Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
Pre-existing issues: - [High] The exact same NULL-pointer dereference vulnerability fixed in `drm/i915` also exists in the sibling driver `drm/xe`. -- --- Patch [1]: [PATCH] drm/i915: Guard against NULL driver_data in i915_pci_probe() --- commit 88147f0f2fd48d4b9d650095dee423ce2e3c8939 Author: Deepanshu Kartikey <[email protected]> drm/i915: Guard against NULL driver_data in i915_pci_probe() This commit fixes a NULL pointer dereference in i915_pci_probe() when a device is force-bound via sysfs driver_override, which results in a NULL driver_data being returned by pci_match_device(). Link: https://syzkaller.appspot.com/bug?extid=db96c5ff032f4292a8dc > diff --git a/drivers/gpu/drm/i915/i915_pci.c b/drivers/gpu/drm/i915/i915_pci.c > index 82415af47d540..2f03f95945f1b 100644 > --- a/drivers/gpu/drm/i915/i915_pci.c > +++ b/drivers/gpu/drm/i915/i915_pci.c > @@ -958,6 +958,9 @@ static int i915_pci_probe(struct pci_dev *pdev, const > struct pci_device_id *ent) > (struct intel_device_info *) ent->driver_data; > int err; > > + if (!intel_info) > + return -ENODEV; [Severity: High] This is a pre-existing issue, but does the exact same vulnerability exist in the sibling drm/xe driver? When a device is force-bound via the sysfs driver_override interface, xe_pci_probe() in drivers/gpu/drm/xe/xe_pci.c will also receive a dummy entry where ent->driver_data is NULL. This is cast to desc and passed directly to find_subplatform(): drivers/gpu/drm/xe/xe_pci.c:xe_pci_probe() { ... const struct xe_device_desc *desc = (const void *)ent->driver_data; ... subplatform_desc = find_subplatform(desc, pdev->device); ... } Inside find_subplatform(), this pointer is unconditionally dereferenced: drivers/gpu/drm/xe/xe_pci.c:find_subplatform() { ... for (sp = desc->subplatforms; sp && sp->subplatform; sp++) ... } Should a similar guard be added to xe_pci_probe() to prevent a kernel panic there as well? -- Sashiko AI review ยท https://sashiko.dev/#/patchset/[email protected]?part=1
