Linux USB
 help / color / mirror / Atom feed
From: Heikki Krogerus <heikki.krogerus@linux.intel.com>
To: Fan Wu <fanwu01@zju.edu.cn>
Cc: Greg Kroah-Hartman <gregkh@linuxfoundation.org>,
	Johan Hovold <johan@kernel.org>,
	Pooja Katiyar <pooja.katiyar@intel.com>,
	Dmitry Baryshkov <dmitry.baryshkov@oss.qualcomm.com>,
	linux-usb@vger.kernel.org, linux-kernel@vger.kernel.org,
	stable@vger.kernel.org
Subject: Re: [PATCH] usb: typec: ucsi: ccg: Fix use-after-free of ucsi on remove
Date: Thu, 18 Jun 2026 13:36:49 +0300	[thread overview]
Message-ID: <ajPKQduMwyVn_X48@kuha> (raw)
In-Reply-To: <20260616132011.103279-1-fanwu01@zju.edu.cn>

On Tue, Jun 16, 2026 at 01:20:11PM +0000, Fan Wu wrote:
> The threaded IRQ handler ccg_irq_handler() calls ucsi_notify_common(),
> which on a connector-change event calls ucsi_connector_change() and
> schedules connector work.  In ucsi_ccg_remove(), ucsi_destroy() frees
> uc->ucsi (kfree) before free_irq() is called, so a handler invocation
> already in flight may access the freed object after ucsi_destroy().
> 
>   CPU 0 (remove)            | CPU 1 (threaded IRQ)
>     ucsi_destroy(uc->ucsi)  |   ccg_irq_handler()
>       kfree(ucsi) // FREE   |     ucsi_notify_common(uc->ucsi) // USE
> 
> Move free_irq() before ucsi_destroy() in the remove path.  It is kept
> after ucsi_unregister(): ucsi_unregister() cancels connector work whose
> handler issues GET_CONNECTOR_STATUS through ucsi_send_command_common(),
> which waits for a completion that is signalled from the IRQ handler, so
> the IRQ must stay active until that work has been cancelled.
> 
> The probe error path already orders free_irq() before ucsi_destroy().
> 
> This bug was found by static analysis.
> 
> Fixes: e32fd989ac1c ("usb: typec: ucsi: ccg: Move to the new API")
> Cc: stable@vger.kernel.org
> Signed-off-by: Fan Wu <fanwu01@zju.edu.cn>

Reviewed-by: Heikki Krogerus <heikki.krogerus@linux.intel.com>

> ---
>  drivers/usb/typec/ucsi/ucsi_ccg.c | 2 +-
>  1 file changed, 1 insertion(+), 1 deletion(-)
> 
> diff --git a/drivers/usb/typec/ucsi/ucsi_ccg.c b/drivers/usb/typec/ucsi/ucsi_ccg.c
> index d83a0051c737..c089000bd448 100644
> --- a/drivers/usb/typec/ucsi/ucsi_ccg.c
> +++ b/drivers/usb/typec/ucsi/ucsi_ccg.c
> @@ -1513,8 +1513,8 @@ static void ucsi_ccg_remove(struct i2c_client *client)
>  	cancel_work_sync(&uc->work);
>  	pm_runtime_disable(uc->dev);
>  	ucsi_unregister(uc->ucsi);
> -	ucsi_destroy(uc->ucsi);
>  	free_irq(uc->irq, uc);
> +	ucsi_destroy(uc->ucsi);
>  }
> 
>  static const struct of_device_id ucsi_ccg_of_match_table[] = {
> --
> 2.45.2

-- 
heikki

      reply	other threads:[~2026-06-18 10:36 UTC|newest]

Thread overview: 2+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-06-16 13:20 [PATCH] usb: typec: ucsi: ccg: Fix use-after-free of ucsi on remove Fan Wu
2026-06-18 10:36 ` Heikki Krogerus [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=ajPKQduMwyVn_X48@kuha \
    --to=heikki.krogerus@linux.intel.com \
    --cc=dmitry.baryshkov@oss.qualcomm.com \
    --cc=fanwu01@zju.edu.cn \
    --cc=gregkh@linuxfoundation.org \
    --cc=johan@kernel.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=linux-usb@vger.kernel.org \
    --cc=pooja.katiyar@intel.com \
    --cc=stable@vger.kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox