All of lore.kernel.org
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Lee Jones" <lee@kernel.org>
Cc: dmitry.torokhov@gmail.com, linux-input@vger.kernel.org
Subject: Re: [PATCH 1/5] HID: wacom: Use hdev->product in wacom_setup_touch_input_capabilities
Date: Tue, 25 Aug 2026 17:19:17 +0000	[thread overview]
Message-ID: <20260825171917.9F18E1F000E9@smtp.kernel.org> (raw)
In-Reply-To: <20260825151242.576456-1-lee@kernel.org>

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:

Pre-existing issues:
- [High] Missing cleanup of workqueues and timers in the probe error path leads to a Use-After-Free vulnerability.
--

commit 84f0c894069529e6d333664a987e925e1ef88eb8
Author: Lee Jones <lee@kernel.org>

HID: wacom: Use hdev->product in wacom_setup_touch_input_capabilities

This commit simplifies wacom_setup_touch_input_capabilities() by replacing
lookups of wacom_wac->shared->touch->product with direct access to
hdev->product. It retrieves the hdev pointer using container_of() on the
provided wacom_wac.

> diff --git a/drivers/hid/wacom_wac.c b/drivers/hid/wacom_wac.c
> index a29bf051ada7c..4436faf2d2bbd 100644
> --- a/drivers/hid/wacom_wac.c
> +++ b/drivers/hid/wacom_wac.c
[ ... ]

While reviewing this patch, I noticed a pre-existing issue in
wacom_parse_and_register() located in drivers/hid/wacom_sys.c:

drivers/hid/wacom_sys.c:wacom_parse_and_register() {
    ...
	if (features->device_type & WACOM_DEVICETYPE_WL_MONITOR) {
		error = hid_hw_open(hdev);
		if (error) {
			hid_err(hdev, "hw open failed\n");
			goto fail_hw_stop;
		}
	}
    ...
fail_hw_stop:
	hid_hw_stop(hdev);
fail:
	wacom_release_resources(wacom);
	return error;
}

[Severity: High]
This isn't a regression introduced by this patch, but is a pre-existing
issue. Does this error path fail to cancel asynchronously scheduled works?

In wacom_probe(), the wacom structure is allocated via devm_kzalloc().
During wacom_parse_and_register(), hid_hw_start() is called which enables
hardware interrupts that can schedule async works (e.g., battery_work).
Additionally, wacom_query_tablet_data() explicitly schedules init_work.

If a subsequent initialization step fails (like hid_hw_open() above), the
function jumps to fail_hw_stop and returns an error without cancelling the
pending works.

Since wacom_probe() then returns this error, causing the devres cleanup to
free the wacom structure, could these pending works later execute and
access the freed memory?

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260825151242.576456-1-lee@kernel.org?part=1

  parent reply	other threads:[~2026-08-25 17:19 UTC|newest]

Thread overview: 13+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-08-25 15:12 [PATCH 1/5] HID: wacom: Use hdev->product in wacom_setup_touch_input_capabilities Lee Jones
2026-08-25 15:12 ` [PATCH 2/5] HID: wacom: Advertise SW_MUTE_DEVICE capability prior to registration Lee Jones
2026-08-25 17:25   ` sashiko-bot
2026-08-26  8:02     ` Lee Jones
2026-08-25 15:12 ` [PATCH 3/5] HID: wacom: Fix Use-After-Free in wacom_intuos_pad Lee Jones
2026-08-25 17:26   ` sashiko-bot
2026-08-25 15:12 ` [PATCH 4/5] HID: wacom: Fix Use-After-Free in wacom_bamboo_pad Lee Jones
2026-08-25 17:22   ` sashiko-bot
2026-08-25 15:12 ` [PATCH 5/5] HID: wacom: Redesign shared sibling data lifecycle Lee Jones
2026-08-25 17:19 ` sashiko-bot [this message]
2026-08-27  2:48 ` [PATCH 1/5] HID: wacom: Use hdev->product in wacom_setup_touch_input_capabilities Ping Cheng
2026-09-01 12:49   ` Lee Jones
2026-09-01 16:24     ` Ping Cheng

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260825171917.9F18E1F000E9@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=dmitry.torokhov@gmail.com \
    --cc=lee@kernel.org \
    --cc=linux-input@vger.kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.