Thank you for your contribution! Sashiko AI review found 1 potential issue(s) 
to consider:

Pre-existing issues:
- [High] The exact same NULL-pointer dereference vulnerability fixed in 
`drm/i915` also exists in the sibling driver `drm/xe`.
--

--- Patch [1]: [PATCH] drm/i915: Guard against NULL driver_data in 
i915_pci_probe() ---
commit 88147f0f2fd48d4b9d650095dee423ce2e3c8939
Author: Deepanshu Kartikey <[email protected]>

drm/i915: Guard against NULL driver_data in i915_pci_probe()

This commit fixes a NULL pointer dereference in i915_pci_probe() when a
device is force-bound via sysfs driver_override, which results in a NULL
driver_data being returned by pci_match_device().

Link: https://syzkaller.appspot.com/bug?extid=db96c5ff032f4292a8dc

> diff --git a/drivers/gpu/drm/i915/i915_pci.c b/drivers/gpu/drm/i915/i915_pci.c
> index 82415af47d540..2f03f95945f1b 100644
> --- a/drivers/gpu/drm/i915/i915_pci.c
> +++ b/drivers/gpu/drm/i915/i915_pci.c
> @@ -958,6 +958,9 @@ static int i915_pci_probe(struct pci_dev *pdev, const 
> struct pci_device_id *ent)
>               (struct intel_device_info *) ent->driver_data;
>       int err;
>  
> +     if (!intel_info)
> +             return -ENODEV;

[Severity: High]
This is a pre-existing issue, but does the exact same vulnerability exist in
the sibling drm/xe driver?

When a device is force-bound via the sysfs driver_override interface,
xe_pci_probe() in drivers/gpu/drm/xe/xe_pci.c will also receive a dummy
entry where ent->driver_data is NULL. This is cast to desc and passed
directly to find_subplatform():

drivers/gpu/drm/xe/xe_pci.c:xe_pci_probe() {
    ...
    const struct xe_device_desc *desc = (const void *)ent->driver_data;
    ...
    subplatform_desc = find_subplatform(desc, pdev->device);
    ...
}

Inside find_subplatform(), this pointer is unconditionally dereferenced:

drivers/gpu/drm/xe/xe_pci.c:find_subplatform() {
    ...
    for (sp = desc->subplatforms; sp && sp->subplatform; sp++)
    ...
}

Should a similar guard be added to xe_pci_probe() to prevent a kernel
panic there as well?

-- 
Sashiko AI review ยท 
https://sashiko.dev/#/patchset/[email protected]?part=1

Reply via email to