kgsl: Avoid use after free in kgsl_destroy_ion()

When deallocating dma-buf metadata in kgsl_destroy_ion, the priv_data
pointer in the associated kgsl_mem_entry structure is not reset after
kfree(). To avoid use after free, set entry->priv_data to NULL
immediately after freeing metadata.

Change-Id: Ia222d3a88666b7ee406f1508eb37a4eef766c83e
Signed-off-by: Shiv Kumar <shikum@qti.qualcomm.com>
Signed-off-by: Pankaj Gupta <gpankaj@qti.qualcomm.com>
This commit is contained in:
Pankaj Gupta 2025-08-19 11:00:16 +05:30 • committed by Michael Bestas
commit 374cf47171
No known key found for this signature in database
GPG key ID: CC95044519BE6669

View file

@ -355,6 +355,7 @@ static void kgsl_destroy_ion(struct kgsl_memdesc *memdesc)
}
memdesc->sgt = NULL;
entry->priv_data = NULL;
}
static const struct kgsl_memdesc_ops kgsl_dmabuf_ops = {