msm: virtio_npu: Fix use-after-free issue in unmap_buf

address the security CR of virtio_npu driver

Change-Id: Ibf656fa76dedb19086b75d8bf519b2f415ac8d22
Signed-off-by: Gao Wang <quic_gaowang@quicinc.com>
This commit is contained in:
Gao Wang 2024-09-19 16:19:59 +08:00
commit a721c06f7d

View file

@ -1,6 +1,7 @@
// SPDX-License-Identifier: GPL-2.0-only
/*
* Copyright (c) 2021, The Linux Foundation. All rights reserved.
* Copyright (c) 2022-2024 Qualcomm Innovation Center, Inc. All rights reserved.
*/
#include <linux/cdev.h>
@ -668,8 +669,10 @@ fail:
static int32_t virt_npu_unmap_buf(struct npu_client *client,
int buf_hdl, uint64_t iova)
{
struct npu_device *npu_dev = client->npu_dev;
struct npu_ion_buf *ion_buf;
mutex_lock(&npu_dev->lock);
/* clear entry and retrieve the corresponding buffer */
ion_buf = npu_get_npu_ion_buffer(client, buf_hdl);
if (!ion_buf) {
@ -694,6 +697,7 @@ static int32_t virt_npu_unmap_buf(struct npu_client *client,
NPU_DBG("unmapped mem addr:0x%llx size:0x%x\n", ion_buf->iova,
ion_buf->size);
npu_free_npu_ion_buffer(client, buf_hdl);
mutex_unlock(&npu_dev->lock);
return 0;
}