Linux EDAC development
 help / color / mirror / Atom feed
From: Dinh Nguyen <dinguyen@kernel.org>
To: bp@alien8.de, tony.luck@intel.com
Cc: dinguyen@kernel.org, rounakdas2025@gmail.com,
	niravkumar.l.rabara@altera.com, linux-edac@vger.kernel.org,
	linux-kernel@vger.kernel.org, stable@vger.kernel.org
Subject: [PATCH 02/10] EDAC/altera: Fix use-after-free in error paths
Date: Mon, 27 Jul 2026 08:24:08 -0500	[thread overview]
Message-ID: <20260727132416.807230-3-dinguyen@kernel.org> (raw)
In-Reply-To: <20260727132416.807230-1-dinguyen@kernel.org>

In both altr_edac_a10_device_add() and altr_portb_setup(), the error path
freed dci before releasing the devres group. Since the managed SB/DB IRQ
handlers use altdev(dci->pvt_info) as their data, an IRQ firing between
freeing dci and unregistering the IRQs could dereference freed memory.

Release the devres group first so the managed IRQs are unregistered
before dci is freed.

Assisted-by: Cursor:claude-4.8-opus
Fixes: 911049845d70 ("EDAC, altera: Add Arria10 SD-MMC EDAC support")
Fixes: 588cb03ea208 ("EDAC, altera: Add Arria10 L2 Cache ECC handling")
Closes: https://sashiko.dev/#/patchset/20260719211238.589402-1-rosenp%40gmail.com
Cc: stable@vger.kernel.org
Signed-off-by: Dinh Nguyen <dinguyen@kernel.org>
---
 drivers/edac/altera_edac.c | 15 ++++++++++++++-
 1 file changed, 14 insertions(+), 1 deletion(-)

diff --git a/drivers/edac/altera_edac.c b/drivers/edac/altera_edac.c
index d6ca68d74f78a..34b33298cf86e 100644
--- a/drivers/edac/altera_edac.c
+++ b/drivers/edac/altera_edac.c
@@ -1625,8 +1625,13 @@ static int altr_portb_setup(struct altr_edac_device_dev *device)
 	return 0;
 
 err_release_group_1:
-	edac_device_free_ctl_info(dci);
+	/*
+	 * Release the devres group first so the managed IRQs are
+	 * unregistered before dci (which contains the IRQ handler's
+	 * data via dci->pvt_info) is freed, avoiding a use-after-free.
+	 */
 	devres_release_group(device->edac->dev, altr_portb_setup);
+	edac_device_free_ctl_info(dci);
 	edac_printk(KERN_ERR, EDAC_DEVICE,
 		    "%s:Error setting up EDAC device: %d\n", ecc_name, rc);
 	return rc;
@@ -2029,9 +2034,17 @@ static int altr_edac_a10_device_add(struct altr_arria10_edac *edac,
 	return 0;
 
 err_release_group1:
+	/*
+	 * Release the devres group first so the managed IRQs are
+	 * unregistered before dci (which contains the IRQ handler's
+	 * data via dci->pvt_info) is freed, avoiding a use-after-free.
+	 */
+	devres_release_group(edac->dev, NULL);
 	edac_device_free_ctl_info(dci);
+	goto err_print;
 err_release_group:
 	devres_release_group(edac->dev, NULL);
+err_print:
 	edac_printk(KERN_ERR, EDAC_DEVICE,
 		    "%s:Error setting up EDAC device: %d\n", ecc_name, rc);
 
-- 
2.42.0.411.g813d9a9188


  parent reply	other threads:[~2026-07-27 13:24 UTC|newest]

Thread overview: 11+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-07-27 13:24 [PATCH 00/10] EDAC/altera: Address sashiko reviews part 1 Dinh Nguyen
2026-07-27 13:24 ` [PATCH 01/10] EDAC/altera: Fix NULL of_node dereference altr_edac_device_probe() Dinh Nguyen
2026-07-27 13:24 ` Dinh Nguyen [this message]
2026-07-27 13:24 ` [PATCH 03/10] EDAC/altera: Guard against NULL match data in altr_sdram_probe() Dinh Nguyen
2026-07-27 13:24 ` [PATCH 04/10] EDAC/altera: Fix IRQ domain leak on platform_get_irq() failure Dinh Nguyen
2026-07-27 13:24 ` [PATCH 05/10] EDAC/altera: Fix code leak on dci allocation failure Dinh Nguyen
2026-07-27 13:24 ` [PATCH 06/10] EDAC/altera: Add suppress_bind_attrs so driver cannot get unbound Dinh Nguyen
2026-07-27 13:24 ` [PATCH 07/10] EDAC/altera: Drop __init from ECC setup paths for re-probe safety Dinh Nguyen
2026-07-27 13:24 ` [PATCH 08/10] EDAC/altera: Skip ECC memory init if already initialized Dinh Nguyen
2026-07-27 13:24 ` [PATCH 09/10] EDAC/altera: Detach sb_irq handler when db_irq setup fails Dinh Nguyen
2026-07-27 13:24 ` [PATCH 10/10] EDAC/altera: Fix error cleanup path in altr_edac_device_probe() Dinh Nguyen

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260727132416.807230-3-dinguyen@kernel.org \
    --to=dinguyen@kernel.org \
    --cc=bp@alien8.de \
    --cc=linux-edac@vger.kernel.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=niravkumar.l.rabara@altera.com \
    --cc=rounakdas2025@gmail.com \
    --cc=stable@vger.kernel.org \
    --cc=tony.luck@intel.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox