From: Eli Billauer <eli.billauer@gmail.com>
To: gregkh@linuxfoundation.org
Cc: arnd@arndb.de, linux-kernel@vger.kernel.org, corbet@lwn.net,
Eli Billauer <eli.billauer@gmail.com>
Subject: [PATCH v4 2/7] char: xillybus: Remove duplicate error path code
Date: Wed, 5 Aug 2026 11:34:31 +0200 [thread overview]
Message-ID: <20260805093436.59740-3-eli.billauer@gmail.com> (raw)
In-Reply-To: <20260805093436.59740-1-eli.billauer@gmail.com>
Remove dedicated code for the error path, which is both redundant and
incorrect: It calls kref_put() before mutex_unlock(&chan->lock). As
kref_put() may result in releasing the memory containing the mutex, this
could lead to UAF.
Assisted-by: Deepseek:v4-pro Kimi:K2.6 ChatGPT:GPT-5.5 Claude:Sonnet-4.6
Assisted-by: Sashiko-0.2.5:gemini-3.1-pro-preview
Signed-off-by: Eli Billauer <eli.billauer@gmail.com>
---
Notes:
Changelog:
=========
Changes v3->v4:
-- Correct the commit description to indicate that the removed duplicate
code wasn't only redundant, but could also lead to a UAF, as pointed
out by Sashiko, and an attribution is hence added too.
Changes v2->v3:
-- Add Assisted-by tag to description
No change on v1->v2.
drivers/char/xillybus/xillyusb.c | 6 +-----
1 file changed, 1 insertion(+), 5 deletions(-)
diff --git a/drivers/char/xillybus/xillyusb.c b/drivers/char/xillybus/xillyusb.c
index 560c3568fc96..ee819e2e3f82 100644
--- a/drivers/char/xillybus/xillyusb.c
+++ b/drivers/char/xillybus/xillyusb.c
@@ -1424,16 +1424,12 @@ static int xillyusb_open(struct inode *inode, struct file *filp)
if (filp->f_mode & FMODE_WRITE)
chan->open_for_write = 0;
+unmutex_fail:
mutex_unlock(&chan->lock);
kref_put(&xdev->kref, cleanup_dev);
return rc;
-
-unmutex_fail:
- kref_put(&xdev->kref, cleanup_dev);
- mutex_unlock(&chan->lock);
- return rc;
}
static ssize_t xillyusb_read(struct file *filp, char __user *userbuf,
--
2.34.1
next prev parent reply other threads:[~2026-08-05 9:35 UTC|newest]
Thread overview: 9+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-05 9:34 [PATCH v4 0/7] char: xillybus: Harden driver and improve code quality Eli Billauer
2026-08-05 9:34 ` [PATCH v4 1/7] char: xillybus: Improve control of execution flow with mutexes Eli Billauer
2026-08-05 9:34 ` Eli Billauer [this message]
2026-08-05 9:34 ` [PATCH v4 3/7] char: xillybus: Avoid possible bandwidth inefficiency Eli Billauer
2026-08-05 9:34 ` [PATCH v4 4/7] char: xillybus: Use unsigned arithmetic for jiffies differences Eli Billauer
2026-08-05 9:34 ` [PATCH v4 5/7] char: xillybus: Integer arithmetic improvements Eli Billauer
2026-08-05 9:34 ` [PATCH v4 6/7] char: xillybus: Add defensive sanity checks Eli Billauer
2026-08-05 9:34 ` [PATCH v4 7/7] char: xillybus: Ignore and report unsolicited interrupts Eli Billauer
2026-08-05 11:03 ` [PATCH v4 0/7] char: xillybus: Harden driver and improve code quality Eli Billauer
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260805093436.59740-3-eli.billauer@gmail.com \
--to=eli.billauer@gmail.com \
--cc=arnd@arndb.de \
--cc=corbet@lwn.net \
--cc=gregkh@linuxfoundation.org \
--cc=linux-kernel@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.