From a721c06f7d24b8ce8136ebf1c031d4f4e0f6dbda Mon Sep 17 00:00:00 2001 From: Gao Wang Date: Thu, 19 Sep 2024 16:19:59 +0800 Subject: [PATCH] msm: virtio_npu: Fix use-after-free issue in unmap_buf address the security CR of virtio_npu driver Change-Id: Ibf656fa76dedb19086b75d8bf519b2f415ac8d22 Signed-off-by: Gao Wang --- drivers/media/platform/msm/npu/virtio_npu.c | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/drivers/media/platform/msm/npu/virtio_npu.c b/drivers/media/platform/msm/npu/virtio_npu.c index bed8eac6fe68..f1cceb8c8605 100644 --- a/drivers/media/platform/msm/npu/virtio_npu.c +++ b/drivers/media/platform/msm/npu/virtio_npu.c @@ -1,6 +1,7 @@ // SPDX-License-Identifier: GPL-2.0-only /* * Copyright (c) 2021, The Linux Foundation. All rights reserved. + * Copyright (c) 2022-2024 Qualcomm Innovation Center, Inc. All rights reserved. */ #include @@ -668,8 +669,10 @@ fail: static int32_t virt_npu_unmap_buf(struct npu_client *client, int buf_hdl, uint64_t iova) { + struct npu_device *npu_dev = client->npu_dev; struct npu_ion_buf *ion_buf; + mutex_lock(&npu_dev->lock); /* clear entry and retrieve the corresponding buffer */ ion_buf = npu_get_npu_ion_buffer(client, buf_hdl); if (!ion_buf) { @@ -694,6 +697,7 @@ static int32_t virt_npu_unmap_buf(struct npu_client *client, NPU_DBG("unmapped mem addr:0x%llx size:0x%x\n", ion_buf->iova, ion_buf->size); npu_free_npu_ion_buffer(client, buf_hdl); + mutex_unlock(&npu_dev->lock); return 0; }