Linux CXL
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: alucerop@amd.com
Cc: linux-cxl@vger.kernel.org
Subject: Re: [PATCH v1 2/4] cxl/region: Add region reference in memdev attach
Date: Tue, 22 Sep 2026 17:56:13 +0000	[thread overview]
Message-ID: <20260922175613.7DC7F1F00893@smtp.kernel.org> (raw)
In-Reply-To: <20260921191239.4249-3-alucerop@amd.com>

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [High] cxl: Use-After-Free of attach->cxlr when endpoint unbinds
--

commit 0680840dffb6451e74369681a082d7e4373586f8
Author: Alejandro Lucero <alucerop@amd.com>

cxl/region: Add region reference in memdev attach

Use a new field in cxl_attach_region struct for easily link it with the
region the memdev is attached to. This facilitates device links creation
where such a region is the supplier with non-PF0 physical functions wanting
to use the CXL region being the consumers.

> diff --git a/drivers/cxl/core/region.c b/drivers/cxl/core/region.c
> index 27e63e6dab7c8..78ca7ebc3e557 100644
> --- a/drivers/cxl/core/region.c
> +++ b/drivers/cxl/core/region.c
> @@ -4132,6 +4132,7 @@ int cxl_memdev_attach_region(struct cxl_memdev *cxlmd)
>  	if (rc)
>  		return rc;
>  
> +	attach->cxlr = cxlr;

[Severity: High]
Could this result in a use-after-free if the endpoint is unbound?

Looking at cxl_memdev_attach_region(), attach is dynamically allocated on the
parent PCI device (cxlds->dev), but the lifetime of cxlr is exclusively tied
to endpoint->dev via the devm action endpoint_unregister_region.

If the CXL endpoint port (endpoint->dev) driver is unbound independently of the
PCI device (e.g., via sysfs or error recovery), the devm action runs and drops
the final reference, freeing cxlr.

However, attach remains alive on the still-bound PCI device, leaving
attach->cxlr pointing to freed memory. A subsequent consumer calling
cxl_get_pf0_memdev() could then access attach->cxlr->dev and trigger a
use-after-free.

Should an additional reference to cxlr be taken here, or the pointer cleared
during endpoint teardown?

>  	attach->hpa_range = (struct range) {
>  		.start = cxlr->params.res->start,
>  		.end = cxlr->params.res->end,

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260921191239.4249-1-alucerop@amd.com?part=2

  reply	other threads:[~2026-09-22 17:56 UTC|newest]

Thread overview: 20+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-21 19:12 [PATCH v1 0/4] Type2 multipf support alucerop
2026-09-21 19:12 ` [PATCH v1 1/4] driver core: Rely on supplier driver binding at link creation alucerop
2026-09-22 17:56   ` sashiko-bot
2026-09-22 21:39   ` Maxime Chevallier
2026-09-23  8:49     ` Lucero Palau, Alejandro
2026-09-23  9:58       ` Lucero Palau, Alejandro
2026-09-24  8:59         ` Lucero Palau, Alejandro
2026-09-21 19:12 ` [PATCH v1 2/4] cxl/region: Add region reference in memdev attach alucerop
2026-09-22 17:56   ` sashiko-bot [this message]
2026-09-21 19:12 ` [PATCH v1 3/4] cxl/memdev: Add support for multi PF devices alucerop
2026-09-21 23:07   ` Dave Jiang
2026-09-22 14:07     ` Lucero Palau, Alejandro
2026-09-22 16:39       ` Dave Jiang
2026-09-22 17:56   ` sashiko-bot
2026-09-21 19:12 ` [PATCH v1 4/4] sfc: add multipf support alucerop
2026-09-22 17:56   ` sashiko-bot
2026-09-24  1:15   ` Jonathan Cameron
2026-09-25 11:16     ` Lucero Palau, Alejandro
2026-09-25 20:24       ` Jonathan Cameron
2026-09-23 20:00 ` [syzbot ci] Re: Type2 " syzbot ci

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260922175613.7DC7F1F00893@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=alucerop@amd.com \
    --cc=linux-cxl@vger.kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox