* [PATCH] cpuidle: coupled: Fix use-after-free on device unregister
@ 2026-05-18 6:43 Mao Weiming
2026-05-18 9:36 ` Greg KH
0 siblings, 1 reply; 2+ messages in thread
From: Mao Weiming @ 2026-05-18 6:43 UTC (permalink / raw)
To: alex.mao; +Cc: stable
From: maoweiming <alex.mao@senarytech.com>
cpuidle_coupled_unregister_device() has had its refcount check inverted
ever since the coupled idle infrastructure was introduced:
if (--coupled->refcnt)
kfree(coupled);
dev->coupled = NULL;
A struct cpuidle_coupled is shared by every CPU in a coupled set.
cpuidle_coupled_register_device() either allocates a new one with
refcnt = 1, or reuses an existing one and bumps refcnt. Therefore the
struct must only be freed when the last CPU in the set has been
unregistered, i.e. when refcnt drops to zero.
The current code does the exact opposite:
- With N >= 2 CPUs in the set, the first CPU to unregister decrements
refcnt from N to N-1, the condition becomes true, and the struct is
freed while the remaining N-1 CPUs still hold dev->coupled pointers
to it. Any subsequent dereference (e.g. from
cpuidle_coupled_cpu_set_alive() during CPU hotplug,
cpuidle_coupled_update_online_cpus(), or the coupled idle entry
path) is a use-after-free.
- When the last CPU finally unregisters, refcnt becomes 0, the
condition is false, and the struct is leaked.
Both behaviours are wrong; the UAF is reachable on platforms enabling
ARCH_NEEDS_CPU_IDLE_COUPLED (OMAP4, Tegra, MIPS CPS) via driver
unbind/unregister and CPU hotplug-driven re-registration paths.
Fix it by freeing the struct only when refcnt reaches zero, matching
the kerneldoc above the function and the symmetric increment in
cpuidle_coupled_register_device().
Fixes: 4126c0197bc8 ("cpuidle: add support for states that affect multiple cpus")
Cc: stable@vger.kernel.org
Signed-off-by: maoweiming <alex.mao@senarytech.com>
---
drivers/cpuidle/coupled.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/cpuidle/coupled.c b/drivers/cpuidle/coupled.c
index fb91a9e0e3c2..25d8a6b27a51 100644
--- a/drivers/cpuidle/coupled.c
+++ b/drivers/cpuidle/coupled.c
@@ -687,7 +687,7 @@ void cpuidle_coupled_unregister_device(struct cpuidle_device *dev)
if (cpumask_empty(&dev->coupled_cpus))
return;
- if (--coupled->refcnt)
+ if (!--coupled->refcnt)
kfree(coupled);
dev->coupled = NULL;
}
--
2.25.1
^ permalink raw reply related [flat|nested] 2+ messages in thread
end of thread, other threads:[~2026-05-18 9:37 UTC | newest]
Thread overview: 2+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-05-18 6:43 [PATCH] cpuidle: coupled: Fix use-after-free on device unregister Mao Weiming
2026-05-18 9:36 ` Greg KH
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox