Re: [PATCH v2 1/2] drm/msm/a6xx: fix use-after-free of OPP in a6xx_pm_resume

From: Dmitry Baryshkov

Date: Wed Sep 30 2026 - 22:09:12 EST


On Tue, Sep 29, 2026 at 05:20:58PM +0300, Roman Demidov wrote:
> The OPP reference obtained via dev_pm_opp_find_freq_ceil() is dropped
> with dev_pm_opp_put() before being passed to dev_pm_opp_set_opp(). If
> the reference count reaches zero, the OPP object may be freed, leading
> to a use-after-free when dev_pm_opp_set_opp() dereferences it.
>
> Fix the order of calls: first use the OPP to set the required
> performance state, then release the reference.
>
> Fixes: 5a903a44a984 ("drm/msm/a6xx: Introduce GMU wrapper support")
> Signed-off-by: Roman Demidov <roman.demidov.nn@xxxxxxxxx>
> ---
> v2: The dev_pm_opp_find_freq_ceil() function returns an OPP object with an
> incremented reference count. Dropping this reference via dev_pm_opp_put()
> could cause the object to be freed if it is concurrently removed from the
> OPP table. Fix this as Sashiko AI <sashiko-bot@xxxxxxxxxx> suggested.
>
> drivers/gpu/drm/msm/adreno/a6xx_gpu.c | 2 +-
> 1 file changed, 1 insertion(+), 1 deletion(-)
>

Reviewed-by: Dmitry Baryshkov <dmitry.baryshkov@xxxxxxxxxxxxxxxx>


--
With best wishes
Dmitry