From: Suraj Kandpal <[email protected]>

[ Upstream commit 31b42af516afa1e184d1a9f9dd4096c54044269a ]

Sometimes during hotplug scenario or suspend/resume scenario encoder is
not always initialized when intel_hdcp_get_capability add
a check to avoid kernel null pointer dereference.

[ Backport to 6.6.y: this tree uses the older intel_hdcp_capable()
  helper name. Apply the same guard there; the code change is otherwise
  unchanged. ]

Signed-off-by: Suraj Kandpal <[email protected]>
Reviewed-by: Dnyaneshwar Bhadane <[email protected]>
Link: 
https://patchwork.freedesktop.org/patch/msgid/[email protected]
Assisted-by: LLM
Signed-off-by: Artem Dinaburg <[email protected]>
---
CVE: CVE-2024-53051
Upstream: 31b42af516afa1e184d1a9f9dd4096c54044269a
Code change unchanged from v1; only the retained backport note was added.
v1: https://lore.kernel.org/r/[email protected]

 drivers/gpu/drm/i915/display/intel_hdcp.c | 7 ++++++-
 1 file changed, 6 insertions(+), 1 deletion(-)

diff --git a/drivers/gpu/drm/i915/display/intel_hdcp.c 
b/drivers/gpu/drm/i915/display/intel_hdcp.c
index f377c4484e18..f7987fb90bb1 100644
--- a/drivers/gpu/drm/i915/display/intel_hdcp.c
+++ b/drivers/gpu/drm/i915/display/intel_hdcp.c
@@ -142,11 +142,16 @@ int intel_hdcp_read_valid_bksv(struct intel_digital_port 
*dig_port,
 /* Is HDCP1.4 capable on Platform and Sink */
 bool intel_hdcp_capable(struct intel_connector *connector)
 {
-       struct intel_digital_port *dig_port = 
intel_attached_dig_port(connector);
+       struct intel_digital_port *dig_port;
        const struct intel_hdcp_shim *shim = connector->hdcp.shim;
        bool capable = false;
        u8 bksv[5];
 
+       if (!intel_attached_encoder(connector))
+               return capable;
+
+       dig_port = intel_attached_dig_port(connector);
+
        if (!shim)
                return capable;
 
-- 
2.39.5

Reply via email to