mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: Shubham Antil <shubham@octane.security>
To: netdev@vger.kernel.org
Cc: oe-linux-nfc@lists.linux.dev, David Heidelberg <david@ixit.cz>,
	"David S . Miller" <davem@davemloft.net>,
	Eric Dumazet <edumazet@google.com>,
	Jakub Kicinski <kuba@kernel.org>, Paolo Abeni <pabeni@redhat.com>,
	Simon Horman <horms@kernel.org>, Johan Hovold <johan@kernel.org>,
	linux-kernel@vger.kernel.org,
	Giovanni Vignone <gio@octane.security>
Subject: [PATCH v4 0/2] nfc: nci: uart: fix write_work teardown UAF (+ nfcmrvl drv_data)
Date: Tue,  6 Oct 2026 17:25:29 +0530	[thread overview]
Message-ID: <20261006115532.72100-1-shubham@octane.security> (raw)

This series fixes a use-after-free in the NFC NCI UART line-discipline
teardown and a NULL dereference in the Marvell NFC UART driver that the
same change surfaces.

nci_uart_tty_close() frees the tx skbs and purges the tx queue before it
cancels the write worker, while the NCI device is still registered.  The
worker can therefore be re-queued -- by a tty hangup, or by the NCI core
still sending through the driver -- and run against freed memory.  The
fix follows the Bluetooth hci_uart ldisc: gate the worker on a readiness
bit under a percpu_rwsem and drain it under the write lock on close.

Enabling the worker that way means it must be enabled before the device
is registered, since the Marvell driver may transmit (firmware download)
from within registration.  That exposes a pre-existing NULL dereference:
nfcmrvl publishes nu->drv_data only after nfcmrvl_nci_register_dev()
returns, so a transmit during registration reaches
nfcmrvl_nci_uart_tx_start() with a NULL nu->drv_data.

 1/2 nfcmrvl: publish nu->drv_data before nci_register_device(), so a
     transmit during registration does not hit a NULL nu->drv_data.
 2/2 nci: uart: the teardown use-after-free fix; NCI_UART_READY and the
     module reference are taken before ops.open(), with shared error
     labels and the tx_wakeup trylock comment aligned with hci_uart.

Both are runtime-tested together under KASAN: the unfixed tree crashes
within the first iterations (slab-use-after-free in nci_uart_write_work),
the series survives 56000+ register/hangup iterations cleanly.

Shubham Antil (2):
  nfc: nfcmrvl: set drv_data before registering the nci device
  nfc: nci: uart: fix use-after-free of write_work on ldisc teardown

 drivers/nfc/nfcmrvl/main.c | 17 ++++++++
 drivers/nfc/nfcmrvl/uart.c |  3 --
 include/net/nfc/nci_core.h |  2 +
 net/nfc/nci/uart.c         | 80 +++++++++++++++++++++++++++++++-------
 4 files changed, 85 insertions(+), 17 deletions(-)

-- 
2.43.0


             reply	other threads:[~2026-10-06 11:55 UTC|newest]

Thread overview: 5+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-10-06 11:55 Shubham Antil [this message]
2026-10-06 11:55 ` [PATCH v4 1/2] nfc: nfcmrvl: set drv_data before registering the nci device Shubham Antil
2026-10-06 11:55 ` [PATCH v4 2/2] nfc: nci: uart: fix use-after-free of write_work on ldisc teardown Shubham Antil
2026-10-09  5:55   ` netdev-bot+sashiko
2026-10-06 11:59 ` [PATCH v4 0/2] nfc: nci: uart: fix write_work teardown UAF (+ nfcmrvl drv_data) netdev-bot+sinfo

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20261006115532.72100-1-shubham@octane.security \
    --to=shubham@octane.security \
    --cc=davem@davemloft.net \
    --cc=david@ixit.cz \
    --cc=edumazet@google.com \
    --cc=gio@octane.security \
    --cc=horms@kernel.org \
    --cc=johan@kernel.org \
    --cc=kuba@kernel.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=netdev@vger.kernel.org \
    --cc=oe-linux-nfc@lists.linux.dev \
    --cc=pabeni@redhat.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®