Thank you for your contribution! Sashiko AI review found 1 potential issue(s) 
to consider:
- [High] drm/mediatek: UAF in mtk_crtc_create() due to dangling mutex_dev
--

commit 8e4c071af71a8f36ce4623ffd3129ead77322d8b
Author: Wentao Liang <[email protected]>

drm/mediatek: Fix pdev reference leak in mtk_drm_bind()

This commit addresses a device reference leak in mtk_drm_bind() by dropping
the reference to the disp-mutex device via put_device() when returning early
for non-master components.

> diff --git a/drivers/gpu/drm/mediatek/mtk_drm_drv.c 
> b/drivers/gpu/drm/mediatek/mtk_drm_drv.c
> --- a/drivers/gpu/drm/mediatek/mtk_drm_drv.c
> +++ b/drivers/gpu/drm/mediatek/mtk_drm_drv.c
> @@ -638,8 +638,10 @@ static int mtk_drm_bind(struct device *dev)
>       private->mtk_drm_bound = true;
>       private->dev = dev;
>  
> -     if (!mtk_drm_get_all_drm_priv(dev))
> +     if (!mtk_drm_get_all_drm_priv(dev)) {
> +             put_device(private->mutex_dev);
>               return 0;
> +     }

[Severity: High]
Does this introduce a dangling pointer that could lead to a Use-After-Free?

When put_device(private->mutex_dev) is called, the reference is dropped, but
the pointer private->mutex_dev is left intact while returning success.

Later, when the master component binds, it initializes the CRTCs for all
components. In mtk_crtc_create(), it retrieves the non-master's private
structure and uses this pointer:

drivers/gpu/drm/mediatek/mtk_crtc.c:mtk_crtc_create() {
    ...
    mtk_crtc->mutex = mtk_mutex_get(priv->mutex_dev);
    ...
}

This accesses the potentially freed device memory in mtk_mutex_get():

drivers/soc/mediatek/mtk-mutex.c:mtk_mutex_get() {
    struct mtk_mutex_ctx *mtx = dev_get_drvdata(dev);
    ...
}

If the disp-mutex device is unregistered between the non-master and master
binds, could this lead to a memory corruption or panic? Should
private->mutex_dev be set to NULL after the put_device() call?

-- 
Sashiko AI review ยท 
https://sashiko.dev/#/patchset/[email protected]?part=1

Reply via email to