Message ID | 20210811175052.21254-1-paskripkin@gmail.com (mailing list archive) |
---|---|
State | New, archived |
Headers | show |
Series | [next] udmabuf: fix general protection fault in udmabuf_create | expand |
On Wed, Aug 11, 2021 at 08:50:52PM +0300, Pavel Skripkin wrote: > Syzbot reported general protection fault in udmabuf_create. The problem > was in wrong error handling. > > In commit 16c243e99d33 ("udmabuf: Add support for mapping hugepages (v4)") > shmem_read_mapping_page() call was replaced with find_get_page_flags(), > but find_get_page_flags() returns NULL on failure instead PTR_ERR(). > > Wrong error checking was causing GPF in get_page(), since passed page > was equal to NULL. Fix it by changing if (IS_ER(!hpage)) to if (!hpage) > > Reported-by: syzbot+e9cd3122a37c5d6c51e8@syzkaller.appspotmail.com > Fixes: 16c243e99d33 ("udmabuf: Add support for mapping hugepages (v4)") > Signed-off-by: Pavel Skripkin <paskripkin@gmail.com> Pushed to drm-misc-next. thanks, Gerd
diff --git a/drivers/dma-buf/udmabuf.c b/drivers/dma-buf/udmabuf.c index 8df761a10251..c57a609db75b 100644 --- a/drivers/dma-buf/udmabuf.c +++ b/drivers/dma-buf/udmabuf.c @@ -227,8 +227,8 @@ static long udmabuf_create(struct miscdevice *device, if (!hpage) { hpage = find_get_page_flags(mapping, pgoff, FGP_ACCESSED); - if (IS_ERR(hpage)) { - ret = PTR_ERR(hpage); + if (!hpage) { + ret = -EINVAL; goto err; } }
Syzbot reported general protection fault in udmabuf_create. The problem was in wrong error handling. In commit 16c243e99d33 ("udmabuf: Add support for mapping hugepages (v4)") shmem_read_mapping_page() call was replaced with find_get_page_flags(), but find_get_page_flags() returns NULL on failure instead PTR_ERR(). Wrong error checking was causing GPF in get_page(), since passed page was equal to NULL. Fix it by changing if (IS_ER(!hpage)) to if (!hpage) Reported-by: syzbot+e9cd3122a37c5d6c51e8@syzkaller.appspotmail.com Fixes: 16c243e99d33 ("udmabuf: Add support for mapping hugepages (v4)") Signed-off-by: Pavel Skripkin <paskripkin@gmail.com> --- drivers/dma-buf/udmabuf.c | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-)