rpmsg update for v7.2

Fix use-after-free in rpmsg-char driver.
 -----BEGIN PGP SIGNATURE-----
 
 iQJCBAABCgAsFiEEBd4DzF816k8JZtUlCx85Pw2ZrcUFAmo2pc0OHGJqb3JuQGty
 eW8uc2UACgkQCx85Pw2ZrcVsQBAArnG1O+UQjt8CViyIknMdrTEplFcYQvSMwyDu
 jQVcz9Y0exom1+CgZPe9zTuR/wEl7t8O9wxjJm+5w1XeiCXl/CElwaZ5FEZxE5NF
 xi7jGbvJDVMgxHBTZ4x4hJE+MgxkwKpLn7dKZuXGUi0AkvPsWVusQPrmbPryT8VB
 9Qx5FaZMz2wTy92Kx3X9S5/4eixG4zX7cVGAJVlGHxFhxWI3M0S5XxoVClI0aSc7
 luhe8bYiA9AtXzEVRI3k2eEeOC/MtSAoZXcU3eef8BhH9YENNv1s4dLHEasN7nuP
 9WozrEn2zDrzi38G6RNra+UIxl1lzuNyQaTJGxpKypo71zmJbUgbySmrtwt9akAC
 ZyXVSKOCp8eZqu1PXFBacsiIDJJEHt2dcgEHXkw0XMl/JSQwEfO5v/ohvnyl9UX4
 VpCPjevKae00LUEFA8IhTgfP0zKLqAlFR/aiZrF2s8eJuxv7Y50SWi5ArVj/6ioe
 B7yDxQNuH/6VM4K29E7vh/81oQETF4x87QNBr1WC26pAMNlPOYrLJ0rvu6fkER+H
 OXDlA5GpwqrnJJy4fBMISrU3hdqADkttgdW1knRmY9jMP78pwH9eGfpra+p54IzF
 28n/ujn+RbksV0cXK/JX7p84Lk9Ik/ZzTkwq2vfSUjZJKI66ASLplZCfqWm+fvyp
 6KPym/c=
 =2sdb
 -----END PGP SIGNATURE-----

Merge tag 'rpmsg-v7.2' of git://git.kernel.org/pub/scm/linux/kernel/git/remoteproc/linux

Pull rpmsg update from Bjorn Andersson:

 - Fix use-after-free in rpmsg-char driver

* tag 'rpmsg-v7.2' of git://git.kernel.org/pub/scm/linux/kernel/git/remoteproc/linux:
  rpmsg: char: Fix use-after-free on probe error path
This commit is contained in:
Linus Torvalds 2026-06-20 23:31:15 -07:00
commit c7f112e12d

View File

@ -104,6 +104,9 @@ static int rpmsg_ept_cb(struct rpmsg_device *rpdev, void *buf, int len,
struct rpmsg_eptdev *eptdev = priv;
struct sk_buff *skb;
if (!eptdev)
return 0;
skb = alloc_skb(len, GFP_ATOMIC);
if (!skb)
return -ENOMEM;
@ -124,6 +127,9 @@ static int rpmsg_ept_flow_cb(struct rpmsg_device *rpdev, void *priv, bool enable
{
struct rpmsg_eptdev *eptdev = priv;
if (!eptdev)
return 0;
eptdev->remote_flow_restricted = enable;
eptdev->remote_flow_updated = true;
@ -490,6 +496,7 @@ static int rpmsg_chrdev_probe(struct rpmsg_device *rpdev)
struct rpmsg_channel_info chinfo;
struct rpmsg_eptdev *eptdev;
struct device *dev = &rpdev->dev;
int ret;
memcpy(chinfo.name, rpdev->id.name, RPMSG_NAME_SIZE);
chinfo.src = rpdev->src;
@ -502,13 +509,17 @@ static int rpmsg_chrdev_probe(struct rpmsg_device *rpdev)
/* Set the default_ept to the rpmsg device endpoint */
eptdev->default_ept = rpdev->ept;
ret = rpmsg_chrdev_eptdev_add(eptdev, chinfo);
if (ret)
return ret;
/*
* The rpmsg_ept_cb uses *priv parameter to get its rpmsg_eptdev context.
* Storedit in default_ept *priv field.
* Stored it in default_ept *priv field.
*/
eptdev->default_ept->priv = eptdev;
return rpmsg_chrdev_eptdev_add(eptdev, chinfo);
return 0;
}
static void rpmsg_chrdev_remove(struct rpmsg_device *rpdev)