From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id E6F344E7802; Wed, 30 Sep 2026 17:18:33 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790788715; cv=none; b=leqhRZ/onAECU9wdDPn6JtATt6de88W5NgkbEYBQ71hUefqbS9fhy5P0rHIqm4reUXbw4s/YMuUoYzv8R0Kp0JvE2q1OouvgC9EnEaInyKJemuCQh+RWhxMnTahMA75GFCGinJRp0AMTYeSjQn0+sh3CcolA+oqaOo33B1Zoc3M= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790788715; c=relaxed/simple; bh=c6keMD3cmLgtOqNIy1oPWEteulEjm0tWIGCgRZuZltg=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=pikrdD/nUvArI5DTgp5I3+8PAGolez2ww5vw3ZITPbtveSTEsUvv7vR9dLJ3+xB1mXIT+qj2lJpWS8eZCZpxDn/t34q5CrR0ndxqFjA4qBympBT6/C8qnrJ9pxkXPlgX4zriEzntuhb0pkOhn74QipWNGNXHeGv86U3EYLlYLzo= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=pyluHuvB; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="pyluHuvB" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 0FF6B1F000FF; Wed, 30 Sep 2026 17:18:32 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxfoundation.org; s=korg; t=1790788713; bh=AqocXljMdBegDt1MBcAqihuNxv+mj7ZKMnxuihqfix4=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=pyluHuvBoqjioU2E3gf8pM2bQ4tixoJrWRrLPI/gmKiLldGxZwphf9pfSanSfzbhF yNk/QxskcGG8Otif5bOw9Qh3bFFUr26cTSEmuhW8LQacqEqiUkTpDos11oidMpvVNU F5EaN2+4JYezX74OYERc8QcVwsTRmiAgsuiqH5sA= From: Greg Kroah-Hartman To: stable@vger.kernel.org Cc: Greg Kroah-Hartman , patches@lists.linux.dev, Fan Wu , Ulf Hansson Subject: [PATCH 6.12 223/877] mmc: hsq: Fix use-after-free in retry work Date: Wed, 30 Sep 2026 17:18:54 +0200 Message-ID: <20260930152419.540084956@linuxfoundation.org> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260930152414.738996857@linuxfoundation.org> References: <20260930152414.738996857@linuxfoundation.org> User-Agent: quilt/0.69 X-stable: review X-Patchwork-Hint: ignore Precedence: bulk X-Mailing-List: patches@lists.linux.dev List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit 6.12-stable review patch. If anyone has any objections, please let me know. ------------------ From: Fan Wu commit 5d132990475f02cfa1debe03d50b479432864ebd upstream. mmc_hsq_pump_requests() queues retry_work when request_atomic() returns -EBUSY; today sdhci-sprd is the only consumer that implements request_atomic(). The work is embedded in a devm-allocated mmc_hsq, but is never cancelled during driver removal. Work still pending at unbind can therefore run after the devm allocation has been released and dereference hsq->mmc and hsq->mrq. Use devm_work_autocancel() to cancel and drain retry_work before the devm allocation is released. By the time devres cleanup begins, mmc_remove_host() has already stopped the host, so no new requests can arm the work. This issue was found by an in-house static analysis tool. Fixes: 6db96e5810e0 ("mmc: host: Introduce the request_atomic() for the host") Cc: stable@vger.kernel.org Assisted-by: Codex:gpt-5.6 Signed-off-by: Fan Wu Signed-off-by: Ulf Hansson Signed-off-by: Greg Kroah-Hartman --- drivers/mmc/host/mmc_hsq.c | 8 +++++++- 1 file changed, 7 insertions(+), 1 deletion(-) --- a/drivers/mmc/host/mmc_hsq.c +++ b/drivers/mmc/host/mmc_hsq.c @@ -7,6 +7,7 @@ * Author: Baolin Wang */ +#include #include #include #include @@ -345,6 +346,7 @@ static const struct mmc_cqe_ops mmc_hsq_ int mmc_hsq_init(struct mmc_hsq *hsq, struct mmc_host *mmc) { + int ret; int i; hsq->num_slots = HSQ_NUM_SLOTS; hsq->next_tag = HSQ_INVALID_TAG; @@ -363,7 +365,11 @@ int mmc_hsq_init(struct mmc_hsq *hsq, st for (i = 0; i < HSQ_NUM_SLOTS; i++) hsq->tag_slot[i] = HSQ_INVALID_TAG; - INIT_WORK(&hsq->retry_work, mmc_hsq_retry_handler); + ret = devm_work_autocancel(mmc_dev(mmc), &hsq->retry_work, + mmc_hsq_retry_handler); + if (ret) + return ret; + spin_lock_init(&hsq->lock); init_waitqueue_head(&hsq->wait_queue);