From: "Peng Fan (OSS)" <peng.fan@oss.nxp.com>
To: Mark Brown <broonie@kernel.org>,
Greg Kroah-Hartman <gregkh@linuxfoundation.org>,
"Rafael J. Wysocki" <rafael@kernel.org>,
Danilo Krummrich <dakr@kernel.org>
Cc: linux-kernel@vger.kernel.org, driver-core@lists.linux.dev,
Peng Fan <peng.fan@nxp.com>
Subject: [PATCH 7/7] regmap: fix potential double-free of map->reg_defaults on cache reinit
Date: Wed, 30 Sep 2026 17:47:01 +0800 [thread overview]
Message-ID: <20260930-regmap-lock-2nd-v1-7-33a8a482f9ae@nxp.com> (raw)
In-Reply-To: <20260930-regmap-lock-2nd-v1-0-33a8a482f9ae@nxp.com>
From: Peng Fan <peng.fan@nxp.com>
regcache_exit() frees map->reg_defaults but does not NULL the pointer.
If regmap_reinit_cache() is later called with a config that has neither
reg_defaults nor num_reg_defaults_raw, regcache_init() skips both
allocation branches and leaves the stale pointer in place. Should
cache_ops->init then fail, the err_free_reg_defaults error path calls
kfree(map->reg_defaults) a second time.
NULL the pointer after freeing so the error-path kfree() is a harmless
no-op.
Assisted-by: LLM
Signed-off-by: Peng Fan <peng.fan@nxp.com>
---
drivers/base/regmap/regcache.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/drivers/base/regmap/regcache.c b/drivers/base/regmap/regcache.c
index 136d6adf3120..3b1c2f28d585 100644
--- a/drivers/base/regmap/regcache.c
+++ b/drivers/base/regmap/regcache.c
@@ -294,6 +294,7 @@ void regcache_exit(struct regmap *map)
regcache_locked_exit(map);
kfree(map->reg_defaults);
+ map->reg_defaults = NULL;
}
/**
--
2.51.0
prev parent reply other threads:[~2026-09-30 9:50 UTC|newest]
Thread overview: 8+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-30 9:46 [PATCH 0/7] regmap: cleanups for regcache and regmap init paths Peng Fan (OSS)
2026-09-30 9:46 ` [PATCH 1/7] regcache: extract locked helpers to replace open-coded lock/unlock pairs Peng Fan (OSS)
2026-09-30 9:46 ` [PATCH 2/7] regcache: extract __regcache_sync() to deduplicate sync dispatch Peng Fan (OSS)
2026-09-30 9:46 ` [PATCH 3/7] regcache: simplify control flow and reduce nesting Peng Fan (OSS)
2026-09-30 9:46 ` [PATCH 4/7] regmap: use krealloc_array() in regmap_register_patch() Peng Fan (OSS)
2026-09-30 9:46 ` [PATCH 5/7] regmap: use devm_kmemdup() for bus copies and remove free_on_exit Peng Fan (OSS)
2026-09-30 9:47 ` [PATCH 6/7] regmap: return errors directly before map allocation in __regmap_init() Peng Fan (OSS)
2026-09-30 9:47 ` Peng Fan (OSS) [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260930-regmap-lock-2nd-v1-7-33a8a482f9ae@nxp.com \
--to=peng.fan@oss.nxp.com \
--cc=broonie@kernel.org \
--cc=dakr@kernel.org \
--cc=driver-core@lists.linux.dev \
--cc=gregkh@linuxfoundation.org \
--cc=linux-kernel@vger.kernel.org \
--cc=peng.fan@nxp.com \
--cc=rafael@kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®