Linux USB
 help / color / mirror / Atom feed
* [PATCH] thunderbolt: Fix tunnel reference leak in tb_dp_dprx_start()
@ 2026-09-17 15:52 Wentao Liang
  2026-09-18  4:58 ` Mika Westerberg
  0 siblings, 1 reply; 2+ messages in thread
From: Wentao Liang @ 2026-09-17 15:52 UTC (permalink / raw)
  To: YehezkelShB
  Cc: andreas.noever, duoming, linux-kernel, linux-usb, westeri,
	Wentao Liang

The extra tunnel reference taken to keep the tunnel around while
tunnel->dprx_work is pending is only dropped in tb_dp_dprx_stop() when
cancel_delayed_work() reports that it canceled a pending work. For
tunnels created by tb_tunnel_discover_dp() there is no callback, so no
work is queued and that condition is never true, leaking the reference
on every activation.

Only take the reference when the delayed work is actually queued.

Fixes: 67600ccfc4f3 ("thunderbolt: Fix use-after-free in tb_dp_dprx_work")
Signed-off-by: Wentao Liang <vulab@iscas.ac.cn>
---
 drivers/thunderbolt/tunnel.c | 13 +++++++------
 1 file changed, 7 insertions(+), 6 deletions(-)

diff --git a/drivers/thunderbolt/tunnel.c b/drivers/thunderbolt/tunnel.c
index f38f7753b6e4..696a7e06d940 100644
--- a/drivers/thunderbolt/tunnel.c
+++ b/drivers/thunderbolt/tunnel.c
@@ -1078,15 +1078,16 @@ static void tb_dp_dprx_work(struct work_struct *work)
 
 static int tb_dp_dprx_start(struct tb_tunnel *tunnel)
 {
-	/*
-	 * Bump up the reference to keep the tunnel around. It will be
-	 * dropped in tb_dp_dprx_stop() once the tunnel is deactivated.
-	 */
-	tb_tunnel_get(tunnel);
-
 	tunnel->dprx_started = true;
 
 	if (tunnel->callback) {
+		/*
+		 * Bump up the reference to keep the tunnel around while
+		 * the delayed work is pending. It is dropped either in
+		 * tb_dp_dprx_stop() when the work was canceled, or by the
+		 * work itself.
+		 */
+		tb_tunnel_get(tunnel);
 		tunnel->dprx_timeout = dprx_timeout_to_ktime(dprx_timeout);
 		queue_delayed_work(tunnel->tb->wq, &tunnel->dprx_work, 0);
 		return -EINPROGRESS;
-- 
2.34.1


^ permalink raw reply related	[flat|nested] 2+ messages in thread

* Re: [PATCH] thunderbolt: Fix tunnel reference leak in tb_dp_dprx_start()
  2026-09-17 15:52 [PATCH] thunderbolt: Fix tunnel reference leak in tb_dp_dprx_start() Wentao Liang
@ 2026-09-18  4:58 ` Mika Westerberg
  0 siblings, 0 replies; 2+ messages in thread
From: Mika Westerberg @ 2026-09-18  4:58 UTC (permalink / raw)
  To: Wentao Liang
  Cc: YehezkelShB, andreas.noever, duoming, linux-kernel, linux-usb,
	westeri

Hi,

On Thu, Sep 17, 2026 at 03:52:31PM +0000, Wentao Liang wrote:
> The extra tunnel reference taken to keep the tunnel around while
> tunnel->dprx_work is pending is only dropped in tb_dp_dprx_stop() when
> cancel_delayed_work() reports that it canceled a pending work. For
> tunnels created by tb_tunnel_discover_dp() there is no callback, so no
> work is queued and that condition is never true, leaking the reference
> on every activation.

There are bunch of fixes in my fixes branch that I think real with this one
too (and they make the callback mandatory) please check if that's the case.

^ permalink raw reply	[flat|nested] 2+ messages in thread

end of thread, other threads:[~2026-09-18  4:58 UTC | newest]

Thread overview: 2+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-17 15:52 [PATCH] thunderbolt: Fix tunnel reference leak in tb_dp_dprx_start() Wentao Liang
2026-09-18  4:58 ` Mika Westerberg

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox