Re: [PATCH] drm/msm/dsi: Fix VM leak in dsi_tx_buf_alloc_6g()
From: Rob Clark
Date: Sat Sep 26 2026 - 11:24:11 EST
On Wed, Sep 16, 2026 at 10:58 AM Wentao Liang <vulab@xxxxxxxxxxx> wrote:
>
> dsi_tx_buf_alloc_6g() takes a reference to the kms VM with
> drm_gpuvm_get() and stores it in msm_host->vm. If
> msm_gem_kernel_new() fails, the function returns early without
> dropping that reference. Since msm_host->tx_gem_obj is cleared on
> the error path, msm_dsi_tx_buf_free() will never see a non-NULL
> tx_gem_obj and thus never calls drm_gpuvm_put(), leaking the VM
> reference.
>
> Drop the VM reference and clear msm_host->vm on the error path.
>
> Fixes: 5e05be782645 ("drm/msm/dsi: free TX buffer in unbind")
> Cc: stable@xxxxxxxxxxxxxxx
> Signed-off-by: Wentao Liang <vulab@xxxxxxxxxxx>
Reviewed-by: Rob Clark <rob.clark@xxxxxxxxxxxxxxxx>
> ---
> drivers/gpu/drm/msm/dsi/dsi_host.c | 2 ++
> 1 file changed, 2 insertions(+)
>
> diff --git a/drivers/gpu/drm/msm/dsi/dsi_host.c b/drivers/gpu/drm/msm/dsi/dsi_host.c
> index 982abaaac00d..29e0de0e0c22 100644
> --- a/drivers/gpu/drm/msm/dsi/dsi_host.c
> +++ b/drivers/gpu/drm/msm/dsi/dsi_host.c
> @@ -1250,6 +1250,8 @@ int dsi_tx_buf_alloc_6g(struct msm_dsi_host *msm_host, int size)
>
> if (IS_ERR(data)) {
> msm_host->tx_gem_obj = NULL;
> + drm_gpuvm_put(msm_host->vm);
> + msm_host->vm = NULL;
> return PTR_ERR(data);
> }
>
> --
> 2.34.1
>