Linux Serial subsystem development
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Johan Hovold" <johan@kernel.org>
Cc: linux-serial@vger.kernel.org
Subject: Re: [PATCH] tty: fix saved termios reset race
Date: Wed, 30 Sep 2026 09:24:06 +0000	[thread overview]
Message-ID: <20260930092407.379EB1F00898@smtp.kernel.org> (raw)
In-Reply-To: <20260930091938.1715754-1-johan@kernel.org>

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [Critical] tty: logical AND bypasses TTY_DRIVER_RESET_SAVED_TERMIOS check
--

commit c7c5b67aff9403896b61f084f64a1630c60063f9
Author: Johan Hovold <johan@kernel.org>

tty: fix saved termios reset race

This commit adds a new flag, TTY_DRIVER_RESET_SAVED_TERMIOS, to selectively
reset termios state only for drivers that ensure the minor number is no
longer in use. This aims to prevent a use-after-free race during device
re-registration.

Link: https://lore.kernel.org/20260926184154.3017929-1-nicoyip.dev@gmail.com

> diff --git a/drivers/tty/tty_io.c b/drivers/tty/tty_io.c
> index 1c30faae9ec13..c9da7b25e3fb1 100644
> --- a/drivers/tty/tty_io.c
> +++ b/drivers/tty/tty_io.c
> @@ -3256,14 +3256,16 @@ struct device *tty_register_device_attr(struct tty_driver *driver,
>  		goto err_put;
>  
>  	if (!(driver->flags & TTY_DRIVER_DYNAMIC_ALLOC)) {
> -		/*
> -		 * Free any saved termios data so that the termios state is
> -		 * reset when reusing a minor number.
> -		 */
> -		tp = driver->termios[index];
> -		if (tp) {
> -			driver->termios[index] = NULL;
> -			kfree(tp);
> +		if (driver->flags && TTY_DRIVER_RESET_SAVED_TERMIOS) {

[Severity: Critical]
Does this code use a logical AND where a bitwise AND is needed?

Since TTY_DRIVER_RESET_SAVED_TERMIOS is a non-zero constant, using && means
this condition evaluates to true for any driver with at least one flag set in
driver->flags. This appears to bypass the intended safety filter in
tty_register_device_attr() and would still apply the termios reset globally to
those drivers, leaving the use-after-free vulnerability unfixed.

> +			/*
> +			 * Free any saved termios data so that the termios state is
> +			 * reset when reusing a minor number.
> +			 */
> +			tp = driver->termios[index];
> +			if (tp) {
> +				driver->termios[index] = NULL;
> +				kfree(tp);
> +			}
>  		}
>  
>  		retval = tty_cdev_add(driver, devt, index, 1);

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260930091938.1715754-1-johan@kernel.org?part=1

  reply	other threads:[~2026-09-30  9:24 UTC|newest]

Thread overview: 3+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-30  9:19 [PATCH] tty: fix saved termios reset race Johan Hovold
2026-09-30  9:24 ` sashiko-bot [this message]
2026-09-30  9:28 ` Johan Hovold

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260930092407.379EB1F00898@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=johan@kernel.org \
    --cc=linux-serial@vger.kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox