From: Jeffin Philip <jeffinphilip14@gmail.com>
To: dmitry.torokhov@gmail.com
Cc: linux-input@vger.kernel.org, linux-kernel@vger.kernel.org,
Jeffin Philip <jeffinphilip14@gmail.com>,
syzbot+1e2ef9bcb29af666b2e6@syzkaller.appspotmail.com
Subject: [PATCH v2] Input: atkbd - fix UAF in atkbd_set_repeat_rate() on disconnect
Date: Fri, 28 Aug 2026 15:35:47 +0530 [thread overview]
Message-ID: <20260828100547.120553-1-jeffinphilip14@gmail.com> (raw)
Commit 0ef7a26af127 ("Input: atkbd - fix canceling event_work in disconnect")
moved cancel_delayed_work_sync() after input_unregister_device() on
the premise that events may arrive until input_unregister_device returns.
However, this created a UAF as work that may have passed the
atkbd->enabled check in atkbd_event_work() may attempt to dereference dev
which is freed in input_unregister_device(). Reverting the commit also
does not solve the issue as events may still come through and pass the
enabled check as atkbd_disable() and event_work() guard with different
locks. Fix this by closing the hardware first using serio_close()
and then unregistering to prevent work from executing after
input_unregister_device(). serio_close() closes the device preventing
work from arriving. Additionally add a check for atkbd->enabled in
atkbd_event() to prevent userspace from queuing new events after
atkbd_disable() sets atkbd->enabled to false.
Reported-by: syzbot+1e2ef9bcb29af666b2e6@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=1e2ef9bcb29af666b2e6
Fixes: 0ef7a26af127 ("Input: atkbd - fix canceling event_work in disconnect")
Signed-off-by: Jeffin Philip <jeffinphilip14@gmail.com>
---
Changelog:
- Changes in v2:
Added a check for atkbd->enabled so userspace cannot queue events after
atkbd_disable.
Link to v1: https://lore.kernel.org/all/20260828080839.116065-1-jeffinphilip14@gmail.com/T/#u
---
drivers/input/keyboard/atkbd.c | 18 +++++++++++-------
1 file changed, 11 insertions(+), 7 deletions(-)
diff --git a/drivers/input/keyboard/atkbd.c b/drivers/input/keyboard/atkbd.c
index 5736f4bc5a50..79e4cd9ee1db 100644
--- a/drivers/input/keyboard/atkbd.c
+++ b/drivers/input/keyboard/atkbd.c
@@ -672,6 +672,9 @@ static int atkbd_event(struct input_dev *dev,
if (!atkbd->write)
return -1;
+ if (!atkbd->enabled)
+ return -1;
+
switch (type) {
case EV_LED:
atkbd_schedule_event_work(atkbd, ATKBD_LED_EVENT_BIT);
@@ -963,17 +966,18 @@ static void atkbd_disconnect(struct serio *serio)
atkbd_disable(atkbd);
- input_unregister_device(atkbd->dev);
-
/*
- * Make sure we don't have a command in flight.
- * Note that since atkbd->enabled is false event work will keep
- * rescheduling itself until it gets canceled and will not try
- * accessing freed input device or serio port.
+ * close serio first so device will not get any data, which prevents
+ * atkbd_event_work from being rescheduled after cancel_delayed_work_sync
+ * returns. This ensures no work can dereference atkbd->dev after it has
+ * been freed.
*/
- cancel_delayed_work_sync(&atkbd->event_work);
serio_close(serio);
+ cancel_delayed_work_sync(&atkbd->event_work);
+
+ input_unregister_device(atkbd->dev);
+
serio_set_drvdata(serio, NULL);
kfree(atkbd);
}
--
2.55.0
next reply other threads:[~2026-08-28 10:06 UTC|newest]
Thread overview: 3+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-28 10:05 Jeffin Philip [this message]
2026-08-28 10:15 ` [PATCH v2] Input: atkbd - fix UAF in atkbd_set_repeat_rate() on disconnect sashiko-bot
2026-08-28 14:32 ` Dmitry Torokhov
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260828100547.120553-1-jeffinphilip14@gmail.com \
--to=jeffinphilip14@gmail.com \
--cc=dmitry.torokhov@gmail.com \
--cc=linux-input@vger.kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=syzbot+1e2ef9bcb29af666b2e6@syzkaller.appspotmail.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.