[PATCH] drm/gem-dma: fix double GEM object put on the mmap error path

From: Baul Lee

Date: Wed Aug 05 2026 - 08:47:37 EST


drm_gem_dma_mmap() drops a GEM reference when the DMA mapping fails:

if (ret)
drm_gem_vm_close(vma);

drm_gem_vm_close() puts vma->vm_private_data. drm_gem_mmap_obj() has
already pointed that at the object, and puts it again when the callback
returns an error:

drm_gem_object_get(obj);
vma->vm_private_data = obj;
...
ret = obj->funcs->mmap(obj, vma);
if (ret)
goto err_drm_gem_object_put;

One get, two puts: a failing dma_mmap_wc() or dma_mmap_pages() underflows
the reference count and can free the object while the caller still holds
it.

The callee does not own that reference. drm_gem_shmem_mmap() returns the
error and leaves the put to the caller, and both callers do it,
drm_gem_mmap_obj() as above and drm_gem_prime_mmap() from its own error
path. Drop the call.

It was harmless until commit f49a51bfdc8e ("drm/shme-helpers: Fix
dma_buf_mmap forwarding bug") moved the vm_private_data assignment ahead
of the callback; before that the field was still NULL when the callback
ran and drm_gem_vm_close() put nothing.

exynos_drm_gem_mmap() and __tegra_gem_mmap() have the same error path.

Fixes: f49a51bfdc8e ("drm/shme-helpers: Fix dma_buf_mmap forwarding bug")
Cc: stable@xxxxxxxxxxxxxxx
Signed-off-by: Baul Lee <baul.lee@xxxxxxxx>
---
drivers/gpu/drm/drm_gem_dma_helper.c | 2 --
1 file changed, 2 deletions(-)

diff --git a/drivers/gpu/drm/drm_gem_dma_helper.c b/drivers/gpu/drm/drm_gem_dma_helper.c
index 1c00a71ab3c9..a34561efd1ae 100644
--- a/drivers/gpu/drm/drm_gem_dma_helper.c
+++ b/drivers/gpu/drm/drm_gem_dma_helper.c
@@ -550,8 +550,6 @@ int drm_gem_dma_mmap(struct drm_gem_dma_object *dma_obj, struct vm_area_struct *
dma_obj->vaddr, dma_obj->dma_addr,
vma->vm_end - vma->vm_start);
}
- if (ret)
- drm_gem_vm_close(vma);

return ret;
}
--
2.50.1 (Apple Git-155)