From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id AB6DB53162E; Wed, 23 Sep 2026 14:27:15 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790173636; cv=none; b=ew73QiJ0th6cX9Vf1PXJ6OSkpMC85g0wGsE5HojgAThx2d4yVDgxFBO8B6aY43LX53Z2Wp+JArB9Mjn5B6fqXNvdb4aGXWgic4A5Gzl0qftSh7cE1fR2jX88U+soMwQ0Es89dDELQKcKr1khvZYldrrDnkBxVOlTqhMuqgEMd/M= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790173636; c=relaxed/simple; bh=JO530mmRmAzrip5waI4LlZKVj3Tv2j0xu6wNfNEdaf4=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=J+yv8KLZKASJCcX1UX0j5BfpRnWqTBLQn+mKf0l1nKEO+zJuaV6lyoxEYZgEfMskSA/w9FBuTcpk+W9TbcRMSlr9LQFbDgsROYVnetFoNivjqcI7gHAMqIkgmJpmR3ncJJR1z+Kbsf/CupTXEXgHAKNhOcXpdQZB7k2OV14HuLk= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=nVeQPIVq; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="nVeQPIVq" Received: by smtp.kernel.org (Postfix) with ESMTPSA id E42131F000FF; Wed, 23 Sep 2026 14:27:14 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxfoundation.org; s=korg; t=1790173635; bh=HRFdua4r2nOqjc9ImfmN52Y3WAqlx8fDVGmApb9SdN4=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=nVeQPIVqhl9oNQnzSguptvQ0cbSBU5enwUk/glnvSkI+IC+8gRz1+K9Dju5le/d5H tzrjwxYGwoRbAvDH7Vnnj7hwZWu2tN+6fyAHyHqJ2KHE15LBL/pygLmI3CDP1VQFoY QNzYm24xP+1emMGbIbk1LVxopGyXIqLsvW1xRmzY= From: Greg Kroah-Hartman To: stable@vger.kernel.org Cc: Greg Kroah-Hartman , patches@lists.linux.dev, Sashiko , Alexey Klimov , Krzysztof Kozlowski , Arnd Bergmann Subject: [PATCH 7.2 309/438] soc: samsung: exynos-pmu: fix use-after-free of interrupt generator node Date: Wed, 23 Sep 2026 16:05:30 +0200 Message-ID: <20260923140652.783258176@linuxfoundation.org> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260923140644.756254324@linuxfoundation.org> References: <20260923140644.756254324@linuxfoundation.org> User-Agent: quilt/0.69 X-stable: review X-Patchwork-Hint: ignore Precedence: bulk X-Mailing-List: patches@lists.linux.dev List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit 7.2-stable review patch. If anyone has any objections, please let me know. ------------------ From: Alexey Klimov commit 4dd1999783d7d12434006289338373e49492dc96 upstream. The setup_cpuhp_and_cpuidle() parses the device tree node for the interrupt generation block via of_parse_phandle() and decrements its reference count using of_node_put() immediately after fetching the resource address. However, later the intr_gen_node pointer is passed into of_syscon_register_regmap(). Fix this by declaring intr_gen_node with __free() and removing of_node_put(). Reported-by: Sashiko Closes: https://sashiko.dev/#/patchset/20260513-exynos850-cpuhotplug-v4-0-54fec5f65362@linaro.org?part=3 Fixes: 78b72897a5c8 ("soc: samsung: exynos-pmu: Enable CPU Idle for gs101") Cc: stable@vger.kernel.org Signed-off-by: Alexey Klimov Link: https://patch.msgid.link/20260828-exynos-pmu-cpuhp-idle-fixes-v2-1-06bce6107bd6@linaro.org Signed-off-by: Krzysztof Kozlowski Link: https://lore.kernel.org/r/20260917081641.72291-2-krzk@kernel.org Signed-off-by: Arnd Bergmann Signed-off-by: Greg Kroah-Hartman --- drivers/soc/samsung/exynos-pmu.c | 7 ++----- 1 file changed, 2 insertions(+), 5 deletions(-) --- a/drivers/soc/samsung/exynos-pmu.c +++ b/drivers/soc/samsung/exynos-pmu.c @@ -409,13 +409,12 @@ static struct notifier_block exynos_cpup static int setup_cpuhp_and_cpuidle(struct device *dev) { - struct device_node *intr_gen_node; + struct device_node *intr_gen_node __free(device_node) = + of_parse_phandle(dev->of_node, "google,pmu-intr-gen-syscon", 0); struct resource intrgen_res; void __iomem *virt_addr; int ret, cpu; - intr_gen_node = of_parse_phandle(dev->of_node, - "google,pmu-intr-gen-syscon", 0); if (!intr_gen_node) { /* * To maintain support for older DTs that didn't specify syscon @@ -431,8 +430,6 @@ static int setup_cpuhp_and_cpuidle(struc * syscon provided regmap. */ ret = of_address_to_resource(intr_gen_node, 0, &intrgen_res); - of_node_put(intr_gen_node); - virt_addr = devm_ioremap(dev, intrgen_res.start, resource_size(&intrgen_res)); if (!virt_addr)