drm: writeback: Fix use after free in drm_writeback_connector_cleanup()
authorDan Carpenter <dan.carpenter@linaro.org>
Wed, 12 Feb 2025 15:23:48 +0000 (18:23 +0300)
committerMaxime Ripard <mripard@kernel.org>
Thu, 13 Feb 2025 08:50:20 +0000 (09:50 +0100)
The drm_writeback_cleanup_job() function frees "pos" so call
list_del(&pos->list_entry) first to avoid a use after free.

Fixes: 1914ba2b91ea ("drm: writeback: Create drmm variants for drm_writeback_connector initialization")
Signed-off-by: Dan Carpenter <dan.carpenter@linaro.org>
Reviewed-by: Dmitry Baryshkov <dmitry.baryshkov@linaro.org>
Link: https://patchwork.freedesktop.org/patch/msgid/78abd541-71e9-4b3b-a05d-2c7caf8d5b2f@stanley.mountain
Signed-off-by: Maxime Ripard <mripard@kernel.org>
drivers/gpu/drm/drm_writeback.c

index 3628fbef77524a7390b3929896a20f1c0a82117d..f139b49af4c9444a1fe9c0742759adfafc2e0a68 100644 (file)
@@ -360,8 +360,8 @@ static void drm_writeback_connector_cleanup(struct drm_device *dev,
 
        spin_lock_irqsave(&wb_connector->job_lock, flags);
        list_for_each_entry_safe(pos, n, &wb_connector->job_queue, list_entry) {
-               drm_writeback_cleanup_job(pos);
                list_del(&pos->list_entry);
+               drm_writeback_cleanup_job(pos);
        }
        spin_unlock_irqrestore(&wb_connector->job_lock, flags);
 }