora.org [10.30.226.201]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id A6548456E0A; Tue, 15 Sep 2026 07:39:48 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=10.30.226.201 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789457988; cv=none; b=jaxjiCpxTgHwRsf2xSx1yB0uz5bhL02KHxx20Izv+ohsQUhyFzYhY5gXUDQsbUVSLOmgGq4Euy07uTn5SIuHtnNYy2+5e7vx6IsZhRjGvpo/KDupdXx5orcS3m3sdhX2v3E8MVmMSJhfE2uUyXz0imYCD5m6fZXAV6c/O6ee2GY= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789457988; c=relaxed/simple; bh=UdMaaxVxX8faS5D/R59hxfAkCFC0hSCarXqNvw4Plzk=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=n1NzGFgHv0W7Dae1L1MhDKLSQWZFrPhUX7oDk1JtWieww00vSp/xQruP+1v4lFNl5G0Vv/Iy7nUMLPGIcz4F3JG95YoqhmbGnmWtTELUIdcRQEOIL5HTt2kJOWqaUOdxVCThT57z1Jp6Qy1kDr4qZ076S4vsFF1jTX/RVq1c0pc= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=UNztBd7H; arc=none smtp.client-ip=10.30.226.201 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="UNztBd7H" Received: by smtp.kernel.org (Postfix) with ESMTPS id 59C3AC2BD01; Tue, 15 Sep 2026 07:39:48 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=kernel.org; s=k20201202; t=1789457988; bh=UdMaaxVxX8faS5D/R59hxfAkCFC0hSCarXqNvw4Plzk=; h=From:Date:Subject:References:In-Reply-To:To:Cc:Reply-To:From; b=UNztBd7HO35GxpuzWbeFV3i+3XTQGaItN9kYkboY3gU+78Lf/k5ffAreYxTLLFHfQ QmEu3CTCotYs3LnqbKBR3j3NKNtmZLtSfNhWqztMKt9K6pywM+SMrh0nNoxvBzk54i ZAoFDU6RjxvHvgAhnf/w9mY+J5fz+rsORBJoL1l09UsNnGICMgcE1B0GmjLHx4OgzV 4SfgFH6eq2mtu+TWE5SEN6yuZr6vqotiM1a9OF22xnYNKCrJ/JT35VU18XlyChA4+X BaJyPDQEYbDFHTx3qO/QcrMHfUrjPng2TzO2he9z1ymixNK1axCiizqoxPqrofUaKU 3dm1v5yzfndGw== Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 3C025C88E75; Tue, 15 Sep 2026 07:39:48 +0000 (UTC) From: Junrui Luo via B4 Relay Date: Tue, 15 Sep 2026 15:39:12 +0800 Subject: [PATCH v2 3/4] drm/virtio: fix object leaks in virtio_gpu_resource_create_blob_ioctl() Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260915-fixes-v2-3-a0d799e4db66@outlook.com> References: <20260915-fixes-v2-0-a0d799e4db66@outlook.com> In-Reply-To: <20260915-fixes-v2-0-a0d799e4db66@outlook.com> To: David Airlie , Gerd Hoffmann , Dmitry Osipenko , Gurchetan Singh , Chia-I Wu , Maarten Lankhorst , Maxime Ripard , Thomas Zimmermann , Simona Vetter , "Michael S. Tsirkin" , Dave Airlie Cc: dri-devel@lists.freedesktop.org, virtualization@lists.linux.dev, linux-kernel@vger.kernel.org, Junrui Luo X-Mailer: b4 0.14.3 X-Developer-Signature: v=1; a=openpgp-sha256; l=1365; i=moonafterrain@outlook.com; h=from:subject:message-id; bh=gmVVZGqljoLUgVlULUlI1tOIf4EBWb5LQtGm6rkt9fE=; b=owJ4nJvAy8zAJVb4wiKgu++DA+NptSSGrBXfnPhTbs/5prpKPvbE5ptnF9Rk6sdnvZlnn9f1d 72ntLBV9dqOUhYGMS4GWTFFluMFl75Z+G7R3eKzJRlmDisTyBAGLk4BmEhdHMP/UIW9ipqJV5Km /Wd8dGJ5As/5Yxmf/e07u8p8pZM3TFk1g+F/+hy9zXW5bH8spjY/9Crh+vl3g+NVdb1pOWzif47 n/rrICwBu3U3v X-Developer-Key: i=moonafterrain@outlook.com; a=openpgp; fpr=C770D2F6384DB42DB44CB46371E838508B8EF040 X-Endpoint-Received: by B4 Relay for moonafterrain@outlook.com/default with auth_id=909 X-Original-From: Junrui Luo Reply-To: moonafterrain@outlook.com From: Junrui Luo virtio_gpu_resource_create_blob_ioctl() calls drm_gem_object_release() on both the virtio_gpu_resource_assign_uuid() and drm_gem_handle_create() error paths instead of dropping the reference it owns, so obj->funcs->free() never runs and the virtio_gpu_object, the resource id and the host-side resource are leaked. Use drm_gem_object_put() instead. Fixes: 897b4d1acaf5 ("drm/virtio: implement blob resources: resource create= blob ioctl") Assisted-by: Claude:claude-opus-5 Signed-off-by: Junrui Luo --- drivers/gpu/drm/virtio/virtgpu_ioctl.c | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/drivers/gpu/drm/virtio/virtgpu_ioctl.c b/drivers/gpu/drm/virti= o/virtgpu_ioctl.c index d16f07abb266..fcdb07a37972 100644 --- a/drivers/gpu/drm/virtio/virtgpu_ioctl.c +++ b/drivers/gpu/drm/virtio/virtgpu_ioctl.c @@ -557,14 +557,14 @@ static int virtio_gpu_resource_create_blob_ioctl(stru= ct drm_device *dev, if (params.blob_flags & VIRTGPU_BLOB_FLAG_USE_CROSS_DEVICE) { ret =3D virtio_gpu_resource_assign_uuid(vgdev, bo); if (ret) { - drm_gem_object_release(obj); + drm_gem_object_put(obj); return ret; } } =20 ret =3D drm_gem_handle_create(file, obj, &handle); if (ret) { - drm_gem_object_release(obj); + drm_gem_object_put(obj); return ret; } =20 --=20 2.51.2 From nobody Fri Sep 25 07:56:19 2026 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-1.web.codeaurora.org [10.30.226.201]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 9AD2B3B7B6E; Tue, 15 Sep 2026 07:39:48 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=10.30.226.201 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789457988; cv=none; b=M7ILgeQLENbGKyMsgZQaGVEUD/FM414Mi4qQ1iwrPnnLhRioYmuMh3Kp/IddA57eg/JSDlXmIWyfIql5GGLHg9C5GjCJ7lwkq1ogSGwmc1DWj1mc/uuuagqIm7wCKfaN03EJQn9DIf4vT/BBnx1rkYqQXfiSQQVfGNcbFtSq4Bk= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789457988; c=relaxed/simple; bh=zTFO9oTlX+pfOrYzO0SUc3KtS2BP0EOaEJ6XFg4DZzE=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=g588v6NtDSUYrdoxkIZipY0ss5bB1QD4j6PHH6tB0FWwym869wiZVO+9c4l8Lx5x7jurMvkm1ox+XW+tFzx/Aat6vGnY7qjrBjT+ZEK8Yj4JNtm9C60EsKh/ncJigJXjprAR4/7m4W3NCldHD8nb5LAPbAQmODpk+Slc9xdoQHI= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=qsPiko46; arc=none smtp.client-ip=10.30.226.201 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="qsPiko46" Received: by smtp.kernel.org (Postfix) with ESMTPS id 5FAB6C2BD04; Tue, 15 Sep 2026 07:39:48 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=kernel.org; s=k20201202; t=1789457988; bh=zTFO9oTlX+pfOrYzO0SUc3KtS2BP0EOaEJ6XFg4DZzE=; h=From:Date:Subject:References:In-Reply-To:To:Cc:Reply-To:From; b=qsPiko461+/rGtjYYzIIIr9O1zR9AcZ+NaKlAeKcDY1H1Y4dwvGvkWmVS6SIV3e6B GCu0kNO+K92j0iQbhkDodyT3k9ViorOMVfqqllQPZ3WS2BAfA36TLjp8hGEJJ4xs1Y TDQMKC73fbhTo7N00XswB8PG4XPP0xTcl9Lvx5P7WXWnCDgrZ+8dN9jc0oWKp0H/ZY 1PlJcjSLrCkZ7QYoIR9LJsi7ZH+3Z9V3W0AyDFTR6zmmoP6HdngeV4nqA2JcZYvpvQ m6tyh4vBHqdSw651IFmeEQsL774ITQsy8PxHDpHdlDPNcGqiQsNHpAG+CCyTf4Oe6B /dhws2C9zq79g== Received: from aws-us-west-2-korg-lkml-1.web.codeaurora.org (localhost.localdomain [127.0.0.1]) by smtp.lore.kernel.org (Postfix) with ESMTP id 4AC0EC982C2; Tue, 15 Sep 2026 07:39:48 +0000 (UTC) From: Junrui Luo via B4 Relay Date: Tue, 15 Sep 2026 15:39:13 +0800 Subject: [PATCH v2 4/4] drm/virtio: release the GEM object on virtio_gpu_vram_create() errors Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260915-fixes-v2-4-a0d799e4db66@outlook.com> References: <20260915-fixes-v2-0-a0d799e4db66@outlook.com> In-Reply-To: <20260915-fixes-v2-0-a0d799e4db66@outlook.com> To: David Airlie , Gerd Hoffmann , Dmitry Osipenko , Gurchetan Singh , Chia-I Wu , Maarten Lankhorst , Maxime Ripard , Thomas Zimmermann , Simona Vetter , "Michael S. Tsirkin" , Dave Airlie Cc: dri-devel@lists.freedesktop.org, virtualization@lists.linux.dev, linux-kernel@vger.kernel.org, Junrui Luo X-Mailer: b4 0.14.3 X-Developer-Signature: v=1; a=openpgp-sha256; l=1795; i=moonafterrain@outlook.com; h=from:subject:message-id; bh=uOmmSc9TIw8FhbYiw6eKAHWdQPO72b/48Wr4hLOpbhU=; b=owJ4nJvAy8zAJVb4wiKgu++DA+NptSSGrBXfnCo6Y9uvrPQ6knz8iXgAh57fXLs4oeXbcyI0g g9ZHdUQNegoZWEQ42KQFVNkOV5w6ZuF7xbdLT5bkmHmsDKBDGHg4hSAiayNZWRYdYD3pfd1v333 Y0/XVyXbiKVp9cXdK7dg2arYFrArNX8Nwz/LRSdULy1e5P5L8VD9nM22TuZyXxs1zp05wLWnl9v iUiYbAPB5SXg= X-Developer-Key: i=moonafterrain@outlook.com; a=openpgp; fpr=C770D2F6384DB42DB44CB46371E838508B8EF040 X-Endpoint-Received: by B4 Relay for moonafterrain@outlook.com/default with auth_id=909 X-Original-From: Junrui Luo Reply-To: moonafterrain@outlook.com From: Junrui Luo virtio_gpu_vram_create() frees the object with a bare kfree(vram) on both error paths after drm_gem_private_object_init() has run, and on the second one after drm_gem_create_mmap_offset() has linked obj->vma_node into the device's VMA offset manager. The freed object stays in that interval tree, so a later lookup or insertion walks freed memory, and the dma_resv and gpuva lock are never destroyed. Call drm_gem_object_release() before kfree() on both paths. Fixes: 16845c5d5409 ("drm/virtio: implement blob resources: implement vram = object") Assisted-by: Claude:claude-opus-5 Signed-off-by: Junrui Luo --- drivers/gpu/drm/virtio/virtgpu_vram.c | 17 +++++++++-------- 1 file changed, 9 insertions(+), 8 deletions(-) diff --git a/drivers/gpu/drm/virtio/virtgpu_vram.c b/drivers/gpu/drm/virtio= /virtgpu_vram.c index 5b4a3ab81cd5..01241ce4d07c 100644 --- a/drivers/gpu/drm/virtio/virtgpu_vram.c +++ b/drivers/gpu/drm/virtio/virtgpu_vram.c @@ -215,16 +215,12 @@ int virtio_gpu_vram_create(struct virtio_gpu_device *= vgdev, =20 /* Create fake offset */ ret =3D drm_gem_create_mmap_offset(obj); - if (ret) { - kfree(vram); - return ret; - } + if (ret) + goto err_release_obj; =20 ret =3D virtio_gpu_resource_id_get(vgdev, &vram->base.hw_res_handle); - if (ret) { - kfree(vram); - return ret; - } + if (ret) + goto err_release_obj; =20 virtio_gpu_cmd_resource_create_blob(vgdev, &vram->base, params, NULL, 0); @@ -240,6 +236,11 @@ int virtio_gpu_vram_create(struct virtio_gpu_device *v= gdev, =20 *bo_ptr =3D &vram->base; return 0; + +err_release_obj: + drm_gem_object_release(obj); + kfree(vram); + return ret; } =20 void virtio_gpu_vram_map_deferred(struct virtio_gpu_object_vram *vram) --=20 2.51.2