]> git.ipfire.org Git - thirdparty/kernel/stable.git/commit
drm/vkms: Hold gem object while still in-use
authorEzequiel Garcia <ezequiel@collabora.com>
Mon, 27 Apr 2020 21:44:05 +0000 (18:44 -0300)
committerGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Wed, 17 Jun 2020 14:42:06 +0000 (16:42 +0200)
commiteb8ceae63ffe1f1f2d4f5f89e8cd7c0a62b6cbc8
treee77742eaaad291d305268209c37cb21a67920b5b
parentc9b9843dd4abfad3b599af9183a57a59bcea0756
drm/vkms: Hold gem object while still in-use

commit 0ea2ea42b31abc1141f2fd3911f952a97d401fcb upstream.

We need to keep the reference to the drm_gem_object
until the last access by vkms_dumb_create.

Therefore, the put the object after it is used.

This fixes a use-after-free issue reported by syzbot.

While here, change vkms_gem_create() symbol to static.

Reported-and-tested-by: syzbot+e3372a2afe1e7ef04bc7@syzkaller.appspotmail.com
Signed-off-by: Ezequiel Garcia <ezequiel@collabora.com>
Reviewed-by: Rodrigo Siqueira <Rodrigo.Siqueira@amd.com>
Signed-off-by: Rodrigo Siqueira <rodrigosiqueiramelo@gmail.com>
Link: https://patchwork.freedesktop.org/patch/msgid/20200427214405.13069-1-ezequiel@collabora.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
drivers/gpu/drm/vkms/vkms_drv.h
drivers/gpu/drm/vkms/vkms_gem.c