On Sun, Jun 28, 2026 at 2:29 AM Geoffrey McRae <[email protected]> wrote:
>
> kcalloc but does not check for failure. If the allocation fails, the
> pointer remains NULL but the function returns success. Subsequent code
> using this buffer will dereference a NULL pointer, causing a kernel
> oops. Add a check to return -ENOMEM if the allocation fails.
>
> Signed-off-by: Geoffrey McRae <[email protected]>
> Cc: Alex Deucher <[email protected]>
> Cc: Christian König <[email protected]>

Reviewed-by: Alex Deucher <[email protected]>

> ---
>  drivers/gpu/drm/amd/amdgpu/amdgpu_mes.c | 13 +++++++++----
>  1 file changed, 9 insertions(+), 4 deletions(-)
>
> diff --git a/drivers/gpu/drm/amd/amdgpu/amdgpu_mes.c 
> b/drivers/gpu/drm/amd/amdgpu/amdgpu_mes.c
> index 6c0dde3786e3..261ddc19c840 100644
> --- a/drivers/gpu/drm/amd/amdgpu/amdgpu_mes.c
> +++ b/drivers/gpu/drm/amd/amdgpu/amdgpu_mes.c
> @@ -250,11 +250,16 @@ int amdgpu_mes_init(struct amdgpu_device *adev)
>                                 goto error_doorbell;
>                         }
>                 }
> -       }
>
> -       adev->gfx.mec.mes_hung_db_array =
> -               kcalloc(amdgpu_mes_get_hung_queue_db_array_size(adev),
> -                       sizeof(u32), GFP_KERNEL);
> +               adev->gfx.mec.mes_hung_db_array =
> +                       kcalloc(amdgpu_mes_get_hung_queue_db_array_size(adev),
> +                               sizeof(u32), GFP_KERNEL);
> +
> +               if (!adev->gfx.mec.mes_hung_db_array) {
> +                       r = -ENOMEM;
> +                       goto error_doorbell;
> +               }
> +       }
>
>         return 0;
>
> --
> 2.43.0
>

Reply via email to