mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: Kamal Mostafa <kamal@canonical.com>
To: linux-kernel@vger.kernel.org, stable@vger.kernel.org,
	kernel-team@lists.ubuntu.com
Cc: Benson Leung <bleung@chromium.org>,
	Greg Kroah-Hartman <gregkh@linuxfoundation.org>,
	Kamal Mostafa <kamal@canonical.com>
Subject: [PATCH 074/104] driver core : Fix use after free of dev->parent in device_shutdown
Date: Thu, 10 Oct 2013 08:42:02 -0700	[thread overview]
Message-ID: <1381419752-29733-75-git-send-email-kamal@canonical.com> (raw)
In-Reply-To: <1381419752-29733-1-git-send-email-kamal@canonical.com>

3.8.13.11 -stable review patch.  If anyone has any objections, please let me know.

------------------

From: Benson Leung <bleung@chromium.org>

commit f123db8e9d6c84c863cb3c44d17e61995dc984fb upstream.

The put_device(dev) at the bottom of the loop of device_shutdown
may result in the dev being cleaned up. In device_create_release,
the dev is kfreed.

However, device_shutdown attempts to use the dev pointer again after
put_device by referring to dev->parent.

Copy the parent pointer instead to avoid this condition.

This bug was found on Chromium OS's chromeos-3.8, which is based on v3.8.11.
See bug report : https://code.google.com/p/chromium/issues/detail?id=297842
This can easily be reproduced when shutting down with
hidraw devices that report battery condition.
Two examples are the HP Bluetooth Mouse X4000b and the Apple Magic Mouse.
For example, with the magic mouse :
The dev in question is "hidraw0"
dev->parent is "magicmouse"

In the course of the shutdown for this device, the input event cleanup calls
a put on hidraw0, decrementing its reference count.
When we finally get to put_device(dev) in device_shutdown, kobject_cleanup
is called and device_create_release does kfree(dev).
dev->parent is no longer valid, and we may crash in
put_device(dev->parent).

This change should be applied on any kernel with this change :
d1c6c030fcec6f860d9bb6c632a3ebe62e28440b

Signed-off-by: Benson Leung <bleung@chromium.org>
Reviewed-by: Ming Lei <ming.lei@canonical.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: Kamal Mostafa <kamal@canonical.com>
---
 drivers/base/core.c | 14 +++++++-------
 1 file changed, 7 insertions(+), 7 deletions(-)

diff --git a/drivers/base/core.c b/drivers/base/core.c
index a235085..0ff9496 100644
--- a/drivers/base/core.c
+++ b/drivers/base/core.c
@@ -1825,7 +1825,7 @@ EXPORT_SYMBOL_GPL(device_move);
  */
 void device_shutdown(void)
 {
-	struct device *dev;
+	struct device *dev, *parent;
 
 	spin_lock(&devices_kset->list_lock);
 	/*
@@ -1842,7 +1842,7 @@ void device_shutdown(void)
 		 * prevent it from being freed because parent's
 		 * lock is to be held
 		 */
-		get_device(dev->parent);
+		parent = get_device(dev->parent);
 		get_device(dev);
 		/*
 		 * Make sure the device is off the kset list, in the
@@ -1852,8 +1852,8 @@ void device_shutdown(void)
 		spin_unlock(&devices_kset->list_lock);
 
 		/* hold lock to avoid race with probe/release */
-		if (dev->parent)
-			device_lock(dev->parent);
+		if (parent)
+			device_lock(parent);
 		device_lock(dev);
 
 		/* Don't allow any more runtime suspends */
@@ -1871,11 +1871,11 @@ void device_shutdown(void)
 		}
 
 		device_unlock(dev);
-		if (dev->parent)
-			device_unlock(dev->parent);
+		if (parent)
+			device_unlock(parent);
 
 		put_device(dev);
-		put_device(dev->parent);
+		put_device(parent);
 
 		spin_lock(&devices_kset->list_lock);
 	}
-- 
1.8.1.2


  parent reply	other threads:[~2013-10-10 15:47 UTC|newest]

Thread overview: 109+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2013-10-10 15:40 [ 3.8.y.z extended stable ] Linux 3.8.13.11 stable review Kamal Mostafa
2013-10-10 15:40 ` [PATCH 001/104] htb: fix sign extension bug Kamal Mostafa
2013-10-10 15:40 ` [PATCH 002/104] net: avoid to hang up on sending due to sysctl configuration overflow Kamal Mostafa
2013-10-10 15:40 ` [PATCH 003/104] net: check net.core.somaxconn sysctl values Kamal Mostafa
2013-10-10 15:40 ` [PATCH 004/104] macvlan: validate flags Kamal Mostafa
2013-10-10 15:40 ` [PATCH 005/104] neighbour: populate neigh_parms on alloc before calling ndo_neigh_setup Kamal Mostafa
2013-10-10 15:40 ` [PATCH 006/104] bonding: modify only neigh_parms owned by us Kamal Mostafa
2013-10-10 15:40 ` [PATCH 007/104] fib_trie: remove potential out of bound access Kamal Mostafa
2013-10-10 15:40 ` [PATCH 008/104] bridge: don't try to update timers in case of broken MLD queries Kamal Mostafa
2013-10-10 15:40 ` [PATCH 009/104] tcp: cubic: fix overflow error in bictcp_update() Kamal Mostafa
2013-10-10 15:40 ` [PATCH 010/104] tcp: cubic: fix bug in bictcp_acked() Kamal Mostafa
2013-10-10 15:40 ` [PATCH 011/104] ipv6: don't stop backtracking in fib6_lookup_1 if subtree does not match Kamal Mostafa
2013-10-10 15:41 ` [PATCH 012/104] 8139cp: Fix skb leak in rx_status_loop failure path Kamal Mostafa
2013-10-10 15:41 ` [PATCH 013/104] tun: signedness bug in tun_get_user() Kamal Mostafa
2013-10-10 15:41 ` [PATCH 014/104] ipv6: remove max_addresses check from ipv6_create_tempaddr Kamal Mostafa
2013-10-10 15:41 ` [PATCH 015/104] ipv6: Store Router Alert option in IP6CB directly Kamal Mostafa
2013-10-10 15:41 ` [PATCH 016/104] ipv6: drop packets with multiple fragmentation headers Kamal Mostafa
2013-10-10 15:41 ` [PATCH 017/104] tcp: set timestamps for restored skb-s Kamal Mostafa
2013-10-10 15:41 ` [PATCH 018/104] net: usb: Add HP hs2434 device to ZLP exception table Kamal Mostafa
2013-10-10 15:41 ` [PATCH 019/104] tcp: initialize rcv_tstamp for restored sockets Kamal Mostafa
2013-10-10 15:41 ` [PATCH 020/104] ipv4: sendto/hdrincl: don't use destination address found in header Kamal Mostafa
2013-10-10 15:41 ` [PATCH 021/104] tcp: tcp_make_synack() should use sock_wmalloc Kamal Mostafa
2013-10-10 15:41 ` [PATCH 022/104] tipc: set sk_err correctly when connection fails Kamal Mostafa
2013-10-10 15:41 ` [PATCH 023/104] net: bridge: convert MLDv2 Query MRC into msecs_to_jiffies for max_delay Kamal Mostafa
2013-10-10 15:41 ` [PATCH 024/104] ICMPv6: treat dest unreachable codes 5 and 6 as EACCES, not EPROTO Kamal Mostafa
2013-10-10 15:41 ` [PATCH 025/104] tg3: Don't turn off led on 5719 serdes port 0 Kamal Mostafa
2013-10-10 15:41 ` [PATCH 026/104] vhost_net: poll vhost queue after marking DMA is done Kamal Mostafa
2013-10-10 15:41 ` [PATCH 027/104] net: ipv6: tcp: fix potential use after free in tcp_v6_do_rcv Kamal Mostafa
2013-10-10 15:41 ` [PATCH 028/104] drm/radeon/si: Add support for CP DMA to CS checker for compute v2 Kamal Mostafa
2013-10-10 15:41 ` [PATCH 029/104] sfc: Fix efx_rx_buf_offset() for recycled pages Kamal Mostafa
2013-10-10 15:41 ` [PATCH 030/104] cfq: explicitly use 64bit divide operation for 64bit arguments Kamal Mostafa
2013-10-10 15:41 ` [PATCH 031/104] cpqarray: fix info leak in ida_locked_ioctl() Kamal Mostafa
2013-10-10 15:41 ` [PATCH 032/104] cciss: fix info leak in cciss_ioctl32_passthru() Kamal Mostafa
2013-10-10 15:41 ` [PATCH 033/104] drm/radeon/atom: workaround vbios bug in transmitter table on rs880 (v2) Kamal Mostafa
2013-10-10 15:41 ` [PATCH 034/104] drm/ast: fix the ast open key function Kamal Mostafa
2013-10-10 15:41 ` [PATCH 035/104] sched/fair: Fix small race where child->se.parent,cfs_rq might point to invalid ones Kamal Mostafa
2013-10-10 15:41 ` [PATCH 036/104] tg3: Expand led off fix to include 5720 Kamal Mostafa
2013-10-10 15:41 ` [PATCH 037/104] HID: provide a helper for validating hid reports Kamal Mostafa
2013-10-10 15:41 ` [PATCH 038/104] HID: zeroplus: validate output report details Kamal Mostafa
2013-10-10 15:41 ` [PATCH 039/104] HID: LG: validate HID " Kamal Mostafa
2013-10-10 15:41 ` [PATCH 040/104] HID: lenovo-tpkbd: validate " Kamal Mostafa
2013-10-10 15:41 ` [PATCH 041/104] HID: validate feature and input " Kamal Mostafa
2013-10-10 15:41 ` [PATCH 042/104] HID: logitech-dj: validate output " Kamal Mostafa
2013-10-10 15:41 ` [PATCH 043/104] HID: multitouch: validate indexes details Kamal Mostafa
2013-10-10 15:41 ` [PATCH 044/104] HID: lenovo-tpkbd: fix leak if tpkbd_probe_tp fails Kamal Mostafa
2013-10-10 15:41 ` [PATCH 045/104] drm/radeon: fix panel scaling with eDP and LVDS bridges Kamal Mostafa
2013-10-10 15:41 ` [PATCH 046/104] cifs: fix filp leak in cifs_atomic_open() Kamal Mostafa
2013-10-10 15:41 ` [PATCH 047/104] net: usb: cdc_ether: Use wwan interface for Telit modules Kamal Mostafa
2013-10-10 15:41 ` [PATCH 048/104] usb: gadget: fix a bug and a WARN_ON in dummy-hcd Kamal Mostafa
2013-10-10 15:41 ` [PATCH 049/104] drm/i915: do not update cursor in crtc mode set Kamal Mostafa
2013-10-10 15:41 ` [PATCH 050/104] drm/i915: Don't enable the cursor on a disable pipe Kamal Mostafa
2013-10-10 15:41 ` [PATCH 051/104] drm/ttm: fix the tt_populated check in ttm_tt_destroy() Kamal Mostafa
2013-10-10 15:41 ` [PATCH 052/104] PCI / ACPI / PM: Clear pme_poll for devices in D3cold on wakeup Kamal Mostafa
2013-10-10 15:41 ` [PATCH 053/104] Smack: Fix the bug smackcipso can't set CIPSO correctly Kamal Mostafa
2013-10-10 15:41 ` [PATCH 054/104] serial: pch_uart: fix tty-kref leak in dma-rx path Kamal Mostafa
2013-10-10 15:41 ` [PATCH 055/104] x86, efi: Don't map Boot Services on i386 Kamal Mostafa
2013-10-10 15:41 ` [PATCH 056/104] ALSA: compress: Fix compress device unregister Kamal Mostafa
2013-10-10 15:41 ` [PATCH 057/104] dm snapshot: workaround for a false positive lockdep warning Kamal Mostafa
2013-10-10 15:41 ` [PATCH 058/104] dm-snapshot: fix performance degradation due to small hash size Kamal Mostafa
2013-10-10 15:41 ` [PATCH 059/104] drm/radeon: Make r100_cp_ring_info() and radeon_ring_gfx() safe (v2) Kamal Mostafa
2013-10-10 15:41 ` [PATCH 060/104] ARM: 7837/3: fix Thumb-2 bug in AES assembler code Kamal Mostafa
2013-10-10 15:41 ` [PATCH 061/104] x86/reboot: Add quirk to make Dell C6100 use reboot=pci automatically Kamal Mostafa
2013-10-10 15:41 ` [PATCH 062/104] drm/radeon: disable tests/benchmarks if accel is disabled Kamal Mostafa
2013-10-10 15:41 ` [PATCH 063/104] xhci: Fix oops happening after address device timeout Kamal Mostafa
2013-10-10 15:41 ` [PATCH 064/104] xhci: Ensure a command structure points to the correct trb on the command ring Kamal Mostafa
2013-10-10 15:41 ` [PATCH 065/104] drm/i915/dp: increase i2c-over-aux retry interval on AUX DEFER Kamal Mostafa
2013-10-10 15:41 ` [PATCH 066/104] staging: vt6656: [BUG] main_usb.c oops on device_close move flag earlier Kamal Mostafa
2013-10-10 15:41 ` [PATCH 067/104] staging: vt6656: [BUG] iwctl_siwencodeext return if device not open Kamal Mostafa
2013-10-10 15:41 ` [PATCH 068/104] USB: UHCI: accept very late isochronous URBs Kamal Mostafa
2013-10-10 15:41 ` [PATCH 069/104] USB: OHCI: " Kamal Mostafa
2013-10-10 15:41 ` [PATCH 070/104] USB: fix PM config symbol in uhci-hcd, ehci-hcd, and xhci-hcd Kamal Mostafa
2013-10-10 15:41 ` [PATCH 071/104] usb/core/devio.c: Don't reject control message to endpoint with wrong direction bit Kamal Mostafa
2013-10-10 15:42 ` [PATCH 072/104] hwmon: (applesmc) Check key count before proceeding Kamal Mostafa
2013-10-10 15:42 ` [PATCH 073/104] fsl/usb: Resolve PHY_CLK_VLD instability issue for ULPI phy Kamal Mostafa
2013-10-10 15:42 ` Kamal Mostafa [this message]
2013-10-10 15:42 ` [PATCH 075/104] USB: Fix breakage in ffs_fs_mount() Kamal Mostafa
2013-10-10 15:42 ` [PATCH 076/104] usb: dwc3: pci: add support for BayTrail Kamal Mostafa
2013-10-10 15:42 ` [PATCH 077/104] usb: dwc3: add support for Merrifield Kamal Mostafa
2013-10-10 15:42 ` [PATCH 078/104] ASoC: max98095: a couple array underflows Kamal Mostafa
2013-10-10 15:42 ` [PATCH 079/104] ASoC: ab8500-codec: info leak in anc_status_control_put() Kamal Mostafa
2013-10-10 15:42 ` [PATCH 080/104] ASoC: 88pm860x: array overflow in snd_soc_put_volsw_2r_st() Kamal Mostafa
2013-10-10 15:42 ` [PATCH 081/104] Bluetooth: Add a new PID/VID 0cf3/e005 for AR3012 Kamal Mostafa
2013-10-10 15:42 ` [PATCH 082/104] Bluetooth: Fix security level for peripheral role Kamal Mostafa
2013-10-10 15:42 ` [PATCH 083/104] Bluetooth: Fix encryption key size " Kamal Mostafa
2013-10-10 15:42 ` [PATCH 084/104] Bluetooth: Add support for BCM20702A0 [0b05, 17cb] Kamal Mostafa
2013-10-10 15:42 ` [PATCH 085/104] Bluetooth: Introduce a new HCI_RFKILLED flag Kamal Mostafa
2013-10-10 15:42 ` [PATCH 086/104] rtlwifi: Align private space in rtl_priv struct Kamal Mostafa
2013-10-10 15:42 ` [PATCH 087/104] p54usb: add USB ID for Corega WLUSB2GTST USB adapter Kamal Mostafa
2013-10-10 15:42 ` [PATCH 088/104] mwifiex: fix hang issue for USB chipsets Kamal Mostafa
2013-10-10 15:42 ` [PATCH 089/104] mwifiex: fix NULL pointer dereference in usb suspend handler Kamal Mostafa
2013-10-10 15:42 ` [PATCH 090/104] fs/binfmt_elf.c: prevent a coredump with a large vm_map_count from Oopsing Kamal Mostafa
2013-10-10 15:42 ` [PATCH 091/104] nilfs2: fix issue with race condition of competition between segments for dirty blocks Kamal Mostafa
2013-10-10 15:42 ` [PATCH 092/104] mm: avoid reinserting isolated balloon pages into LRU lists Kamal Mostafa
2013-10-10 15:42 ` [PATCH 093/104] USB: serial: option: Ignore card reader interface on Huawei E1750 Kamal Mostafa
2013-10-10 15:42 ` [PATCH 094/104] gpio/omap: maintain GPIO and IRQ usage separately Kamal Mostafa
2013-10-10 15:42 ` [PATCH 095/104] gpio/omap: auto-setup a GPIO when used as an IRQ Kamal Mostafa
2013-10-10 15:42 ` [PATCH 096/104] ib_srpt: Destroy cm_id before destroying QP Kamal Mostafa
2013-10-10 15:42 ` [PATCH 097/104] powerpc: Fix parameter clobber in csum_partial_copy_generic() Kamal Mostafa
2013-10-10 15:42 ` [PATCH 098/104] powerpc: Restore registers on error exit from csum_partial_copy_generic() Kamal Mostafa
2013-10-10 15:42 ` [PATCH 099/104] powerpc/sysfs: Disable writing to PURR in guest mode Kamal Mostafa
2013-10-10 15:42 ` [PATCH 100/104] powerpc/iommu: Use GFP_KERNEL instead of GFP_ATOMIC in iommu_init_table() Kamal Mostafa
2013-10-10 15:42 ` [PATCH 101/104] powerpc/vio: Fix modalias_show return values Kamal Mostafa
2013-10-10 15:42 ` [PATCH 102/104] ib_srpt: always set response for task management Kamal Mostafa
2013-10-10 15:42 ` [PATCH 103/104] xen/hvc: allow xenboot console to be used again Kamal Mostafa
2013-10-10 15:42 ` [PATCH 104/104] net: Update the sysctl permissions handler to test effective uid/gid Kamal Mostafa
2013-10-10 17:37 ` [ 3.8.y.z extended stable ] Linux 3.8.13.11 stable review Bjorn Helgaas
2013-10-18  1:30   ` Ben Hutchings
2013-10-18 15:41     ` Bjorn Helgaas
2013-10-18 15:56       ` Luis Henriques

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=1381419752-29733-75-git-send-email-kamal@canonical.com \
    --to=kamal@canonical.com \
    --cc=bleung@chromium.org \
    --cc=gregkh@linuxfoundation.org \
    --cc=kernel-team@lists.ubuntu.com \
    --cc=linux-kernel@vger.kernel.org \
    --cc=stable@vger.kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®