mirror of
https://github.com/torvalds/linux.git
synced 2026-09-23 05:04:02 +02:00
mmc: via-sdmmc: cancel card-detect work on remove
Disabling the device interrupt and freeing the IRQ prevents new card-detect
work from being queued, but carddet_work already queued by the handler can
still run after via_sd_remove() returns. via_sdc_card_detect() recovers the
host through container_of() and dereferences its MMIO base; once remove()
returns the host can be freed, so that work would touch freed memory.
Cancel carddet_work after freeing the IRQ and before cancelling
finish_bh_work, which the card-detect handler can also queue. carddet_work
can re-enable the interrupt through via_reset_pcictrl(); mask it again
afterwards.
This issue was found by an in-house static analysis tool and confirmed by
manual code review.
Fixes: f0bf7f61b8 ("mmc: Add new via-sdmmc host controller driver")
Cc: stable@vger.kernel.org
Assisted-by: Codex:gpt-5.6
Signed-off-by: Fan Wu <fanwu01@zju.edu.cn>
Signed-off-by: Ulf Hansson <ulfh@kernel.org>
This commit is contained in:
parent
088eaa92fc
commit
57e5d877f8
|
|
@ -1205,6 +1205,10 @@ static void via_sd_remove(struct pci_dev *pcidev)
|
|||
|
||||
free_irq(pcidev->irq, sdhost);
|
||||
|
||||
cancel_work_sync(&sdhost->carddet_work);
|
||||
/* carddet_work may re-enable the interrupt via via_reset_pcictrl(). */
|
||||
writeb(0x0, sdhost->pcictrl_mmiobase + VIA_CRDR_PCIINTCTRL);
|
||||
|
||||
timer_delete_sync(&sdhost->timer);
|
||||
|
||||
cancel_work_sync(&sdhost->finish_bh_work);
|
||||
|
|
|
|||
Loading…
Reference in New Issue
Block a user