]> git.ipfire.org Git - thirdparty/kernel/linux.git/commitdiff
drm/panthor: Fix UAF race between device unplug and FW event processing
authorKetil Johnsen <ketil.johnsen@arm.com>
Mon, 27 Oct 2025 14:02:15 +0000 (15:02 +0100)
committerLiviu Dudau <liviu.dudau@arm.com>
Mon, 3 Nov 2025 14:25:21 +0000 (14:25 +0000)
The function panthor_fw_unplug() will free the FW memory sections.
The problem is that there could still be pending FW events which are yet
not handled at this point. process_fw_events_work() can in this case try
to access said freed memory.

Simply call disable_work_sync() to both drain and prevent future
invocation of process_fw_events_work().

Signed-off-by: Ketil Johnsen <ketil.johnsen@arm.com>
Fixes: de85488138247 ("drm/panthor: Add the scheduler logical block")
Reviewed-by: Liviu Dudau <liviu.dudau@arm.com>
Link: https://patch.msgid.link/20251027140217.121274-1-ketil.johnsen@arm.com
Signed-off-by: Liviu Dudau <liviu.dudau@arm.com>
drivers/gpu/drm/panthor/panthor_sched.c

index c9c6bfe47b76e868bd14deea69d4571fb3700f49..3507e189082a247eb5a94fd67bc0c512fe7a718c 100644 (file)
@@ -3878,6 +3878,7 @@ void panthor_sched_unplug(struct panthor_device *ptdev)
        struct panthor_scheduler *sched = ptdev->scheduler;
 
        cancel_delayed_work_sync(&sched->tick_work);
+       disable_work_sync(&sched->fw_events_work);
 
        mutex_lock(&sched->lock);
        if (sched->pm.has_ref) {