mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: Jonathan Cameron <jic23@kernel.org>
To: Biren Pandya <birenpandya@gmail.com>
Cc: "David Lechner" <dlechner@baylibre.com>,
	"Nuno Sá" <nuno.sa@analog.com>,
	"Andy Shevchenko" <andy@kernel.org>,
	"Linus Walleij" <linusw@kernel.org>,
	linux-iio@vger.kernel.org, linux-kernel@vger.kernel.org,
	stable@vger.kernel.org
Subject: Re: [PATCH 1/2] iio: accel: kxsd9: fix use-after-free on remove
Date: Sun, 5 Jul 2026 01:09:51 +0100	[thread overview]
Message-ID: <20260705010951.7a2b298e@jic23-huawei> (raw)
In-Reply-To: <20260703-kxsd9-v3-proper-v1-1-e9f08af25d7e@gmail.com>

On Fri, 03 Jul 2026 22:53:22 +0530
Biren Pandya <birenpandya@gmail.com> wrote:

> The kxsd9 driver currently calls iio_triggered_buffer_cleanup() before
> iio_device_unregister() in the remove() function. This order creates a
> race condition where userspace can still access sysfs or ioctl interfaces
> while the triggered buffers are being torn down, potentially leading to
> a use-after-free.
> 
> Fix this by swapping the cleanup order. Unregister the IIO device first
> to guarantee that all userspace interfaces are destroyed and no new
> accesses can occur before cleaning up the triggered buffers.
> 
> This vulnerability was flagged by the Sashiko automated review system.
> 
> Link: https://sashiko.dev/#/patchset/20260621193036.78549-2-birenpandya@gmail.com
> Fixes: 9a9a369d6178 ("iio: accel: kxsd9: Deploy system and runtime PM")
That tag touches the pm runtime stuff just below, but nothing to do with the
bug reported here.

Should be:
Fixes: 0427a106a98a ("iio: accel: kxsd9: Add triggered buffer handling")

> Cc: stable@vger.kernel.org
> Signed-off-by: Biren Pandya <birenpandya@gmail.com>
> ---
>  drivers/iio/accel/kxsd9.c | 2 +-
>  1 file changed, 1 insertion(+), 1 deletion(-)
> 
> diff --git a/drivers/iio/accel/kxsd9.c b/drivers/iio/accel/kxsd9.c
> index 7ac885d94d7f4..27adcdd312014 100644
> --- a/drivers/iio/accel/kxsd9.c
> +++ b/drivers/iio/accel/kxsd9.c
> @@ -478,8 +478,8 @@ void kxsd9_common_remove(struct device *dev)
>  	struct iio_dev *indio_dev = dev_get_drvdata(dev);
>  	struct kxsd9_state *st = iio_priv(indio_dev);
>  
> -	iio_triggered_buffer_cleanup(indio_dev);
>  	iio_device_unregister(indio_dev);
> +	iio_triggered_buffer_cleanup(indio_dev);
>  	pm_runtime_get_sync(dev);
>  	pm_runtime_put_noidle(dev);
>  	pm_runtime_disable(dev);
> 


  reply	other threads:[~2026-07-05  0:09 UTC|newest]

Thread overview: 6+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-07-03 17:23 [PATCH 0/2] iio: accel: kxsd9: fix use-after-free and PM leaks Biren Pandya
2026-07-03 17:23 ` [PATCH 1/2] iio: accel: kxsd9: fix use-after-free on remove Biren Pandya
2026-07-05  0:09   ` Jonathan Cameron [this message]
2026-07-03 17:23 ` [PATCH 2/2] iio: accel: kxsd9: fix runtime PM leaks and unchecked returns Biren Pandya
2026-07-05  0:19   ` Jonathan Cameron
2026-07-05  0:05 ` [PATCH 0/2] iio: accel: kxsd9: fix use-after-free and PM leaks Jonathan Cameron

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260705010951.7a2b298e@jic23-huawei \
    --to=jic23@kernel.org \
    --cc=andy@kernel.org \
    --cc=birenpandya@gmail.com \
    --cc=dlechner@baylibre.com \
    --cc=linusw@kernel.org \
    --cc=linux-iio@vger.kernel.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=nuno.sa@analog.com \
    --cc=stable@vger.kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®