PCI: plda: Fix use-after-free of event IRQs during teardown

plda_pcie_irq_domain_deinit() removes pcie->event_domain via
irq_domain_remove(), but the per-event IRQs mapped from that domain
are requested with devm_request_irq() in plda_init_interrupts(). The
actual free_irq() for a devm-managed IRQ is deferred by devres until
after the calling probe()/remove() function returns.

This means irq_domain_remove() can free the domain's internal data
before the deferred free_irq() for IRQs still mapped into it has run.
When devres later processes that deferred cleanup, it can end up
dereferencing the already-freed domain.

Free each event IRQ explicitly with devm_free_irq() before removing
the domain. This triggers the free immediately and removes the IRQ
from the devres tracking list, so devres will not attempt to free it
a second time later.

Also dispose of the event, INTx, and MSI IRQ mappings with
irq_dispose_mapping() before their owning domains are removed.

Finally, guard the calls to irq_set_chained_handler_and_data() for
pcie->irq, pcie->msi_irq, and pcie->intx_irq so they only run when
those fields hold a valid (>0) IRQ number.

This is a pre-existing issue, flagged by automated review during work
on an earlier, unrelated patch to this driver.

Build-tested and boot-tested on StarFive VisionFive v1.2A board

Fixes: 76c9113968 ("PCI: plda: Add host init/deinit and map bus functions")
Closes: https://lore.kernel.org/linux-pci/20260714115343.4D49E1F000E9@smtp.kernel.org/
Signed-off-by: Ali Tariq <alitariq45892@gmail.com>
Signed-off-by: Manivannan Sadhasivam <manivannan.sadhasivam@oss.qualcomm.com>
Cc: stable@vger.kernel.org
Link: https://patch.msgid.link/20260723140434.675512-2-alitariq45892@gmail.com
This commit is contained in:
Ali Tariq 2026-07-23 19:04:33 +05:00 committed by Manivannan Sadhasivam
parent dc59e4fea9
commit 26b73bae01

View File

@ -559,9 +559,27 @@ EXPORT_SYMBOL_GPL(plda_pcie_setup_iomems);
static void plda_pcie_irq_domain_deinit(struct plda_pcie_rp *pcie)
{
irq_set_chained_handler_and_data(pcie->irq, NULL, NULL);
irq_set_chained_handler_and_data(pcie->msi_irq, NULL, NULL);
irq_set_chained_handler_and_data(pcie->intx_irq, NULL, NULL);
u32 i, event_irq;
if (pcie->irq > 0)
irq_set_chained_handler_and_data(pcie->irq, NULL, NULL);
if (pcie->msi_irq > 0)
irq_set_chained_handler_and_data(pcie->msi_irq, NULL, NULL);
if (pcie->intx_irq > 0)
irq_set_chained_handler_and_data(pcie->intx_irq, NULL, NULL);
for_each_set_bit(i, &pcie->events_bitmap, pcie->num_events) {
event_irq = irq_find_mapping(pcie->event_domain, i);
if (event_irq) {
devm_free_irq(pcie->dev, event_irq, pcie);
irq_dispose_mapping(event_irq);
}
}
if (pcie->intx_irq)
irq_dispose_mapping(pcie->intx_irq);
if (pcie->msi_irq)
irq_dispose_mapping(pcie->msi_irq);
irq_domain_remove(pcie->msi.dev_domain);