From: Austin via B4 Relay <devnull+austin.schlegel.arthrex.com@kernel.org>
To: Laxman Dewangan <ldewangan@nvidia.com>,
Greg Kroah-Hartman <gregkh@linuxfoundation.org>,
Jiri Slaby <jirislaby@kernel.org>,
Thierry Reding <thierry.reding@kernel.org>,
Jonathan Hunter <jonathanh@nvidia.com>
Cc: linux-kernel@vger.kernel.org, linux-serial@vger.kernel.org,
linux-tegra@vger.kernel.org,
Austin <austin.schlegel@arthrex.com>
Subject: [PATCH 2/2] serial: tegra: fix TX DMA descriptor use-after-free
Date: Thu, 01 Oct 2026 15:04:02 -0400 [thread overview]
Message-ID: <20261001-tty-linus-v1-2-ecb8576c802d@arthrex.com> (raw)
In-Reply-To: <20261001-tty-linus-v1-0-ecb8576c802d@arthrex.com>
From: Austin <austin.schlegel@arthrex.com>
tegra_uart_stop_tx() calls dmaengine_terminate_all() and then
async_tx_ack(tup->tx_dma_desc) on the descriptor that was just
terminated. With the GPC DMA driver, dmaengine_terminate_all() frees
the active descriptor immediately, so the ack call that follows
touches freed memory, the same use-after-free pattern fixed for the
RX path in tegra_uart_terminate_rx_dma() ("serial: tegra: fix RX DMA
descriptor use-after-free"). dmaengine clients must not touch a
descriptor once dmaengine_terminate_all() has returned.
Move the ack before dmaengine_terminate_all(), while the descriptor
is still owned by the driver. tegra_uart_tx_dma_complete() already
acks inside the completion callback, where the descriptor is valid,
and is unaffected.
Found by code inspection while fixing the analogous RX bug; not
reproduced on hardware, since triggering it requires stopping an
in-flight TX DMA transfer (e.g. via a modem control line or flush)
at the right moment. The RX and TX paths share the same
dmaengine_terminate_all()-then-ack structure and the same root cause.
Signed-off-by: Austin <austin.schlegel@arthrex.com>
---
drivers/tty/serial/serial-tegra.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/tty/serial/serial-tegra.c b/drivers/tty/serial/serial-tegra.c
index c9ec633e7164..0d1a2ebe2a59 100644
--- a/drivers/tty/serial/serial-tegra.c
+++ b/drivers/tty/serial/serial-tegra.c
@@ -625,9 +625,9 @@ static void tegra_uart_stop_tx(struct uart_port *u)
dmaengine_pause(tup->tx_dma_chan);
dmaengine_tx_status(tup->tx_dma_chan, tup->tx_cookie, &state);
+ async_tx_ack(tup->tx_dma_desc);
dmaengine_terminate_all(tup->tx_dma_chan);
count = tup->tx_bytes_requested - state.residue;
- async_tx_ack(tup->tx_dma_desc);
uart_xmit_advance(&tup->uport, count);
tup->tx_in_progress = 0;
}
--
2.53.0
next prev parent reply other threads:[~2026-10-01 19:04 UTC|newest]
Thread overview: 7+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-10-01 19:04 [PATCH 0/2] serial: tegra: fix RX/TX " Austin via B4 Relay
2026-10-01 19:04 ` [PATCH 1/2] serial: tegra: fix RX " Austin via B4 Relay
2026-10-02 4:06 ` Austin Schlegel
2026-10-02 5:53 ` Greg Kroah-Hartman
2026-10-01 19:04 ` Austin via B4 Relay [this message]
2026-10-02 4:07 ` [PATCH 2/2] serial: tegra: fix TX " Austin Schlegel
2026-10-02 4:06 ` [PATCH 0/2] serial: tegra: fix RX/TX " Austin Schlegel
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20261001-tty-linus-v1-2-ecb8576c802d@arthrex.com \
--to=devnull+austin.schlegel.arthrex.com@kernel.org \
--cc=austin.schlegel@arthrex.com \
--cc=gregkh@linuxfoundation.org \
--cc=jirislaby@kernel.org \
--cc=jonathanh@nvidia.com \
--cc=ldewangan@nvidia.com \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-serial@vger.kernel.org \
--cc=linux-tegra@vger.kernel.org \
--cc=thierry.reding@kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®