mirror of
https://github.com/BobTheBlinker/android_kernel_motorola_sm6375.git
synced 2026-10-07 12:25:00 -04:00
msm: virtio_npu: Fix use-after-free issue in unmap_buf
address the security CR of virtio_npu driver Change-Id: Ibf656fa76dedb19086b75d8bf519b2f415ac8d22 Signed-off-by: Gao Wang <quic_gaowang@quicinc.com>
This commit is contained in:
parent
c5539fb1c2
commit
a721c06f7d
1 changed files with 4 additions and 0 deletions
|
|
@ -1,6 +1,7 @@
|
|||
// SPDX-License-Identifier: GPL-2.0-only
|
||||
/*
|
||||
* Copyright (c) 2021, The Linux Foundation. All rights reserved.
|
||||
* Copyright (c) 2022-2024 Qualcomm Innovation Center, Inc. All rights reserved.
|
||||
*/
|
||||
|
||||
#include <linux/cdev.h>
|
||||
|
|
@ -668,8 +669,10 @@ fail:
|
|||
static int32_t virt_npu_unmap_buf(struct npu_client *client,
|
||||
int buf_hdl, uint64_t iova)
|
||||
{
|
||||
struct npu_device *npu_dev = client->npu_dev;
|
||||
struct npu_ion_buf *ion_buf;
|
||||
|
||||
mutex_lock(&npu_dev->lock);
|
||||
/* clear entry and retrieve the corresponding buffer */
|
||||
ion_buf = npu_get_npu_ion_buffer(client, buf_hdl);
|
||||
if (!ion_buf) {
|
||||
|
|
@ -694,6 +697,7 @@ static int32_t virt_npu_unmap_buf(struct npu_client *client,
|
|||
NPU_DBG("unmapped mem addr:0x%llx size:0x%x\n", ion_buf->iova,
|
||||
ion_buf->size);
|
||||
npu_free_npu_ion_buffer(client, buf_hdl);
|
||||
mutex_unlock(&npu_dev->lock);
|
||||
|
||||
return 0;
|
||||
}
|
||||
|
|
|
|||
Loading…
Reference in a new issue