Thank you for your contribution! Sashiko AI review found 1 potential issue(s) 
to consider:
- [High] drm/bridge: it6505: regmap UAF on DP AUX access after driver unbind
--

commit 258ee9e0d0d476579fb9e6be277ae45cea6d1cde
Author: Daniel Golle <[email protected]>

drm/bridge: it6505: unregister DP AUX adapter on bridge detach

The DP AUX adapter is registered in .attach() but only unregistered
in i2c remove(), causing registration failure on rebind. This commit
moves the unregistration to .detach() and adds it to the .attach() error path.

> diff --git a/drivers/gpu/drm/bridge/ite-it6505.c 
> b/drivers/gpu/drm/bridge/ite-it6505.c
> index 9c4aae383c1c5..19bab8d65e222 100644
> --- a/drivers/gpu/drm/bridge/ite-it6505.c
> +++ b/drivers/gpu/drm/bridge/ite-it6505.c
[ ... ]
> @@ -3655,7 +3657,6 @@ static void it6505_i2c_remove(struct i2c_client *client)
>       struct it6505 *it6505 = i2c_get_clientdata(client);
>  
>       drm_bridge_remove(&it6505->bridge);
> -     drm_dp_aux_unregister(&it6505->aux);

[Severity: High]
Does removing drm_dp_aux_unregister() from the I2C remove path leave the DP
AUX character device and I2C adapter registered when the driver is unbound?

If the I2C driver is unbound via sysfs (e.g., 
/sys/bus/i2c/drivers/it6505/unbind)
while the DRM display pipeline remains attached, it6505_i2c_remove() executes
and returns. The driver core then automatically executes devres cleanup,
which destroys it6505->regmap.

Because the DP AUX adapter and its /dev/drm_dp_auxN character device are no
longer unregistered in this path, they remain fully registered and exposed to
userspace.

Any subsequent I/O on the char device will invoke it6505_aux_transfer(),
which calls it6505_aux_do_transfer(). This function unconditionally accesses
the it6505->regmap pointer that was just freed by devres during I2C unbind.

Similarly, any DRM atomic commit triggered by userspace will traverse the
still-attached bridge chain and call bridge callbacks that access the freed
regmap.

Can this lifetime mismatch lead to a use-after-free and memory corruption?

>       it6505_debugfs_remove(it6505);
>       it6505_remove_notifier_module(it6505);
>       disable_irq(it6505->irq);

-- 
Sashiko AI review ยท 
https://sashiko.dev/#/patchset/[email protected]?part=4

Reply via email to