From: Austin via B4 Relay <devnull+austin.schlegel.arthrex.com@kernel.org>
To: Laxman Dewangan <ldewangan@nvidia.com>,
Greg Kroah-Hartman <gregkh@linuxfoundation.org>,
Jiri Slaby <jirislaby@kernel.org>,
Thierry Reding <thierry.reding@kernel.org>,
Jonathan Hunter <jonathanh@nvidia.com>
Cc: linux-kernel@vger.kernel.org, linux-serial@vger.kernel.org,
linux-tegra@vger.kernel.org,
Austin <austin.schlegel@arthrex.com>
Subject: [PATCH 1/2] serial: tegra: fix RX DMA descriptor use-after-free
Date: Thu, 01 Oct 2026 15:04:01 -0400 [thread overview]
Message-ID: <20261001-tty-linus-v1-1-ecb8576c802d@arthrex.com> (raw)
In-Reply-To: <20261001-tty-linus-v1-0-ecb8576c802d@arthrex.com>
From: Austin <austin.schlegel@arthrex.com>
tegra_uart_terminate_rx_dma() calls dmaengine_terminate_all() and then
tegra_uart_rx_buffer_push(), which calls async_tx_ack(tup->rx_dma_desc)
on the just-terminated descriptor. With the GPC DMA driver,
dmaengine_terminate_all() frees the active descriptor immediately, so
the subsequent async_tx_ack() touches freed memory. dmaengine clients
are not allowed to touch a descriptor once it has been terminated.
The same freed-descriptor access happens via tegra_uart_rx_dma_complete(),
which also reaches tegra_uart_rx_buffer_push() after RX has stopped.
Move the ack into the two call sites that still own a live descriptor:
tegra_uart_rx_dma_complete() (before the completion callback hands the
descriptor back) and tegra_uart_terminate_rx_dma() (before terminating),
and drop it from tegra_uart_rx_buffer_push() itself, since that function
no longer has a descriptor it's safe to ack.
The ack was originally added in commit b31245b94207 ("serial: tegra:
ack the rx dma desc after transfer terminated") to avoid a descriptor
leak with the Tegra20 APB DMA driver. Keep that fix intact: the ack
still happens for every terminated RX transfer, just before the
descriptor is freed instead of after.
Found by inspection while chasing the KFENCE report below on a Jetson
AGX Orin (Tegra234) with UART loopback:
BUG: KFENCE: use-after-free read in tegra_uart_rx_buffer_push+0x38/0x168
tegra_uart_rx_buffer_push+0x38/0x168
tegra_uart_terminate_rx_dma+0x88/0xf8
tegra_uart_isr+0x380/0x470
allocated by task 0 on cpu 0 (~9 ms earlier):
tegra_dma_prep_slave_sg+0x134/0x3c0
tegra_uart_start_rx_dma.isra.0+0xc4/0x138
tegra_uart_isr+0x340/0x470
freed by task 0 on cpu 0:
tegra_dma_desc_free+0x1c/0x30
vchan_dma_desc_free_list+0x10c/0x160
tegra_dma_terminate_all+0x21c/0x290
tegra_uart_terminate_rx_dma+0x7c/0xf8
Soak tested on Tegra234 (Jetson AGX Orin) for 13+ hours with
kfence.sample_interval=1 and continuous UART loopback traffic: zero
KFENCE reports, tx/rx byte counts in /proc/tty/driver/tegra_hsuart
remained equal throughout with no framing or break errors.
Fixes: b31245b94207 ("serial: tegra: ack the rx dma desc after transfer terminated")
Signed-off-by: Austin <austin.schlegel@arthrex.com>
---
drivers/tty/serial/serial-tegra.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/drivers/tty/serial/serial-tegra.c b/drivers/tty/serial/serial-tegra.c
index 8004fc00fb9c..c9ec633e7164 100644
--- a/drivers/tty/serial/serial-tegra.c
+++ b/drivers/tty/serial/serial-tegra.c
@@ -716,7 +716,6 @@ static void tegra_uart_rx_buffer_push(struct tegra_uart_port *tup,
struct tty_port *port = &tup->uport.state->port;
unsigned int count;
- async_tx_ack(tup->rx_dma_desc);
count = tup->rx_bytes_requested - residue;
/* If we are here, DMA is stopped */
@@ -747,6 +746,7 @@ static void tegra_uart_rx_dma_complete(void *args)
set_rts(tup, false);
tup->rx_dma_active = false;
+ async_tx_ack(tup->rx_dma_desc);
tegra_uart_rx_buffer_push(tup, 0);
tegra_uart_start_rx_dma(tup);
@@ -769,6 +769,7 @@ static void tegra_uart_terminate_rx_dma(struct tegra_uart_port *tup)
dmaengine_pause(tup->rx_dma_chan);
dmaengine_tx_status(tup->rx_dma_chan, tup->rx_cookie, &state);
+ async_tx_ack(tup->rx_dma_desc);
dmaengine_terminate_all(tup->rx_dma_chan);
tegra_uart_rx_buffer_push(tup, state.residue);
--
2.53.0
next prev parent reply other threads:[~2026-10-01 19:04 UTC|newest]
Thread overview: 7+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-10-01 19:04 [PATCH 0/2] serial: tegra: fix RX/TX " Austin via B4 Relay
2026-10-01 19:04 ` Austin via B4 Relay [this message]
2026-10-02 4:06 ` [PATCH 1/2] serial: tegra: fix RX " Austin Schlegel
2026-10-02 5:53 ` Greg Kroah-Hartman
2026-10-01 19:04 ` [PATCH 2/2] serial: tegra: fix TX " Austin via B4 Relay
2026-10-02 4:07 ` Austin Schlegel
2026-10-02 4:06 ` [PATCH 0/2] serial: tegra: fix RX/TX " Austin Schlegel
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20261001-tty-linus-v1-1-ecb8576c802d@arthrex.com \
--to=devnull+austin.schlegel.arthrex.com@kernel.org \
--cc=austin.schlegel@arthrex.com \
--cc=gregkh@linuxfoundation.org \
--cc=jirislaby@kernel.org \
--cc=jonathanh@nvidia.com \
--cc=ldewangan@nvidia.com \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-serial@vger.kernel.org \
--cc=linux-tegra@vger.kernel.org \
--cc=thierry.reding@kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®