public inbox for linux-mmc@vger.kernel.org
 help / color / mirror / Atom feed
From: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
To: Ulf Hansson <ulf.hansson@linaro.org>
Cc: linux-mmc@vger.kernel.org, linux-kernel@vger.kernel.org,
	stable <stable@kernel.org>
Subject: Re: [PATCH] mmc: moxart: fix potential use-after-free on remove path.
Date: Sun, 8 Mar 2026 19:03:52 +0100	[thread overview]
Message-ID: <2026030816-womb-recollect-bdb4@gregkh> (raw)
In-Reply-To: <CAPDyKFp=9qL2XROcTXDsv106FdoFwzziFU6YpBCB85aQ5ZFZRA@mail.gmail.com>

On Wed, Mar 04, 2026 at 05:25:25PM +0100, Ulf Hansson wrote:
> On Mon, 23 Feb 2026 at 14:48, Greg Kroah-Hartman
> <gregkh@linuxfoundation.org> wrote:
> >
> > Just like in commit bd2db32e7c3e ("moxart: fix potential use-after-free
> > on remove path"), we should wait until after we are finished writing to
> > the mmc host device before removing it, otherwise it could have been
> > already freed.
> 
> mmc_remove_host() doesn't actually free the host, but it reverses what
> mmc_add_host() did during probe.
> 
> Since the moxart driver uses devm_mmc_alloc_host() the last reference
> to the host will be dropped after ->remove() completes, leading to
> mmc_free_host() to be called for it.

Then how did commit bd2db32e7c3e ("moxart: fix potential use-after-free
on remove path") do anything?  It really wasn't needed either?  And so
the CVE related to it should be rejected?

> However, improvements can still be made in the ->remove() callback. See below.
> 
> >
> > Cc: Ulf Hansson <ulf.hansson@linaro.org>
> > Cc: stable <stable@kernel.org>
> > Assisted-by: gkh_clanker_2000
> 
> What's this?

My assorted hacks of scripts that found this issue.

> > Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
> > ---
> >  drivers/mmc/host/moxart-mmc.c | 2 +-
> >  1 file changed, 1 insertion(+), 1 deletion(-)
> >
> > diff --git a/drivers/mmc/host/moxart-mmc.c b/drivers/mmc/host/moxart-mmc.c
> > index 3dd8f232052f..256e16390ef3 100644
> > --- a/drivers/mmc/host/moxart-mmc.c
> > +++ b/drivers/mmc/host/moxart-mmc.c
> > @@ -690,12 +690,12 @@ static void moxart_remove(struct platform_device *pdev)
> >                 dma_release_channel(host->dma_chan_tx);
> >         if (!IS_ERR_OR_NULL(host->dma_chan_rx))
> >                 dma_release_channel(host->dma_chan_rx);
> > -       mmc_remove_host(mmc);
> >
> >         writel(0, host->base + REG_INTERRUPT_MASK);
> >         writel(0, host->base + REG_POWER_CONTROL);
> >         writel(readl(host->base + REG_CLOCK_CONTROL) | CLK_OFF,
> >                host->base + REG_CLOCK_CONTROL);
> > +       mmc_remove_host(mmc);
> 
> Rather than moving this to the bottom of the function, it would be
> more correct to move it to the beginning.
> 
> This way, we ensure things have been closed down properly before
> releasing the dma channels.

Ok, but I was just trying to follow the same pattern in the above
mentioned commit.  If that pattern was not actually fixing something,
then this change also doesn't do anything, so it's not needed either.

thanks,

greg k-h

  reply	other threads:[~2026-03-08 18:03 UTC|newest]

Thread overview: 7+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-02-23 13:41 [PATCH] mmc: moxart: fix potential use-after-free on remove path Greg Kroah-Hartman
2026-03-04 16:25 ` Ulf Hansson
2026-03-08 18:03   ` Greg Kroah-Hartman [this message]
2026-03-09 11:42     ` Ulf Hansson
2026-03-09 12:24       ` Greg Kroah-Hartman
2026-03-09 12:29         ` Ulf Hansson
2026-03-09 12:51           ` Greg Kroah-Hartman

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=2026030816-womb-recollect-bdb4@gregkh \
    --to=gregkh@linuxfoundation.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=linux-mmc@vger.kernel.org \
    --cc=stable@kernel.org \
    --cc=ulf.hansson@linaro.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox