mirror of
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git
synced 2026-07-22 03:27:30 -04:00
accel/amdxdna: Fix potential amdxdna_umap lifetime race
amdxdna_umap_release() calls the blocking mmu_interval_notifier_remove()
before removing the object from abo->mem.umap_list. If
aie2_populate_range() runs concurrently, it may obtain a reference to an
amdxdna_umap that is being released, leading to a potential use-after-free.
Use kref_get_unless_zero() in aie2_populate_range() when acquiring a
reference. If the reference count has already dropped to zero, release
is in progress and the entry is skipped.
Fixes: e486147c91 ("accel/amdxdna: Add BO import and export")
Reviewed-by: Max Zhen <max.zhen@amd.com>
Signed-off-by: Lizhi Hou <lizhi.hou@amd.com>
Link: https://patch.msgid.link/20260706221228.434099-1-lizhi.hou@amd.com
This commit is contained in:
@@ -1039,7 +1039,7 @@ static int aie2_populate_range(struct amdxdna_gem_obj *abo)
|
||||
found = false;
|
||||
down_write(&xdna->notifier_lock);
|
||||
list_for_each_entry(mapp, &abo->mem.umap_list, node) {
|
||||
if (mapp->invalid) {
|
||||
if (mapp->invalid && kref_get_unless_zero(&mapp->refcnt)) {
|
||||
found = true;
|
||||
break;
|
||||
}
|
||||
@@ -1050,7 +1050,7 @@ static int aie2_populate_range(struct amdxdna_gem_obj *abo)
|
||||
up_write(&xdna->notifier_lock);
|
||||
return 0;
|
||||
}
|
||||
kref_get(&mapp->refcnt);
|
||||
|
||||
up_write(&xdna->notifier_lock);
|
||||
|
||||
mm = mapp->notifier.mm;
|
||||
|
||||
Reference in New Issue
Block a user