* [PATCH] nfc: llcp: clear device pointer on disconnect
@ 2026-09-26 21:20 Aldo Ariel Panzardo
0 siblings, 0 replies; only message in thread
From: Aldo Ariel Panzardo @ 2026-09-26 21:20 UTC (permalink / raw)
To: david, davem, edumazet, kuba, pabeni
Cc: horms, oe-linux-nfc, netdev, linux-kernel, stable,
Aldo Ariel Panzardo
nfc_llcp_recv_disc() drops the device reference via nfc_put_device()
when a connected socket receives a DISC PDU, but does not clear
llcp_sock->dev. If the socket is later reconnected, any cleanup code
that checks llcp_sock->dev will find a non-NULL pointer and attempt a
second nfc_put_device(), underflowing the device refcount.
Clear the pointer immediately after the put so that a subsequent
reconnect does not double-release the device.
Fixes: d646960f7986 ("NFC: Initial LLCP support")
Cc: stable@vger.kernel.org
Signed-off-by: Aldo Ariel Panzardo <qwe.aldo@gmail.com>
---
net/nfc/llcp_core.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/net/nfc/llcp_core.c b/net/nfc/llcp_core.c
index 74bf81700..199543c47 100644
--- a/net/nfc/llcp_core.c
+++ b/net/nfc/llcp_core.c
@@ -1220,6 +1220,7 @@ static void nfc_llcp_recv_disc(struct nfc_llcp_local *local,
if (sk->sk_state == LLCP_CONNECTED) {
nfc_put_device(local->dev);
+ llcp_sock->dev = NULL;
sk->sk_state = LLCP_CLOSED;
sk->sk_state_change(sk);
}
--
2.43.0
^ permalink raw reply related [flat|nested] only message in thread
only message in thread, other threads:[~2026-09-26 21:20 UTC | newest]
Thread overview: (only message) (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-26 21:20 [PATCH] nfc: llcp: clear device pointer on disconnect Aldo Ariel Panzardo
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox