drm/vmwgfx: Fix Use-after-free in validation
[ Upstream commit dfe1323a ] Nodes stored in the validation duplicates hashtable come from an arena allocator that is cleared at the end of vmw_execbuf_process. All nodes are expected to be cleared in vmw_validation_drop_ht but this node escaped because its resource was destroyed prematurely. Fixes: 64ad2abf ("drm/vmwgfx: Adapt validation code for reference-free lookups") Reported-by:Kuzey Arda Bulut <kuzeyardabulut@gmail.com> Signed-off-by:
Ian Forbes <ian.forbes@broadcom.com> Reviewed-by:
Zack Rusin <zack.rusin@broadcom.com> Signed-off-by:
Zack Rusin <zack.rusin@broadcom.com> Link: https://lore.kernel.org/r/20250926195427.1405237-1-ian.forbes@broadcom.com Signed-off-by:
Sasha Levin <sashal@kernel.org>
Loading
Please sign in to comment