The Linux Kernel Mailing List
 help / color / mirror / Atom feed
From: Adrian Hunter <adrian.hunter@intel.com>
To: alexandre.belloni@bootlin.com
Cc: Frank.Li@nxp.com, akhilrajeev@nvidia.com,
	mukesh.savaliya@oss.qualcomm.com, rafael@kernel.org,
	linux-i3c@lists.infradead.org, linux-kernel@vger.kernel.org,
	linux-pci@vger.kernel.org, linux-pm@vger.kernel.org
Subject: [PATCH V4 04/14] i3c: master: Fix use-after-free of master->this
Date: Thu,  6 Aug 2026 16:18:47 +0300	[thread overview]
Message-ID: <20260806131857.119830-5-adrian.hunter@intel.com> (raw)
In-Reply-To: <20260806131857.119830-1-adrian.hunter@intel.com>

sysfs attribute callbacks for the master controller device dereference
master->this.  However, master->this is freed in
i3c_master_detach_free_devs() before the master device itself is
released.

As a result, sysfs accesses can dereference a freed master->this
pointer, leading to a use-after-free.

Keep master->this alive until i3c_masterdev_release(), which is called
after the master device and its sysfs state are being torn down. Do not
free master->this as part of the normal device detach path.

On the error path in i3c_master_set_info(), reset master->this and
bus.cur_master to NULL before freeing the allocated device.

Fixes: 3a379bbcea0a ("i3c: Add core I3C infrastructure")
Cc: stable@vger.kernel.org
Signed-off-by: Adrian Hunter <adrian.hunter@intel.com>
---


Changes in V4:

	Also reset master->this and bus.cur_master to NULL on the
	i3c_master_set_info() error path before freeing the allocated
	device.  Tidied up the commit message wording.

Changes in V3:

	New patch


 drivers/i3c/master.c | 17 +++++++++++------
 1 file changed, 11 insertions(+), 6 deletions(-)

diff --git a/drivers/i3c/master.c b/drivers/i3c/master.c
index abb582645a2e..2357874bb9d6 100644
--- a/drivers/i3c/master.c
+++ b/drivers/i3c/master.c
@@ -842,6 +842,11 @@ static struct attribute *i3c_masterdev_attrs[] = {
 };
 ATTRIBUTE_GROUPS(i3c_masterdev);
 
+static void i3c_master_free_i3c_dev(struct i3c_dev_desc *dev)
+{
+	kfree(dev);
+}
+
 static void i3c_masterdev_release(struct device *dev)
 {
 	struct i3c_master_controller *master = dev_to_i3cmaster(dev);
@@ -854,6 +859,8 @@ static void i3c_masterdev_release(struct device *dev)
 	i3c_bus_cleanup(bus);
 
 	fwnode_handle_put(dev->fwnode);
+
+	i3c_master_free_i3c_dev(master->this);
 }
 
 static const struct device_type i3c_masterdev_type = {
@@ -1125,11 +1132,6 @@ static void i3c_device_release(struct device *dev)
 	kfree(i3cdev);
 }
 
-static void i3c_master_free_i3c_dev(struct i3c_dev_desc *dev)
-{
-	kfree(dev);
-}
-
 static struct i3c_dev_desc *
 i3c_master_alloc_i3c_dev(struct i3c_master_controller *master,
 			 const struct i3c_device_info *info)
@@ -2266,6 +2268,8 @@ int i3c_master_set_info(struct i3c_master_controller *master,
 	return 0;
 
 err_free_dev:
+	master->bus.cur_master = NULL;
+	master->this = NULL;
 	i3c_master_free_i3c_dev(i3cdev);
 
 	return ret;
@@ -2286,7 +2290,8 @@ static void i3c_master_detach_free_devs(struct i3c_master_controller *master)
 					i3cdev->boardinfo->init_dyn_addr,
 					I3C_ADDR_SLOT_FREE);
 
-		i3c_master_free_i3c_dev(i3cdev);
+		if (i3cdev != master->this)
+			i3c_master_free_i3c_dev(i3cdev);
 	}
 
 	list_for_each_entry_safe(i2cdev, i2ctmp, &master->bus.devs.i2c,
-- 
2.53.0


  parent reply	other threads:[~2026-08-06 13:19 UTC|newest]

Thread overview: 27+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-08-06 13:18 [PATCH V4 00/14] i3c: Support IBI-based system wakeup Adrian Hunter
2026-08-06 13:18 ` [PATCH V4 01/14] i3c: master: Fix recursive locking during device registration Adrian Hunter
2026-08-06 18:24   ` Frank Li
2026-08-06 13:18 ` [PATCH V4 02/14] i3c: Fix unlocked dereference of dev->desc in i3c_device_get_supported_xfer_mode() Adrian Hunter
2026-08-06 18:26   ` Frank Li
2026-08-06 13:18 ` [PATCH V4 03/14] i3c: master: Do not treat master device as a duplicate target Adrian Hunter
2026-08-06 13:18 ` Adrian Hunter [this message]
2026-08-06 18:30   ` [PATCH V4 04/14] i3c: master: Fix use-after-free of master->this Frank Li
2026-08-06 13:18 ` [PATCH V4 05/14] i3c: Make dev->desc locking assumptions explicit Adrian Hunter
2026-08-06 18:31   ` Frank Li
2026-08-06 13:18 ` [PATCH V4 06/14] i3c: master: Fix potential UAF in i3c_device_uevent() Adrian Hunter
2026-08-06 18:33   ` Frank Li
2026-08-06 13:18 ` [PATCH V4 07/14] i3c: master: Fix potential UAF in i3c_device_match() Adrian Hunter
2026-08-06 13:18 ` [PATCH V4 08/14] i3c: master: Support IBI-based wakeup capability Adrian Hunter
2026-08-06 18:58   ` Mukesh Savaliya
2026-08-06 13:18 ` [PATCH V4 09/14] i3c: master: Report wakeup events for IBIs Adrian Hunter
2026-08-06 18:35   ` Frank Li
2026-08-06 13:18 ` [PATCH V4 10/14] i3c: master: Add helper to query bus wakeup requirements Adrian Hunter
2026-08-06 18:46   ` Frank Li
2026-08-06 19:03   ` Mukesh Savaliya
2026-08-06 13:18 ` [PATCH V4 11/14] i3c: master: Reject IBI requests from non-IBI-capable devices Adrian Hunter
2026-08-06 13:18 ` [PATCH V4 12/14] i3c: mipi-i3c-hci-pci: Propagate I3C wakeup requirements to PCI Adrian Hunter
2026-08-06 18:42   ` Frank Li
2026-08-06 13:18 ` [PATCH V4 13/14] i3c: mipi-i3c-hci: Factor out i3c_hci_sysdev() Adrian Hunter
2026-08-06 18:44   ` Frank Li
2026-08-06 19:07   ` Mukesh Savaliya
2026-08-06 13:18 ` [PATCH V4 14/14] i3c: mipi-i3c-hci: Advertise IBI wakeup capability Adrian Hunter

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260806131857.119830-5-adrian.hunter@intel.com \
    --to=adrian.hunter@intel.com \
    --cc=Frank.Li@nxp.com \
    --cc=akhilrajeev@nvidia.com \
    --cc=alexandre.belloni@bootlin.com \
    --cc=linux-i3c@lists.infradead.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=linux-pci@vger.kernel.org \
    --cc=linux-pm@vger.kernel.org \
    --cc=mukesh.savaliya@oss.qualcomm.com \
    --cc=rafael@kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox