mirror of
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git
synced 2026-07-22 02:17:36 -04:00
rpmsg: char: Fix use-after-free on probe error path
rpmsg_chrdev_probe() stores the newly allocated eptdev in the default
endpoint's priv pointer before calling rpmsg_chrdev_eptdev_add(). If
rpmsg_chrdev_eptdev_add() then fails, its error path frees eptdev while
the default endpoint may still dispatch callbacks with the stale priv
pointer.
Avoid publishing eptdev through the default endpoint until
rpmsg_chrdev_eptdev_add() succeeds. Messages received before the priv
pointer is published should be ignored by rpmsg_ept_cb(). Flow-control
updates can hit rpmsg_ept_flow_cb() in the same window, so make both
callbacks return success when priv is NULL.
Fixes: bc69d10665 ("rpmsg: char: Introduce the "rpmsg-raw" channel")
Signed-off-by: Yuho Choi <dbgh9129@gmail.com>
Cc: stable@vger.kernel.org
Link: https://lore.kernel.org/r/20260601183247.1962010-1-dbgh9129@gmail.com
Signed-off-by: Mathieu Poirier <mathieu.poirier@linaro.org>
This commit is contained in:
committed by
Mathieu Poirier
parent
254f49634e
commit
1ff3f528e6
@@ -104,6 +104,9 @@ static int rpmsg_ept_cb(struct rpmsg_device *rpdev, void *buf, int len,
|
||||
struct rpmsg_eptdev *eptdev = priv;
|
||||
struct sk_buff *skb;
|
||||
|
||||
if (!eptdev)
|
||||
return 0;
|
||||
|
||||
skb = alloc_skb(len, GFP_ATOMIC);
|
||||
if (!skb)
|
||||
return -ENOMEM;
|
||||
@@ -124,6 +127,9 @@ static int rpmsg_ept_flow_cb(struct rpmsg_device *rpdev, void *priv, bool enable
|
||||
{
|
||||
struct rpmsg_eptdev *eptdev = priv;
|
||||
|
||||
if (!eptdev)
|
||||
return 0;
|
||||
|
||||
eptdev->remote_flow_restricted = enable;
|
||||
eptdev->remote_flow_updated = true;
|
||||
|
||||
@@ -490,6 +496,7 @@ static int rpmsg_chrdev_probe(struct rpmsg_device *rpdev)
|
||||
struct rpmsg_channel_info chinfo;
|
||||
struct rpmsg_eptdev *eptdev;
|
||||
struct device *dev = &rpdev->dev;
|
||||
int ret;
|
||||
|
||||
memcpy(chinfo.name, rpdev->id.name, RPMSG_NAME_SIZE);
|
||||
chinfo.src = rpdev->src;
|
||||
@@ -502,13 +509,17 @@ static int rpmsg_chrdev_probe(struct rpmsg_device *rpdev)
|
||||
/* Set the default_ept to the rpmsg device endpoint */
|
||||
eptdev->default_ept = rpdev->ept;
|
||||
|
||||
ret = rpmsg_chrdev_eptdev_add(eptdev, chinfo);
|
||||
|
||||
if (ret)
|
||||
return ret;
|
||||
/*
|
||||
* The rpmsg_ept_cb uses *priv parameter to get its rpmsg_eptdev context.
|
||||
* Storedit in default_ept *priv field.
|
||||
* Stored it in default_ept *priv field.
|
||||
*/
|
||||
eptdev->default_ept->priv = eptdev;
|
||||
|
||||
return rpmsg_chrdev_eptdev_add(eptdev, chinfo);
|
||||
return 0;
|
||||
}
|
||||
|
||||
static void rpmsg_chrdev_remove(struct rpmsg_device *rpdev)
|
||||
|
||||
Reference in New Issue
Block a user