Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider: - [High] drm/mediatek: UAF in mtk_crtc_create() due to dangling mutex_dev --
commit 8e4c071af71a8f36ce4623ffd3129ead77322d8b Author: Wentao Liang <[email protected]> drm/mediatek: Fix pdev reference leak in mtk_drm_bind() This commit addresses a device reference leak in mtk_drm_bind() by dropping the reference to the disp-mutex device via put_device() when returning early for non-master components. > diff --git a/drivers/gpu/drm/mediatek/mtk_drm_drv.c > b/drivers/gpu/drm/mediatek/mtk_drm_drv.c > --- a/drivers/gpu/drm/mediatek/mtk_drm_drv.c > +++ b/drivers/gpu/drm/mediatek/mtk_drm_drv.c > @@ -638,8 +638,10 @@ static int mtk_drm_bind(struct device *dev) > private->mtk_drm_bound = true; > private->dev = dev; > > - if (!mtk_drm_get_all_drm_priv(dev)) > + if (!mtk_drm_get_all_drm_priv(dev)) { > + put_device(private->mutex_dev); > return 0; > + } [Severity: High] Does this introduce a dangling pointer that could lead to a Use-After-Free? When put_device(private->mutex_dev) is called, the reference is dropped, but the pointer private->mutex_dev is left intact while returning success. Later, when the master component binds, it initializes the CRTCs for all components. In mtk_crtc_create(), it retrieves the non-master's private structure and uses this pointer: drivers/gpu/drm/mediatek/mtk_crtc.c:mtk_crtc_create() { ... mtk_crtc->mutex = mtk_mutex_get(priv->mutex_dev); ... } This accesses the potentially freed device memory in mtk_mutex_get(): drivers/soc/mediatek/mtk-mutex.c:mtk_mutex_get() { struct mtk_mutex_ctx *mtx = dev_get_drvdata(dev); ... } If the disp-mutex device is unregistered between the non-master and master binds, could this lead to a memory corruption or panic? Should private->mutex_dev be set to NULL after the put_device() call? -- Sashiko AI review ยท https://sashiko.dev/#/patchset/[email protected]?part=1
