From: Rik van Riel <riel@surriel.com>
To: Sean Young <sean@mess.org>
Cc: Mauro Carvalho Chehab <mchehab@kernel.org>,
Jarod Wilson <jarod@redhat.com>,
linux-media@vger.kernel.org, linux-kernel@vger.kernel.org
Subject: [PATCH] media: redrat3: fix UAF in probe error path leaving rc device registered
Date: Sat, 8 Aug 2026 17:42:13 -0400 [thread overview]
Message-ID: <20260808174213.1d68336e@fangorn> (raw)
redrat3 stores its device name and phys path inside the main rr3
structure, and the rc device's device_name and input_phys point into
rr3. When the RC device is registered, it keeps those pointers.
KASAN: slab-use-after-free in string_nocheck lib/vsprintf.c:648
Read of size 1 at addr ffff888051fda758 by task udevd/7464
Call Trace:
string_nocheck lib/vsprintf.c:648 [inline]
string+0x216/0x2d0 lib/vsprintf.c:730
vsnprintf+0x74a/0xef0 lib/vsprintf.c:2945
vscnprintf+0x41/0x90 lib/vsprintf.c:3014
sysfs_emit+0x10e/0x180 fs/sysfs/file.c:761
input_dev_show_name+0x58/0x70 drivers/input/input.c:1282
Allocated by task 10:
redrat3_dev_probe+0x477/0x2570 drivers/media/rc/redrat3.c:1023
Freed by task 10:
redrat3_delete drivers/media/rc/redrat3.c:466 [inline]
redrat3_dev_probe+0x1bf4/0x2570 drivers/media/rc/redrat3.c:1124
Syzkaller triggers this via usb probing. It probes the RedRat3 USB
interface, which calls redrat3_dev_probe() in redrat3.c. That function
allocates rr3, then builds an rc device whose name points into rr3 via
redrat3_init_rc_dev() in redrat3.c, and registers it with
rc_register_device().
When the detector enable fails after the RC device is registered, the
probe jumps to the led_free path. That path unregisters the LED but
does not unregister the RC device before freeing rr3 via
redrat3_delete() in redrat3.c. The RC device still holds
device_name = rr3->name which is now freed.
Later udevd reads /sys/.../input device name via sysfs_emit() in
file.c, which calls input_dev_show_name() in input.c, which emits
dev->name which is the freed rr3->name.
Fix the error path to unregister and free the RC device before freeing
rr3, matching the order already used in redrat3_dev_disconnect() in
redrat3.c.
This change should be safe because the RC device is fully registered
at this point and its teardown via rc_unregister_device() is protected
by the input device mutex, and rr3 is still alive during unregister so
device_name remains valid until after unregister. No new lock ordering
is introduced.
Reported-by: syzbot+302b9b575a06733ff60c@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=302b9b575a06733ff60c
Link: https://lore.kernel.org/all/6a74a76d.ec7c9571.3ac9bb.0056.GAE@google.com/
Fixes: 2154be651b90 ("[media] redrat3: new rc-core IR transceiver device driver")
Cc: stable@vger.kernel.org
Assisted-by: Hermes:muse-spark-1.2 syzkaller
Signed-off-by: Rik van Riel <riel@surriel.com>
---
drivers/media/rc/redrat3.c | 2 ++
1 file changed, 2 insertions(+)
diff --git a/drivers/media/rc/redrat3.c b/drivers/media/rc/redrat3.c
index 3f828a564e19..ae1e01097639 100644
--- a/drivers/media/rc/redrat3.c
+++ b/drivers/media/rc/redrat3.c
@@ -1120,6 +1120,8 @@ static int redrat3_dev_probe(struct usb_interface *intf,
led_free:
led_classdev_unregister(&rr3->led);
+ rc_unregister_device(rr3->rc);
+ rc_free_device(rr3->rc);
redrat_free:
redrat3_delete(rr3, rr3->udev);
--
2.55.0
next reply other threads:[~2026-08-08 21:42 UTC|newest]
Thread overview: 2+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-08 21:42 Rik van Riel [this message]
2026-08-09 0:59 ` [PATCH] media: redrat3: fix UAF in probe error path leaving rc device registered Rik van Riel
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260808174213.1d68336e@fangorn \
--to=riel@surriel.com \
--cc=jarod@redhat.com \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-media@vger.kernel.org \
--cc=mchehab@kernel.org \
--cc=sean@mess.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.