From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-oi1-f200.google.com (mail-oi1-f200.google.com [209.85.167.200]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 1E01E305677 for ; Sat, 1 Aug 2026 01:06:49 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.167.200 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785546410; cv=none; b=cuouMM0HxuYZYf4YBlv2o7IIWnB94YVqpHaP8i2egulxuINf9o3L+269G/gfvsB5aZ2ygAj/9Z69iPs/KWK851dQO4H+Fv2qHttI+UsOG4JtFaXf5J7CiPqmTjxuwwzos2JiBWUqFHjGsHjN30/4afXbjUT4LTcNbk0rHw5pdRY= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785546410; c=relaxed/simple; bh=V+ZYBdfpKPSKJV4q6AYpY+NUJ+KfOQh9Nx3yZaIGQtQ=; h=MIME-Version:Date:In-Reply-To:Message-ID:Subject:From:To:Cc: Content-Type; b=HCcCivTILF/oZ9KPxh9qCdPhKbPD0MHbU1D1qSWKGXi8ALk5aQY+8XTbqMpTt/unCPE4PgjblLGOued+VZ6S6RloMmqpyH1oz+zaVeSJCBDrz9MDP4/1UCt9NaJl4wR/0UThezQC3XqYDUAOlDpRJRe17yRbOhHq8/SeUovYo+0= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=fail (p=none dis=none) header.from=syzkaller.appspotmail.com; spf=pass smtp.mailfrom=M3KW2WVRGUFZ5GODRSRYTGD7.apphosting.bounces.google.com; arc=none smtp.client-ip=209.85.167.200 Authentication-Results: smtp.subspace.kernel.org; dmarc=fail (p=none dis=none) header.from=syzkaller.appspotmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=M3KW2WVRGUFZ5GODRSRYTGD7.apphosting.bounces.google.com Received: by mail-oi1-f200.google.com with SMTP id 5614622812f47-495b8120909so1981010b6e.1 for ; Fri, 31 Jul 2026 18:06:48 -0700 (PDT) X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785546408; x=1786151208; h=content-type:cc:to:from:subject:message-id:in-reply-to:date :mime-version:x-gm-message-state:from:to:cc:subject:date:message-id :reply-to:content-type; bh=yzmXRaL0getkmS97wjPyTKw+5JYaanNt7AkLGsr0oSM=; b=JvVm+S4PrPx7lUEcaImkZIj2Vfu7SmjFC5B2gPowQIC6TnJkYsWBGh6wV7VcXz40Wi xdSbOHJ8WBDMlfDJbcE/YiRtw6gHd1Qpr70kjE8czC81kh0DMh4ut+OfZmd76Z36nwLm IaGCrx7M2EF3CYFYYM6zpJ4/F8PnKkbg2sN0/ZrXl28HfzNUt3TlF1+HjC3P04ReZfWv yS6wkHEYTpoZjEauq9zXnuFhbQoCKf8JX0PAT0Oa1AxxHrPYM3dieUDuf7JnxU4MqcIc R/O9duuFCvxTNel77LOop+Ji6PxRJtQ7BuxNQ6ucLSTV7I1pSs6wuekOSxpCSz7mfVqJ kejg== X-Forwarded-Encrypted: i=1; AHgh+RoO3AAEYmHqICpjCkTOigLsltCEXNkQGog6Ze7H77RBgulnGciFibANEDWOeQCJ4GvxI7njoJrAL7Sbo/c=@vger.kernel.org X-Gm-Message-State: AOJu0YyTve2ILK8c/ArSfhIaL06u9BVJK7aW++uxTgbTR6Za4tkjEFZG 2gZUOSHLPQrFUR2r6JrNKnlYipPyx8OV6lmzjgPWO4bjt4KlATOA7meGbL9JpDkgrXqt3IMl7EU r36FUcUZri6L6iQR2PDPSX5ag577qkd600lxuYqUxGXhTZN1REdF0B7SscdQ= Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 X-Received: by 2002:a05:6808:198d:b0:485:48da:133d with SMTP id 5614622812f47-4af5e29c73bmr4506838b6e.10.1785546408149; Fri, 31 Jul 2026 18:06:48 -0700 (PDT) Date: Fri, 31 Jul 2026 18:06:48 -0700 In-Reply-To: <61542DAB-21C6-4A5F-8E90-B20B6E0D38A3@grrlz.net> X-Google-Appengine-App-Id: s~syzkaller X-Google-Appengine-App-Id-Alias: syzkaller Message-ID: <6a6d46a8.2d659fcc.1d46f5.01af.GAE@google.com> Subject: Re: [syzbot] [kernel?] KASAN: slab-use-after-free Read in __release_resource From: syzbot To: include@grrlz.net Cc: include@grrlz.net, linux-kernel@vger.kernel.org, syzkaller-bugs@googlegroups.com Content-Type: text/plain; charset="UTF-8" > On 1 August 2026 02:02:24 BST, syzbot > wrote: >>> #syz test: From 9cd23575828ada0a338a2dd0019e97476c4f5d23 Mon Sep 17 >> >>I've failed to parse your command. >>Did you perhaps forget to provide the branch name, or added an extra ':'? >>Please use one of the two supported formats: >>1. #syz test >>2. #syz test: repo branch-or-commit-hash >>Note the lack of ':' in option 1. >> >>> 00:00:00 2001 >>> From: Bradley Morgan >>> Date: Sat, 1 Aug 2026 00:58:20 +0000 >>> Subject: [PATCH] driver core: platform: use remove_resource() to >>properly reparent children >>> >>> platform_device_add() inserts resources into the global iomem/ioport >>> trees via insert_resource(), which may reparent existing resources as >>> children of the newly inserted one. >>> >>> The teardown paths in platform_device_add() (error path) and >>> platform_device_del() use release_resource() to remove these >>> resources. However, release_resource() calls __release_resource() >>> with release_child=true, which simply unlinks the resource from its >>> parent's child list without reparenting its children. Any child >>> resources that were moved under it by insert_resource() are left >>> with dangling ->parent pointers. >>> >>> When the platform device's kmemdup'd resource array is subsequently >>> freed by platform_device_release(), those children (e.g. a PCI BAR >>> resource that was reparented under the platform device's resource) >>> end up with ->parent pointing to freed memory. A later >>> release_resource() on such a child dereferences the stale pointer in >>> __release_resource(), causing a slab-use-after-free. >>> >>> Fix it by using remove_resource() instead, which is the proper >>> counterpart to insert_resource(). remove_resource() calls >>> __release_resource() with release_child=false, which reparents >>> children up to the removed resource's parent before unlinking it, >>> keeping all ->parent pointers valid. >>> >>> Reported-by: syzbot+ee1062851b628d722093@syzkaller.appspotmail.com >>> Closes: >>https://lore.kernel.org/all/6a6d39e7.f794c993.27aeb.0009.GAE@google.com/ >>> Assisted-by: GLM:glm-5.2 >>> Signed-off-by: Bradley Morgan >>> --- >>> drivers/base/platform.c | 4 ++-- >>> 1 file changed, 2 insertions(+), 2 deletions(-) >>> >>> diff --git a/drivers/base/platform.c b/drivers/base/platform.c >>> index a71015f1d915..9a6932d50ee5 100644 >>> --- a/drivers/base/platform.c >>> +++ b/drivers/base/platform.c >>> @@ -830,7 +830,7 @@ int platform_device_add(struct platform_device >>*pdev) >>> while (i--) { >>> struct resource *r = &pdev->resource[i]; >>> if (r->parent) >>> - release_resource(r); >>> + remove_resource(r); >>> } >>> >>> return ret; >>> @@ -860,7 +860,7 @@ void platform_device_del(struct platform_device >>*pdev) >>> for (i = 0; i < pdev->num_resources; i++) { >>> struct resource *r = &pdev->resource[i]; >>> if (r->parent) >>> - release_resource(r); >>> + remove_resource(r); >>> } >>> } >>> } >>> -- >>> 2.47.3 >>> >>> >>> Note: AI generated. >>> Thanks! >> > > > #syz test This crash does not have a reproducer. I cannot test it. > > diff --git a/drivers/base/platform.c b/drivers/base/platform.c > --- a/drivers/base/platform.c > +++ b/drivers/base/platform.c > @@ -830,7 +830,7 @@ int platform_device_add(struct platform_device *pdev) > while (i--) { > struct resource *r = &pdev->resource[i]; > if (r->parent) > - release_resource(r); > + remove_resource(r); > } > > return ret; > @@ -860,7 +860,7 @@ void platform_device_del(struct platform_device *pdev) > for (i = 0; i < pdev->num_resources; i++) { > struct resource *r = &pdev->resource[i]; > if (r->parent) > - release_resource(r); > + remove_resource(r); > } > } > } > > > this better work. for goodness sake.... :( > > Thanks!