From 80f8ee28db7e6601e96df6bd21306a7c47341de3 Mon Sep 17 00:00:00 2001 From: Kasin Li Date: Fri, 17 Nov 2023 02:46:06 +0800 Subject: [PATCH] soc: hgsl: fix race of isync timeline when creating In isync timeline create, after timeline object is attached into idr and unlock the isync_timeline_lock, timeline object still is accessed. if there is a release thread which try to release the same timeline object, then maybe cause UAF issue. Move the access operation into lock to avoid. Change-Id: Ie2ff412b90924acb8f40e182f26c770b1f110a56 Signed-off-by: Kasin Li --- drivers/soc/qcom/hgsl/hgsl_sync.c | 10 ++++++---- 1 file changed, 6 insertions(+), 4 deletions(-) diff --git a/drivers/soc/qcom/hgsl/hgsl_sync.c b/drivers/soc/qcom/hgsl/hgsl_sync.c index 0b8a7fd6a1d5..5efc7c948c87 100644 --- a/drivers/soc/qcom/hgsl/hgsl_sync.c +++ b/drivers/soc/qcom/hgsl/hgsl_sync.c @@ -275,14 +275,16 @@ int hgsl_isync_timeline_create(struct hgsl_priv *priv, idr_preload(GFP_KERNEL); spin_lock(&priv->isync_timeline_lock); idr = idr_alloc(&priv->isync_timeline_idr, timeline, 1, 0, GFP_NOWAIT); - spin_unlock(&priv->isync_timeline_lock); - idr_preload_end(); - if (idr > 0) { timeline->id = idr; *timeline_id = idr; ret = 0; - } else + } + spin_unlock(&priv->isync_timeline_lock); + idr_preload_end(); + + /* allocate IDR failed */ + if (ret != 0) kfree(timeline); return ret;