]> git.ipfire.org Git - thirdparty/kernel/stable.git/commitdiff
drm/msm: fix potential NULL dereference in cleanup
authorDan Carpenter <dan.carpenter@oracle.com>
Wed, 13 Oct 2021 08:11:33 +0000 (11:11 +0300)
committerGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Wed, 17 Nov 2021 10:04:07 +0000 (11:04 +0100)
[ Upstream commit 027d052a36e56789a2134772bacb4fd0860f03a3 ]

The "msm_obj->node" list needs to be initialized earlier so that the
list_del() in msm_gem_free_object() doesn't experience a NULL pointer
dereference.

Fixes: 6ed0897cd800 ("drm/msm: Fix debugfs deadlock")
Signed-off-by: Dan Carpenter <dan.carpenter@oracle.com>
Link: https://lore.kernel.org/r/20211013081133.GF6010@kili
Signed-off-by: Rob Clark <robdclark@chromium.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
drivers/gpu/drm/msm/msm_gem.c

index 1e8a971a86f2923541060acace359b92f92b8a7a..1ba18f53dbda14ef8be3c109689f3f506a866a2a 100644 (file)
@@ -1184,6 +1184,7 @@ static int msm_gem_new_impl(struct drm_device *dev,
        msm_obj->madv = MSM_MADV_WILLNEED;
 
        INIT_LIST_HEAD(&msm_obj->submit_entry);
+       INIT_LIST_HEAD(&msm_obj->node);
        INIT_LIST_HEAD(&msm_obj->vmas);
 
        *obj = &msm_obj->base;