mirror of
https://github.com/torvalds/linux.git
synced 2026-09-22 12:44:03 +02:00
usb: typec: thunderbolt: Disable work before freeing tbt on remove
tbt_altmode_remove() drops the plug and cable references without
draining tbt->work. The work function dereferences those references,
and can also requeue itself in its error path. The VDM callbacks can
queue the same work item.
Disable and drain tbt->work before dropping the references. This waits
for an existing invocation and prevents subsequent schedule_work()
calls from queueing it during teardown.
This issue was found by an in-house static analysis tool and confirmed
by manual code review.
Fixes: 100e257386 ("usb: typec: Add driver for Thunderbolt 3 Alternate Mode")
Cc: stable@vger.kernel.org
Assisted-by: Codex:gpt-5.6
Signed-off-by: Fan Wu <fanwu01@zju.edu.cn>
Acked-by: Heikki Krogerus <heikki.krogerus@linux.intel.com>
Link: https://patch.msgid.link/20260802014959.416687-1-fanwu01@zju.edu.cn
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
This commit is contained in:
parent
3d9eeb3361
commit
92090f6ff2
|
|
@ -307,6 +307,8 @@ static void tbt_altmode_remove(struct typec_altmode *alt)
|
|||
{
|
||||
struct tbt_altmode *tbt = typec_altmode_get_drvdata(alt);
|
||||
|
||||
disable_work_sync(&tbt->work);
|
||||
|
||||
for (int i = TYPEC_PLUG_SOP_PP; i >= 0; --i) {
|
||||
if (tbt->plug[i])
|
||||
typec_altmode_put_plug(tbt->plug[i]);
|
||||
|
|
|
|||
Loading…
Reference in New Issue
Block a user