From: sashiko-bot@kernel.org
To: "Johan Hovold" <johan@kernel.org>
Cc: linux-serial@vger.kernel.org
Subject: Re: [PATCH] tty: fix saved termios reset race
Date: Wed, 30 Sep 2026 09:24:06 +0000 [thread overview]
Message-ID: <20260930092407.379EB1F00898@smtp.kernel.org> (raw)
In-Reply-To: <20260930091938.1715754-1-johan@kernel.org>
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
- [Critical] tty: logical AND bypasses TTY_DRIVER_RESET_SAVED_TERMIOS check
--
commit c7c5b67aff9403896b61f084f64a1630c60063f9
Author: Johan Hovold <johan@kernel.org>
tty: fix saved termios reset race
This commit adds a new flag, TTY_DRIVER_RESET_SAVED_TERMIOS, to selectively
reset termios state only for drivers that ensure the minor number is no
longer in use. This aims to prevent a use-after-free race during device
re-registration.
Link: https://lore.kernel.org/20260926184154.3017929-1-nicoyip.dev@gmail.com
> diff --git a/drivers/tty/tty_io.c b/drivers/tty/tty_io.c
> index 1c30faae9ec13..c9da7b25e3fb1 100644
> --- a/drivers/tty/tty_io.c
> +++ b/drivers/tty/tty_io.c
> @@ -3256,14 +3256,16 @@ struct device *tty_register_device_attr(struct tty_driver *driver,
> goto err_put;
>
> if (!(driver->flags & TTY_DRIVER_DYNAMIC_ALLOC)) {
> - /*
> - * Free any saved termios data so that the termios state is
> - * reset when reusing a minor number.
> - */
> - tp = driver->termios[index];
> - if (tp) {
> - driver->termios[index] = NULL;
> - kfree(tp);
> + if (driver->flags && TTY_DRIVER_RESET_SAVED_TERMIOS) {
[Severity: Critical]
Does this code use a logical AND where a bitwise AND is needed?
Since TTY_DRIVER_RESET_SAVED_TERMIOS is a non-zero constant, using && means
this condition evaluates to true for any driver with at least one flag set in
driver->flags. This appears to bypass the intended safety filter in
tty_register_device_attr() and would still apply the termios reset globally to
those drivers, leaving the use-after-free vulnerability unfixed.
> + /*
> + * Free any saved termios data so that the termios state is
> + * reset when reusing a minor number.
> + */
> + tp = driver->termios[index];
> + if (tp) {
> + driver->termios[index] = NULL;
> + kfree(tp);
> + }
> }
>
> retval = tty_cdev_add(driver, devt, index, 1);
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260930091938.1715754-1-johan@kernel.org?part=1
next prev parent reply other threads:[~2026-09-30 9:24 UTC|newest]
Thread overview: 3+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-30 9:19 [PATCH] tty: fix saved termios reset race Johan Hovold
2026-09-30 9:24 ` sashiko-bot [this message]
2026-09-30 9:28 ` Johan Hovold
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260930092407.379EB1F00898@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=johan@kernel.org \
--cc=linux-serial@vger.kernel.org \
--cc=sashiko-reviews@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox