From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-pf1-f169.google.com (mail-pf1-f169.google.com [209.85.210.169]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 3EE5D384CDE for ; Sat, 11 Jul 2026 09:21:42 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.210.169 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1783761706; cv=none; b=uz4fgn40ex1pPox5BvyBGQ/VRuKj2ZbvCSOTotP6LdHExpCTUIE8WmzoNSw6iuC66UHWxj/7yhsFKfA1JLip6wYs+kFikbDlpMKRi45iczNzyZyPr5VLYotN7gyfCM1lRsRg+SX0IV2DChpkrIF/U6ogJU0uN3Y5igoLu8QVgWo= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1783761706; c=relaxed/simple; bh=D3DyRDfYmIf0cQl/XuSThu6cyET5FQRA2JO6N/D7FYI=; h=From:To:Cc:Subject:Date:Message-Id:In-Reply-To:References: MIME-Version; b=bsnm8sl0eCXkeXMglS3AJ3VW6PteGpxL/X7UBoC6Zm6QSdBOu7+sA4TajMwjuv7AqIxLBH80stioJv3ToBUt5CKbNbYM2ItyTg1RTLBbobQGLCj9peQqTmDVMpNdtvbwRY0mUh9UidWF8kORRId/QbyZM3E+2ph3eMznebrASXw= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=fail (p=none dis=none) header.from=debian.org; spf=pass smtp.mailfrom=gmail.com; arc=none smtp.client-ip=209.85.210.169 Authentication-Results: smtp.subspace.kernel.org; dmarc=fail (p=none dis=none) header.from=debian.org Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Received: by mail-pf1-f169.google.com with SMTP id d2e1a72fcca58-845c92bc464so1494674b3a.2 for ; Sat, 11 Jul 2026 02:21:42 -0700 (PDT) X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1783761701; x=1784366501; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=AOzFhkvMsPSUSjbI9YVx5lNGMOZCWdcLEVik8BT/Ayc=; b=EFefrFgJ7xVV0oRRfoeTAi8YBLa31MONj+aychpopsyGp3o9hL31r/dcGSGw+eif93 1Hj89MJgS8CB0/x4k6j99y7bnGc3UE4thBwbl7EZcYtsPMyHmDPcIuMltmntIsW4XQ8L 2wv5TIg4hgbBjfBLM1MHW3BgDNjT45Ahe23HGAKHwaYsY119lBZT1u2Ie2rjmj4GBu0e r9CCLM9DaDXgky+5Nmsu9i3+JrWd0pHGEKiBlI7mqijHU8fgzW5TMNjybApyXRM8C16w kuc2DAUK9Tx+uMIqut8h9g8b43Q4FEef9r9jwGusLZ5fbL5nEhSbqowaBDIiPk1B8Hf7 rsaw== X-Forwarded-Encrypted: i=1; AHgh+RpQL8ZlbpeKI6YaRC2j8Nr4XkwpTNV1mpg/KI4KfQddPJNnWEemXA8X/WRqLk+8XCUDUzeU82UIMhL+EpQ=@vger.kernel.org X-Gm-Message-State: AOJu0YzeUsU9LGrpbOa6K6HFma351QEmbIypCIbG0IAsrFC4MA18U2It UTrSACKMY35VuVfXX7ujzEz/bjDRgWCtKq/PTHsjKcxLsAEtbRkFogU= X-Gm-Gg: AfdE7cnhM4uofXMgB7M3vvB9xQRRScdyYaJr2nGnJHL2FS5Copoa5KszZt4pzgH8RUS 1uTvnXxDOua+zW5VceFbatA2DnDhPLEBqoZbkeZgAaMCILpjSd8hGpe3aGEoOCUPSFrW/vi/2kH agucFyVl8UtT6Z6tWq+9BUcTqF/Bc2Voq/pdoZiWW2KTYCZIVx46A9GjWkZlbOm4u8JMtxMVD5E OpXACq2F5Mjt9e+xLqDLW0hrQJH47GevCU5ZRr2AUmaisORL8CMLptMqyFTlH7SPLXEbFlNUvEr UXxtlHpGFnUcAb27t/Rdbx9N+Hl4n1/HUHmI3ywpKe/aSYygUIH86BE6tPPizvHIeC10UgVmZjm ksStpjnx9Kas7NKf7qM7lX4Seouyh3jnh1DH+Ng2u6Lxl9qdG9NoZry3EGP5TBst72ILs+n0P1u Et/jWuDAC5oCn0oHaqxvOqCX0Fl8T0bkX01DyYbcgKAuFfVmHwluHQGXRVkACbBwLIXJRWna1iv E2zrYsocAofcay+tBbXjR+lAg== X-Received: by 2002:a05:6a00:2303:b0:848:2f74:1d68 with SMTP id d2e1a72fcca58-84889750a60mr2313588b3a.78.1783761700389; Sat, 11 Jul 2026 02:21:40 -0700 (PDT) Received: from penguin.tail0a1999.ts.net (61-228-52-13.dynamic-ip.hinet.net. [61.228.52.13]) by smtp.gmail.com with ESMTPSA id d2e1a72fcca58-847f6dbfd41sm11468726b3a.57.2026.07.11.02.21.38 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sat, 11 Jul 2026 02:21:39 -0700 (PDT) From: Shih-Yuan Lee To: Dmitry Torokhov Cc: linux-input@vger.kernel.org, linux-kernel@vger.kernel.org, Shih-Yuan Lee Subject: [PATCH v3 2/3] Input: applespi - cancel pending work on driver remove Date: Sat, 11 Jul 2026 17:20:53 +0800 Message-Id: <20260711092054.13818-3-fourdollars@debian.org> X-Mailer: git-send-email 2.39.5 In-Reply-To: <20260711092054.13818-1-fourdollars@debian.org> References: <20260711092054.13818-1-fourdollars@debian.org> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit During driver removal in applespi_remove(), the managed private data structure is freed by devres. However, the driver does not cancel the asynchronous work applespi->work, which registers the touchpad input device. This creates a use-after-free (UAF) vulnerability if a pending or running worker thread attempts to access the private data after the remove function returns. Fix this by explicitly calling cancel_work_sync(&applespi->work) in applespi_remove() before cleanups. Signed-off-by: Shih-Yuan Lee --- drivers/input/keyboard/applespi.c | 2 ++ 1 file changed, 2 insertions(+) diff --git a/drivers/input/keyboard/applespi.c b/drivers/input/keyboard/applespi.c index 79e5cb5001c7..fd785dba1174 100644 --- a/drivers/input/keyboard/applespi.c +++ b/drivers/input/keyboard/applespi.c @@ -1861,6 +1861,8 @@ static void applespi_remove(struct spi_device *spi) applespi_drain_reads(applespi); + cancel_work_sync(&applespi->work); + if (override_dma) spi->controller->can_dma = applespi->original_can_dma; -- 2.39.5