The Linux Kernel Mailing List
 help / color / mirror / Atom feed
* [PATCH v2] misc: mei: fix race condition between client teardown and read completion
@ 2026-08-24  2:32 nirbhayykumarr
  2026-08-24  5:05 ` gregkh
  0 siblings, 1 reply; 2+ messages in thread
From: nirbhayykumarr @ 2026-08-24  2:32 UTC (permalink / raw)
  To: alexander.usyskin@intel.com, arnd@arndb.de,
	gregkh@linuxfoundation.org
  Cc: w@1wt.eu, linux-kernel@vger.kernel.org, stable@vger.kernel.org

In mei_release(), a host client is torn down upon close(). During this
teardown sequence, mei_cl_disconnect() is invoked, which releases
dev->device_lock while waiting for the firmware response.

If an in-flight read request was previously submitted, an incoming
completion interrupt processed concurrently by the MEI interrupt
handler can add a completed callback into cl->rd_completed via
mei_cl_add_rd_completed().

Because mei_cl_flush_queues(cl, NULL) was invoked before mei_cl_unlink(cl),
an incoming completion callback can slip into cl->rd_completed after the
flush has completed but before the client is unlinked from dev->file_list.
When mei_cl_unlink() is subsequently called, the invariant check at
drivers/misc/mei/client.c:698 triggers:

  WARN_ON(!list_empty(&cl->rd_completed) ||
          !list_empty(&cl->rd_pending) ||
          !list_empty(&cl->link));

Call trace:
  WARNING: CPU: 2 PID: 5056 at drivers/misc/mei/client.c:698 mei_cl_unlink+0xaa/0x140 [mei]
  RIP: 0010:mei_cl_unlink+0xaa/0x140 [mei]
  Call Trace:
   <TASK>
   mei_release+0x202/0x270 [mei]
   __fput+0x105/0x2e0
   __x64_sys_close+0x90/0x140
   do_syscall_64+0xaa/0x660
   entry_SYSCALL_64_after_hwframe+0x77/0x7f
   </TASK>

Immediately following mei_cl_unlink(), mei_release() calls kfree(cl).
If any remaining or deferred callback references the freed client, a
use-after-free occurs.

Fix this by flushing queues after unlinking the client from dev->file_list
inside mei_cl_unlink(), preventing concurrent IRQ completions from
populating the client's completed queue during teardown.

Fixes: f35fe5f47ed0 ("mei: add a vtag map for each client")
Helped-by: Willy Tarreau <w@1wt.eu>
Helped-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Nirbhay Kumar <nirbhayykumarr@proton.me>
Cc: stable@vger.kernel.org
---
v2:
 - Removed redundant Reported-by tag.
 - Added Fixes tag tracing back to the commit that introduced the race window.
 - Added Helped-by tags to credit Willy and Greg for guidance.
 - Sent inline without attachment as requested.

 drivers/misc/mei/client.c | 2 ++
 drivers/misc/mei/main.c   | 1 -
 2 files changed, 2 insertions(+), 1 deletion(-)

diff --git a/drivers/misc/mei/client.c b/drivers/misc/mei/client.c
index 643b003..38b5792 100644
--- a/drivers/misc/mei/client.c
+++ b/drivers/misc/mei/client.c
@@ -695,6 +695,8 @@ int mei_cl_unlink(struct mei_cl *cl)
 	cl->state = MEI_FILE_UNINITIALIZED;
 	cl->writing_state = MEI_IDLE;

+	mei_cl_flush_queues(cl, NULL);
+
 	WARN_ON(!list_empty(&cl->rd_completed) ||
 		!list_empty(&cl->rd_pending) ||
 		!list_empty(&cl->link));
diff --git a/drivers/misc/mei/main.c b/drivers/misc/mei/main.c
index 4fbf0b3..9e14ab4 100644
--- a/drivers/misc/mei/main.c
+++ b/drivers/misc/mei/main.c
@@ -148,7 +148,6 @@ static int mei_release(struct inode *inode, struct file *file)
 		goto out;
 	}

-	mei_cl_flush_queues(cl, NULL);
 	cl_dbg(dev, cl, "removing\n");

 	mei_cl_unlink(cl);
-- 
2.55.0

^ permalink raw reply related	[flat|nested] 2+ messages in thread

* Re: [PATCH v2] misc: mei: fix race condition between client teardown and read completion
  2026-08-24  2:32 [PATCH v2] misc: mei: fix race condition between client teardown and read completion nirbhayykumarr
@ 2026-08-24  5:05 ` gregkh
  0 siblings, 0 replies; 2+ messages in thread
From: gregkh @ 2026-08-24  5:05 UTC (permalink / raw)
  To: nirbhayykumarr
  Cc: alexander.usyskin@intel.com, arnd@arndb.de, w@1wt.eu,
	linux-kernel@vger.kernel.org, stable@vger.kernel.org

On Mon, Aug 24, 2026 at 02:32:20AM +0000, nirbhayykumarr@proton.me wrote:
> Helped-by: Willy Tarreau <w@1wt.eu>
> Helped-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>

While kind, these are not real tags.  See the submitting-patches.rst
file in the kerneln tree for how to do this properly.

Also, you forgot the Assisted-by: tag, right?

thanks,

greg k-h

^ permalink raw reply	[flat|nested] 2+ messages in thread

end of thread, other threads:[~2026-08-24  5:05 UTC | newest]

Thread overview: 2+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-08-24  2:32 [PATCH v2] misc: mei: fix race condition between client teardown and read completion nirbhayykumarr
2026-08-24  5:05 ` gregkh

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox