From 610bee83fade1c9ada339d8686716abe2ae76b9f Mon Sep 17 00:00:00 2001 From: Prasad Arepalli Date: Mon, 7 Jul 2025 15:14:17 +0530 Subject: [PATCH 1/2] msm: ipa: Avoid use-after-free scenario Introduce changes to avoid use-after-free scenarios by accessing the memory before freeing it. Change-Id: Iaa5d29b400cad593045f3644cb60a51fc09682e8 Signed-off-by: Prasad Arepalli --- drivers/platform/msm/ipa/ipa_v3/ipa_pm.c | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/drivers/platform/msm/ipa/ipa_v3/ipa_pm.c b/drivers/platform/msm/ipa/ipa_v3/ipa_pm.c index c2232d59b691..0db725a54626 100644 --- a/drivers/platform/msm/ipa/ipa_v3/ipa_pm.c +++ b/drivers/platform/msm/ipa/ipa_v3/ipa_pm.c @@ -1,6 +1,7 @@ // SPDX-License-Identifier: GPL-2.0-only /* * Copyright (c) 2017-2021, The Linux Foundation. All rights reserved. + * Copyright (c) Qualcomm Technologies, Inc. and/or its subsidiaries. */ #include @@ -770,9 +771,9 @@ int ipa_pm_register(struct ipa_pm_register_params *params, u32 *hdl) client->skip_clk_vote = params->skip_clk_vote; client->wlock = wakeup_source_register(NULL, client->name); if (!client->wlock) { - ipa_pm_deregister(*hdl); IPA_PM_ERR("IPA wakeup source register failed %s\n", client->name); + ipa_pm_deregister(*hdl); return -ENOMEM; } From c8edf34ac9cfb69a3e4ee9be4e4d12ce57a20a93 Mon Sep 17 00:00:00 2001 From: Sivakanth Vaka Date: Mon, 4 Mar 2024 16:59:59 +0530 Subject: [PATCH 2/2] ipa: Added changes to move the hdr entry to free list Added changes to move the hdr free offset list after deteting the hdrs from the hdr table if delted hdr is pointing to the some proc ctx. Signed-off-by: Sivakanth Vaka Signed-off-by: Avinash Kumar Change-Id: Ic1f20fc8070ae7a45c2d7a5abd5b9c56a96c49cf --- drivers/platform/msm/ipa/ipa_v3/ipa_hdr.c | 15 ++++++++++----- 1 file changed, 10 insertions(+), 5 deletions(-) diff --git a/drivers/platform/msm/ipa/ipa_v3/ipa_hdr.c b/drivers/platform/msm/ipa/ipa_v3/ipa_hdr.c index a3f090def566..28285a6eed57 100644 --- a/drivers/platform/msm/ipa/ipa_v3/ipa_hdr.c +++ b/drivers/platform/msm/ipa/ipa_v3/ipa_hdr.c @@ -710,7 +710,10 @@ static int __ipa3_del_hdr_proc_ctx(u32 proc_ctx_hdl, return 0; } - if (release_hdr) + if (entry->hdr && entry == entry->hdr->proc_ctx) + entry->hdr->proc_ctx = NULL; + + if (entry->hdr && release_hdr) __ipa3_del_hdr(entry->hdr->id, false); /* move the offset entry to appropriate free list */ @@ -774,17 +777,19 @@ int __ipa3_del_hdr(u32 hdr_hdl, bool by_user) return 0; } + if (entry->proc_ctx && entry == entry->proc_ctx->hdr) + entry->proc_ctx->hdr = NULL; + if (entry->is_hdr_proc_ctx || entry->proc_ctx) { dma_unmap_single(ipa3_ctx->pdev, entry->phys_base, entry->hdr_len, DMA_TO_DEVICE); __ipa3_del_hdr_proc_ctx(entry->proc_ctx->id, false, false); - } else { - /* move the offset entry to appropriate free list */ - list_move(&entry->offset_entry->link, - &htbl->head_free_offset_list[entry->offset_entry->bin]); } + /* move the offset entry to appropriate free list */ + list_move(&entry->offset_entry->link, + &htbl->head_free_offset_list[entry->offset_entry->bin]); list_del(&entry->link); htbl->hdr_cnt--; entry->cookie = 0;