mirror of
https://github.com/torvalds/linux.git
synced 2026-07-28 01:55:51 +02:00
thunderbolt: Keep the domain reference while processing hotplug
We process hotplug events in a workqueue that may run after the domain has been removed by tb_domain_remove(). For example if user unloads the driver while at the same time plugging a device router we may have scheduled tb_handle_hotplug() to run. Avoid possible UAF in this case by taking the domain reference before scheduling the hotplug handler in tb_queue_hotplug(). Signed-off-by: Mika Westerberg <mika.westerberg@linux.intel.com>
This commit is contained in:
parent
2fb199dc64
commit
138ec65b2c
|
|
@ -98,7 +98,7 @@ static void tb_queue_hotplug(struct tb *tb, u64 route, u8 port, bool unplug)
|
|||
if (!ev)
|
||||
return;
|
||||
|
||||
ev->tb = tb;
|
||||
ev->tb = tb_domain_get(tb);
|
||||
ev->route = route;
|
||||
ev->port = port;
|
||||
ev->unplug = unplug;
|
||||
|
|
@ -2527,6 +2527,9 @@ static void tb_handle_hotplug(struct work_struct *work)
|
|||
pm_runtime_mark_last_busy(&tb->dev);
|
||||
pm_runtime_put_autosuspend(&tb->dev);
|
||||
|
||||
/* Undo the refcount increased in tb_queue_hotplug() */
|
||||
tb_domain_put(tb);
|
||||
|
||||
kfree(ev);
|
||||
}
|
||||
|
||||
|
|
|
|||
Loading…
Reference in New Issue
Block a user