From: Adriano Cordova <adrianox@gmail.com>
To: Ulf Hansson <ulfh@kernel.org>
Cc: Stephen Boyd <swboyd@chromium.org>,
Johan Hovold <johan@kernel.org>,
linux-mmc@vger.kernel.org, linux-kernel@vger.kernel.org,
Adriano Cordova <adrianox@gmail.com>,
stable@vger.kernel.org
Subject: [PATCH v3 1/2] mmc: vub300: fix use-after-free in vub300 teardown
Date: Wed, 9 Sep 2026 07:58:55 -0300 [thread overview]
Message-ID: <20260909105856.129733-1-adrianox@gmail.com> (raw)
The request-completion paths call the final kref_put() before
mmc_request_done(). Dropping the last reference can free the host via
vub300_delete() -> mmc_free_host(), and mmc_request_done() then reads
the freed host.
Call mmc_request_done() before the final kref_put() so the host is
still valid.
Fixes: 88095e7b473a ("mmc: Add new VUB300 USB-to-SD/SDIO/MMC driver")
Assisted-by: opencode: deepseek v4 flash
Cc: stable@vger.kernel.org
Signed-off-by: Adriano Cordova <adrianox@gmail.com>
---
Changes since v1:
- Added Assisted-by tag
Changes since v2:
- Split patch into two logical patches
- Corrected the Fixes: tag
drivers/mmc/host/vub300.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/drivers/mmc/host/vub300.c b/drivers/mmc/host/vub300.c
index 2dae474dcd06..c87c54aa0e99 100644
--- a/drivers/mmc/host/vub300.c
+++ b/drivers/mmc/host/vub300.c
@@ -1794,8 +1794,8 @@ static void vub300_cmndwork_thread(struct work_struct *work)
construct_request_response(vub300, cmd);
vub300->resp_len = 0;
mutex_unlock(&vub300->cmd_mutex);
- kref_put(&vub300->kref, vub300_delete);
mmc_request_done(vub300->mmc, req);
+ kref_put(&vub300->kref, vub300_delete);
return;
}
}
@@ -1946,8 +1946,8 @@ static void vub300_mmc_request(struct mmc_host *mmc, struct mmc_request *req)
satisfy_request_from_offloaded_data(vub300, cmd)) {
cmd->error = 0;
mutex_unlock(&vub300->cmd_mutex);
- kref_put(&vub300->kref, vub300_delete);
mmc_request_done(mmc, req);
+ kref_put(&vub300->kref, vub300_delete);
return;
} else {
vub300->cmd = cmd;
--
2.51.0
next reply other threads:[~2026-09-09 10:59 UTC|newest]
Thread overview: 2+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-09 10:58 Adriano Cordova [this message]
2026-09-09 10:58 ` [PATCH v3 2/2] mmc: core: don't dereference parent when releasing host index Adriano Cordova
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260909105856.129733-1-adrianox@gmail.com \
--to=adrianox@gmail.com \
--cc=johan@kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-mmc@vger.kernel.org \
--cc=stable@vger.kernel.org \
--cc=swboyd@chromium.org \
--cc=ulfh@kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.