* [PATCH v2] misc: mei: fix race condition between client teardown and read completion
@ 2026-08-24 2:32 nirbhayykumarr
2026-08-24 5:05 ` gregkh
0 siblings, 1 reply; 2+ messages in thread
From: nirbhayykumarr @ 2026-08-24 2:32 UTC (permalink / raw)
To: alexander.usyskin@intel.com, arnd@arndb.de,
gregkh@linuxfoundation.org
Cc: w@1wt.eu, linux-kernel@vger.kernel.org, stable@vger.kernel.org
In mei_release(), a host client is torn down upon close(). During this
teardown sequence, mei_cl_disconnect() is invoked, which releases
dev->device_lock while waiting for the firmware response.
If an in-flight read request was previously submitted, an incoming
completion interrupt processed concurrently by the MEI interrupt
handler can add a completed callback into cl->rd_completed via
mei_cl_add_rd_completed().
Because mei_cl_flush_queues(cl, NULL) was invoked before mei_cl_unlink(cl),
an incoming completion callback can slip into cl->rd_completed after the
flush has completed but before the client is unlinked from dev->file_list.
When mei_cl_unlink() is subsequently called, the invariant check at
drivers/misc/mei/client.c:698 triggers:
WARN_ON(!list_empty(&cl->rd_completed) ||
!list_empty(&cl->rd_pending) ||
!list_empty(&cl->link));
Call trace:
WARNING: CPU: 2 PID: 5056 at drivers/misc/mei/client.c:698 mei_cl_unlink+0xaa/0x140 [mei]
RIP: 0010:mei_cl_unlink+0xaa/0x140 [mei]
Call Trace:
<TASK>
mei_release+0x202/0x270 [mei]
__fput+0x105/0x2e0
__x64_sys_close+0x90/0x140
do_syscall_64+0xaa/0x660
entry_SYSCALL_64_after_hwframe+0x77/0x7f
</TASK>
Immediately following mei_cl_unlink(), mei_release() calls kfree(cl).
If any remaining or deferred callback references the freed client, a
use-after-free occurs.
Fix this by flushing queues after unlinking the client from dev->file_list
inside mei_cl_unlink(), preventing concurrent IRQ completions from
populating the client's completed queue during teardown.
Fixes: f35fe5f47ed0 ("mei: add a vtag map for each client")
Helped-by: Willy Tarreau <w@1wt.eu>
Helped-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Nirbhay Kumar <nirbhayykumarr@proton.me>
Cc: stable@vger.kernel.org
---
v2:
- Removed redundant Reported-by tag.
- Added Fixes tag tracing back to the commit that introduced the race window.
- Added Helped-by tags to credit Willy and Greg for guidance.
- Sent inline without attachment as requested.
drivers/misc/mei/client.c | 2 ++
drivers/misc/mei/main.c | 1 -
2 files changed, 2 insertions(+), 1 deletion(-)
diff --git a/drivers/misc/mei/client.c b/drivers/misc/mei/client.c
index 643b003..38b5792 100644
--- a/drivers/misc/mei/client.c
+++ b/drivers/misc/mei/client.c
@@ -695,6 +695,8 @@ int mei_cl_unlink(struct mei_cl *cl)
cl->state = MEI_FILE_UNINITIALIZED;
cl->writing_state = MEI_IDLE;
+ mei_cl_flush_queues(cl, NULL);
+
WARN_ON(!list_empty(&cl->rd_completed) ||
!list_empty(&cl->rd_pending) ||
!list_empty(&cl->link));
diff --git a/drivers/misc/mei/main.c b/drivers/misc/mei/main.c
index 4fbf0b3..9e14ab4 100644
--- a/drivers/misc/mei/main.c
+++ b/drivers/misc/mei/main.c
@@ -148,7 +148,6 @@ static int mei_release(struct inode *inode, struct file *file)
goto out;
}
- mei_cl_flush_queues(cl, NULL);
cl_dbg(dev, cl, "removing\n");
mei_cl_unlink(cl);
--
2.55.0
^ permalink raw reply related [flat|nested] 2+ messages in thread
* Re: [PATCH v2] misc: mei: fix race condition between client teardown and read completion
2026-08-24 2:32 [PATCH v2] misc: mei: fix race condition between client teardown and read completion nirbhayykumarr
@ 2026-08-24 5:05 ` gregkh
0 siblings, 0 replies; 2+ messages in thread
From: gregkh @ 2026-08-24 5:05 UTC (permalink / raw)
To: nirbhayykumarr
Cc: alexander.usyskin@intel.com, arnd@arndb.de, w@1wt.eu,
linux-kernel@vger.kernel.org, stable@vger.kernel.org
On Mon, Aug 24, 2026 at 02:32:20AM +0000, nirbhayykumarr@proton.me wrote:
> Helped-by: Willy Tarreau <w@1wt.eu>
> Helped-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
While kind, these are not real tags. See the submitting-patches.rst
file in the kerneln tree for how to do this properly.
Also, you forgot the Assisted-by: tag, right?
thanks,
greg k-h
^ permalink raw reply [flat|nested] 2+ messages in thread
end of thread, other threads:[~2026-08-24 5:05 UTC | newest]
Thread overview: 2+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-08-24 2:32 [PATCH v2] misc: mei: fix race condition between client teardown and read completion nirbhayykumarr
2026-08-24 5:05 ` gregkh
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox