Re: [PATCH v2 1/3] drm/nouveau/uvmm: fix NULL deref unwinding an OP_MAP_SPARSE op

From: lyude

Date: Tue Aug 11 2026 - 17:27:14 EST


Reviewed-by: Lyude Paul <lyude@xxxxxxxxxx>

On Tue, 2026-08-11 at 16:46 +0800, Zhenhao Wan wrote:
> Each bind_job_op is zeroed by kzalloc_obj() in
> bind_job_op_from_uop(),
> and the OP_MAP_SPARSE case in nouveau_uvmm_bind_job_submit() only
> creates
> a region, so op->ops stays NULL for a successfully processed sparse
> map.
>
> If a later op in the same job fails, the reverse unwind loop revisits
> that
> op and calls drm_gpuva_ops_free(&uvmm->base, op->ops)
> unconditionally.
> drm_gpuva_ops_free() dereferences its argument right away
> (list_for_each_entry_safe on &ops->list), so a NULL op->ops oopses.
> The
> path is reachable by any render-node fd holder, since NOUVEAU_VM_BIND
> is
> DRM_RENDER_ALLOW.
>
> Guard the free with IS_ERR_OR_NULL(), as
> nouveau_uvmm_bind_job_cleanup()
> already does for the identical free.
>
> Fixes: b88baab82871 ("drm/nouveau: implement new VM_BIND uAPI")
> Reported-by: Yuhao Jiang <danisjiang@xxxxxxxxx>
> Assisted-by: Claude:claude-opus-5
> Cc: stable@xxxxxxxxxxxxxxx
> Signed-off-by: Zhenhao Wan <whi4ed0g@xxxxxxxxx>
> ---
>  drivers/gpu/drm/nouveau/nouveau_uvmm.c | 3 ++-
>  1 file changed, 2 insertions(+), 1 deletion(-)
>
> diff --git a/drivers/gpu/drm/nouveau/nouveau_uvmm.c
> b/drivers/gpu/drm/nouveau/nouveau_uvmm.c
> index 36445915aa58..849bf42c124e 100644
> --- a/drivers/gpu/drm/nouveau/nouveau_uvmm.c
> +++ b/drivers/gpu/drm/nouveau/nouveau_uvmm.c
> @@ -1489,7 +1489,8 @@ nouveau_uvmm_bind_job_submit(struct nouveau_job
> *job,
>   break;
>   }
>  
> - drm_gpuva_ops_free(&uvmm->base, op->ops);
> + if (!IS_ERR_OR_NULL(op->ops))
> + drm_gpuva_ops_free(&uvmm->base, op->ops);
>   op->ops = NULL;
>   op->reg = NULL;
>   }