From: Allen Pan <[email protected]> [ Upstream commit 334b56cea5d9df5989be6cf1a5898114fa70ad98 ]
[How] Check wheather state is NULL before releasing it. [ Backport to 6.6.y: implemented the same guard in older dc_release_state() in dc.c rather than dc_state_release() in dc_state.c. ] Cc: Mario Limonciello <[email protected]> Cc: Alex Deucher <[email protected]> Cc: [email protected] Reviewed-by: Charlene Liu <[email protected]> Acked-by: Alex Hung <[email protected]> Signed-off-by: Allen Pan <[email protected]> Tested-by: Daniel Wheeler <[email protected]> Signed-off-by: Alex Deucher <[email protected]> Assisted-by: LLM Signed-off-by: Artem Dinaburg <[email protected]> --- Hi Greg, Sasha, and drm amd maintainers, I am working through the small CVE backports still missing from 6.6.y. This one addresses CVE-2024-26948. It adds upstream's NULL guard to the older display-state release helper. The helper is used by display-state cleanup paths and currently dereferences its argument unconditionally. The patch makes the helper NULL-safe. The fix is already present in 6.12.y, 6.18.y, and 7.2.y, but not in 6.6.y. This fix also affects 6.1.y, which will need a separate backport; this submission contains only the 6.6.y patch. The target-specific adjustment is recorded in the bracketed note above. Could you please queue it for 6.6.y? CVE: CVE-2024-26948 Upstream: 334b56cea5d9df5989be6cf1a5898114fa70ad98 AI assistance: An LLM helped identify, adapt, and validate this backport; I reviewed the resulting code and validation evidence. Thanks, Artem Dinaburg drivers/gpu/drm/amd/display/dc/core/dc.c | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/drivers/gpu/drm/amd/display/dc/core/dc.c b/drivers/gpu/drm/amd/display/dc/core/dc.c index bea18f450ac9c7..6ba67a20eb4846 100644 --- a/drivers/gpu/drm/amd/display/dc/core/dc.c +++ b/drivers/gpu/drm/amd/display/dc/core/dc.c @@ -2302,7 +2302,8 @@ static void dc_state_free(struct kref *kref) void dc_release_state(struct dc_state *context) { - kref_put(&context->refcount, dc_state_free); + if (context != NULL) + kref_put(&context->refcount, dc_state_free); } bool dc_set_generic_gpio_for_stereo(bool enable, -- 2.39.5
