From: Wentao Liang <vulab@iscas.ac.cn>
To: YehezkelShB@gmail.com
Cc: andreas.noever@gmail.com, duoming@zju.edu.cn,
linux-kernel@vger.kernel.org, linux-usb@vger.kernel.org,
westeri@kernel.org, Wentao Liang <vulab@iscas.ac.cn>
Subject: [PATCH] thunderbolt: Fix tunnel reference leak in tb_dp_dprx_start()
Date: Thu, 17 Sep 2026 15:52:31 +0000 [thread overview]
Message-ID: <20260917155231.2161107-1-vulab@iscas.ac.cn> (raw)
The extra tunnel reference taken to keep the tunnel around while
tunnel->dprx_work is pending is only dropped in tb_dp_dprx_stop() when
cancel_delayed_work() reports that it canceled a pending work. For
tunnels created by tb_tunnel_discover_dp() there is no callback, so no
work is queued and that condition is never true, leaking the reference
on every activation.
Only take the reference when the delayed work is actually queued.
Fixes: 67600ccfc4f3 ("thunderbolt: Fix use-after-free in tb_dp_dprx_work")
Signed-off-by: Wentao Liang <vulab@iscas.ac.cn>
---
drivers/thunderbolt/tunnel.c | 13 +++++++------
1 file changed, 7 insertions(+), 6 deletions(-)
diff --git a/drivers/thunderbolt/tunnel.c b/drivers/thunderbolt/tunnel.c
index f38f7753b6e4..696a7e06d940 100644
--- a/drivers/thunderbolt/tunnel.c
+++ b/drivers/thunderbolt/tunnel.c
@@ -1078,15 +1078,16 @@ static void tb_dp_dprx_work(struct work_struct *work)
static int tb_dp_dprx_start(struct tb_tunnel *tunnel)
{
- /*
- * Bump up the reference to keep the tunnel around. It will be
- * dropped in tb_dp_dprx_stop() once the tunnel is deactivated.
- */
- tb_tunnel_get(tunnel);
-
tunnel->dprx_started = true;
if (tunnel->callback) {
+ /*
+ * Bump up the reference to keep the tunnel around while
+ * the delayed work is pending. It is dropped either in
+ * tb_dp_dprx_stop() when the work was canceled, or by the
+ * work itself.
+ */
+ tb_tunnel_get(tunnel);
tunnel->dprx_timeout = dprx_timeout_to_ktime(dprx_timeout);
queue_delayed_work(tunnel->tb->wq, &tunnel->dprx_work, 0);
return -EINPROGRESS;
--
2.34.1
next reply other threads:[~2026-09-17 15:52 UTC|newest]
Thread overview: 2+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-17 15:52 Wentao Liang [this message]
2026-09-18 4:58 ` [PATCH] thunderbolt: Fix tunnel reference leak in tb_dp_dprx_start() Mika Westerberg
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260917155231.2161107-1-vulab@iscas.ac.cn \
--to=vulab@iscas.ac.cn \
--cc=YehezkelShB@gmail.com \
--cc=andreas.noever@gmail.com \
--cc=duoming@zju.edu.cn \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-usb@vger.kernel.org \
--cc=westeri@kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox