From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 065DF53A3BF; Wed, 23 Sep 2026 14:51:26 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790175087; cv=none; b=UTW+qW7pA/QkN3dVimnm9wZbzZVBr3LKIuDKRFCHxrXdez89ZIsP/SFwxdiNOqQiYuvHpfI48MOVYhd1R9l8ep5lEMbWoDcS49Ge3dFBkGh0sI8sIK92sBP3lVBZabks1rdudleKhCiLQps7W2Ca6NMhx8oyPYzsOwbYe/NJl5I= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790175087; c=relaxed/simple; bh=amEjk9uKlgVWxP5EAyPNHDxYA7v1ttB318sX+mybMOo=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=PPu/gm/ksvTyhWgNmCfEDdP2m8lW2fxK/l+jAicicp1W2ibOe3Vy0DdmeHg/lDsxkRsD+XAyTTmpX/heBvb1onto6dmh2KaKltOd9SgFGEyxu8Nc7P4UKyYbFBX7NDEWwvy6s5ywknmefp44oak9J95VbcjScVLQ/B0yNaEU7xY= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=TL/4MlzX; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="TL/4MlzX" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 479431F000FF; Wed, 23 Sep 2026 14:51:25 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxfoundation.org; s=korg; t=1790175085; bh=w6DGxcM0Uu4Iovl7ZljzBTGlqqXLLgg593AEnYQ1skQ=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=TL/4MlzXWmiH+xPSOJD4WaA1aHYCEum9/yg0u/k8oVP2EbS3yha70p0Yo8plVY3tk rKrShePPqU91E3cOFbNdsZETKmPk0yL/5JCYbdTYCKatm1QOyqG5J52OITtmFtT3ko XKeSJpn35cUxJV3nQVzNJTKf4XyVFjEqoi2IsPNI= From: Greg Kroah-Hartman To: stable@vger.kernel.org Cc: Greg Kroah-Hartman , patches@lists.linux.dev, Fan Wu , Ulf Hansson Subject: [PATCH 6.18 282/398] mmc: hsq: Fix use-after-free in retry work Date: Wed, 23 Sep 2026 16:05:56 +0200 Message-ID: <20260923140650.724685681@linuxfoundation.org> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260923140643.441954610@linuxfoundation.org> References: <20260923140643.441954610@linuxfoundation.org> User-Agent: quilt/0.69 X-stable: review X-Patchwork-Hint: ignore Precedence: bulk X-Mailing-List: patches@lists.linux.dev List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit 6.18-stable review patch. If anyone has any objections, please let me know. ------------------ From: Fan Wu commit 5d132990475f02cfa1debe03d50b479432864ebd upstream. mmc_hsq_pump_requests() queues retry_work when request_atomic() returns -EBUSY; today sdhci-sprd is the only consumer that implements request_atomic(). The work is embedded in a devm-allocated mmc_hsq, but is never cancelled during driver removal. Work still pending at unbind can therefore run after the devm allocation has been released and dereference hsq->mmc and hsq->mrq. Use devm_work_autocancel() to cancel and drain retry_work before the devm allocation is released. By the time devres cleanup begins, mmc_remove_host() has already stopped the host, so no new requests can arm the work. This issue was found by an in-house static analysis tool. Fixes: 6db96e5810e0 ("mmc: host: Introduce the request_atomic() for the host") Cc: stable@vger.kernel.org Assisted-by: Codex:gpt-5.6 Signed-off-by: Fan Wu Signed-off-by: Ulf Hansson Signed-off-by: Greg Kroah-Hartman --- drivers/mmc/host/mmc_hsq.c | 8 +++++++- 1 file changed, 7 insertions(+), 1 deletion(-) --- a/drivers/mmc/host/mmc_hsq.c +++ b/drivers/mmc/host/mmc_hsq.c @@ -7,6 +7,7 @@ * Author: Baolin Wang */ +#include #include #include #include @@ -345,6 +346,7 @@ static const struct mmc_cqe_ops mmc_hsq_ int mmc_hsq_init(struct mmc_hsq *hsq, struct mmc_host *mmc) { + int ret; int i; hsq->num_slots = HSQ_NUM_SLOTS; hsq->next_tag = HSQ_INVALID_TAG; @@ -363,7 +365,11 @@ int mmc_hsq_init(struct mmc_hsq *hsq, st for (i = 0; i < HSQ_NUM_SLOTS; i++) hsq->tag_slot[i] = HSQ_INVALID_TAG; - INIT_WORK(&hsq->retry_work, mmc_hsq_retry_handler); + ret = devm_work_autocancel(mmc_dev(mmc), &hsq->retry_work, + mmc_hsq_retry_handler); + if (ret) + return ret; + spin_lock_init(&hsq->lock); init_waitqueue_head(&hsq->wait_queue);