msm: virtio_npu: Fix use-after-free issue in virt_npu_map_buf

address the security CR of virtio_npu driver

Change-Id: Ib77014bc12490e7b09367354024baa2754d3e433
Signed-off-by: gaowang <quic_gaowang@quicinc.com>
This commit is contained in:
gaowang 2024-09-24 16:19:44 +08:00 • committed by Gao Wang
commit 79c14fa641

View file

@ -814,6 +814,7 @@ static int32_t virt_npu_map_buf(struct npu_client *client,
struct npu_ion_buf *ion_buf = NULL;
int rc = 0;
mutex_lock(&npu_dev->lock);
ion_buf = npu_alloc_npu_ion_buffer(client, buf_hdl, size);
if (!ion_buf) {
NPU_ERR("fail to alloc npu_ion_buffer\n");
@ -853,6 +854,7 @@ static int32_t virt_npu_map_buf(struct npu_client *client,
rc = virt_npu_mmap(client, 0, ion_buf->table->sgl,
ion_buf->table->nents, size, &ion_buf->iova);
mutex_unlock(&npu_dev->lock);
map_end:
if (rc)