KASAN caught amdgpu / HMM use-after-free

Yang, Philip Philip.Yang at amd.com
Wed Feb 27 17:14:04 UTC 2019


Hi Michel,

Yes, I found the same issue and the bug has been fixed by Jerome:

876b462120aa mm/hmm: use reference counting for HMM struct

The fix is on hmm-for-5.1 branch, I cherry-pick it into my local branch 
to workaround the issue.

Regards,
Philip

On 2019-02-27 12:02 p.m., Michel Dänzer wrote:
> 
> See the attached dmesg excerpt. I've hit this a few times running piglit
> with amd-staging-drm-next, first on February 22nd.
> 
> The memory was freed after calling hmm_mirror_unregister in
> amdgpu_mn_destroy.
> 
> 


More information about the amd-gfx mailing list