Hi Krzysztof,

On Fri, Sep 11, 2026 at 06:11:45AM +0000, Krzysztof Karas wrote:
> It is possible for eb_relocate_parse_slow() to call kvfree() on
> entries outside the original exec array during following
> scenario inside eb_relocate_parse_slow():
> 
> 1) eb_copy_relocations() allocates as many as eb->buffer_count
>    copies for exec entries;
> 2) eb_parse() appends up to two VMAs, right after incrementing
>    eb->buffer_count;
> 3) cleanup under "out" label uses this incremented buffer_count
>    to release relocation pointers from exec array via kvfree(),
>    not from VMA array.
> 
> To amend this problem, ensure that relocation cleanup uses the
> original exec object count, excluding the VMAs appended by the
> command parser.
> 
> Fixes: 8e4ba491b0ba ("drm/i915: Parse command buffer earlier in 
> eb_relocate(slow)")
> Cc: [email protected] # 5.10+
> Assisted-by: GitHub-Copilot:gpt-6-astra
> Signed-off-by: Krzysztof Karas <[email protected]>

pushed to drm-intel-gt-next.

Thanks,
Andi

Reply via email to