mirror of
https://github.com/torvalds/linux.git
synced 2026-09-24 06:24:02 +02:00
PCI: plda: Fix use-after-free of event IRQs during teardown
plda_pcie_irq_domain_deinit() removes pcie->event_domain via
irq_domain_remove(), but the per-event IRQs mapped from that domain
are requested with devm_request_irq() in plda_init_interrupts(). The
actual free_irq() for a devm-managed IRQ is deferred by devres until
after the calling probe()/remove() function returns.
This means irq_domain_remove() can free the domain's internal data
before the deferred free_irq() for IRQs still mapped into it has run.
When devres later processes that deferred cleanup, it can end up
dereferencing the already-freed domain.
Free each event IRQ explicitly with devm_free_irq() before removing
the domain. This triggers the free immediately and removes the IRQ
from the devres tracking list, so devres will not attempt to free it
a second time later.
Also dispose of the event, INTx, and MSI IRQ mappings with
irq_dispose_mapping() before their owning domains are removed.
Finally, guard the calls to irq_set_chained_handler_and_data() for
pcie->irq, pcie->msi_irq, and pcie->intx_irq so they only run when
those fields hold a valid (>0) IRQ number.
This is a pre-existing issue, flagged by automated review during work
on an earlier, unrelated patch to this driver.
Build-tested and boot-tested on StarFive VisionFive v1.2A board
Fixes: 76c9113968 ("PCI: plda: Add host init/deinit and map bus functions")
Closes: https://lore.kernel.org/linux-pci/20260714115343.4D49E1F000E9@smtp.kernel.org/
Signed-off-by: Ali Tariq <alitariq45892@gmail.com>
Signed-off-by: Manivannan Sadhasivam <manivannan.sadhasivam@oss.qualcomm.com>
Cc: stable@vger.kernel.org
Link: https://patch.msgid.link/20260723140434.675512-2-alitariq45892@gmail.com
This commit is contained in:
parent
dc59e4fea9
commit
26b73bae01
|
|
@ -559,9 +559,27 @@ EXPORT_SYMBOL_GPL(plda_pcie_setup_iomems);
|
|||
|
||||
static void plda_pcie_irq_domain_deinit(struct plda_pcie_rp *pcie)
|
||||
{
|
||||
irq_set_chained_handler_and_data(pcie->irq, NULL, NULL);
|
||||
irq_set_chained_handler_and_data(pcie->msi_irq, NULL, NULL);
|
||||
irq_set_chained_handler_and_data(pcie->intx_irq, NULL, NULL);
|
||||
u32 i, event_irq;
|
||||
|
||||
if (pcie->irq > 0)
|
||||
irq_set_chained_handler_and_data(pcie->irq, NULL, NULL);
|
||||
if (pcie->msi_irq > 0)
|
||||
irq_set_chained_handler_and_data(pcie->msi_irq, NULL, NULL);
|
||||
if (pcie->intx_irq > 0)
|
||||
irq_set_chained_handler_and_data(pcie->intx_irq, NULL, NULL);
|
||||
|
||||
for_each_set_bit(i, &pcie->events_bitmap, pcie->num_events) {
|
||||
event_irq = irq_find_mapping(pcie->event_domain, i);
|
||||
if (event_irq) {
|
||||
devm_free_irq(pcie->dev, event_irq, pcie);
|
||||
irq_dispose_mapping(event_irq);
|
||||
}
|
||||
}
|
||||
|
||||
if (pcie->intx_irq)
|
||||
irq_dispose_mapping(pcie->intx_irq);
|
||||
if (pcie->msi_irq)
|
||||
irq_dispose_mapping(pcie->msi_irq);
|
||||
|
||||
irq_domain_remove(pcie->msi.dev_domain);
|
||||
|
||||
|
|
|
|||
Loading…
Reference in New Issue
Block a user