On Sun, Jun 28, 2026 at 2:29 AM Geoffrey McRae <[email protected]> wrote: > > kcalloc but does not check for failure. If the allocation fails, the > pointer remains NULL but the function returns success. Subsequent code > using this buffer will dereference a NULL pointer, causing a kernel > oops. Add a check to return -ENOMEM if the allocation fails. > > Signed-off-by: Geoffrey McRae <[email protected]> > Cc: Alex Deucher <[email protected]> > Cc: Christian König <[email protected]>
Reviewed-by: Alex Deucher <[email protected]> > --- > drivers/gpu/drm/amd/amdgpu/amdgpu_mes.c | 13 +++++++++---- > 1 file changed, 9 insertions(+), 4 deletions(-) > > diff --git a/drivers/gpu/drm/amd/amdgpu/amdgpu_mes.c > b/drivers/gpu/drm/amd/amdgpu/amdgpu_mes.c > index 6c0dde3786e3..261ddc19c840 100644 > --- a/drivers/gpu/drm/amd/amdgpu/amdgpu_mes.c > +++ b/drivers/gpu/drm/amd/amdgpu/amdgpu_mes.c > @@ -250,11 +250,16 @@ int amdgpu_mes_init(struct amdgpu_device *adev) > goto error_doorbell; > } > } > - } > > - adev->gfx.mec.mes_hung_db_array = > - kcalloc(amdgpu_mes_get_hung_queue_db_array_size(adev), > - sizeof(u32), GFP_KERNEL); > + adev->gfx.mec.mes_hung_db_array = > + kcalloc(amdgpu_mes_get_hung_queue_db_array_size(adev), > + sizeof(u32), GFP_KERNEL); > + > + if (!adev->gfx.mec.mes_hung_db_array) { > + r = -ENOMEM; > + goto error_doorbell; > + } > + } > > return 0; > > -- > 2.43.0 >
