From: Artem Dinaburg <artem@trailofbits.com>
To: stable@vger.kernel.org
Cc: Artem Dinaburg <artem@trailofbits.com>,
Greg Kroah-Hartman <gregkh@linuxfoundation.org>,
Sasha Levin <sashal@kernel.org>,
Sudeep Holla <sudeep.holla@kernel.org>,
Sashiko <sashiko-bot@kernel.org>,
Sudeep Holla <sudeep.holla@arm.com>,
Cristian Marussi <cristian.marussi@arm.com>,
linux-arm-kernel@lists.infradead.org,
linux-kernel@vger.kernel.org, arm-scmi@vger.kernel.org
Subject: [PATCH 6.6.y 2/2] firmware: arm_scmi: Unwind TX receiver mailbox setup failure
Date: Thu, 8 Oct 2026 15:16:21 -0400 [thread overview]
Message-ID: <20261008191624.98532-3-artem@trailofbits.com> (raw)
In-Reply-To: <20261008191624.98532-1-artem@trailofbits.com>
From: Sudeep Holla <sudeep.holla@kernel.org>
[ Upstream commit 6f7c06744d53dc8e047725d411d7f915d9ec35ae ]
mailbox_chan_setup() can request an additional unidirectional TX
receiver channel after successfully acquiring the primary channel. If
that second request fails, the function returns immediately and leaves
the primary channel allocated.
Unwind the primary mailbox channel before returning the error so probe
deferral or other setup failures do not leave the channel busy for later
probe attempts.
[ Backport to 6.6.y: apply the same failure unwind to the pre-transport-
split mailbox source. ]
Fixes: 9f68ff79ec2c ("firmware: arm_scmi: Add support for unidirectional mailbox channels")
Reported-by: Sashiko <sashiko-bot@kernel.org>
Link: https://patch.msgid.link/20260714-scmi_core_fixes-v6-13-3afe499d46e3@kernel.org
Signed-off-by: Sudeep Holla <sudeep.holla@kernel.org>
Assisted-by: LLM
Signed-off-by: Artem Dinaburg <artem@trailofbits.com>
---
This is patch 2 of 2 in the ordered 6.6.y backport series.
This change addresses CVE-2026-93083. The receiver-mailbox setup can fail
after callbacks become reachable; the unwind has real effect, but it is
safe only after channel setup state is published in the order fixed by
CVE-2026-93093.
This needed a target-specific adjustment; I called it out in the bracketed
backport note above.
The fix is already present in 6.12.y, 6.18.y, and 7.2.y, but not in 6.6.y.
drivers/firmware/arm_scmi/mailbox.c | 5 ++++-
1 file changed, 4 insertions(+), 1 deletion(-)
diff --git a/drivers/firmware/arm_scmi/mailbox.c b/drivers/firmware/arm_scmi/mailbox.c
index 80b67f46a4d1..a34a3c693e15 100644
--- a/drivers/firmware/arm_scmi/mailbox.c
+++ b/drivers/firmware/arm_scmi/mailbox.c
@@ -230,14 +230,17 @@ static int mailbox_chan_setup(struct scmi_chan_info *cinfo, struct device *dev,
smbox->chan_receiver = mbox_request_channel(cl, a2p_rx_chan);
if (IS_ERR(smbox->chan_receiver)) {
ret = PTR_ERR(smbox->chan_receiver);
+ smbox->chan_receiver = NULL;
if (ret != -EPROBE_DEFER)
dev_err(cdev, "failed to request SCMI Tx Receiver mailbox\n");
- return ret;
+ goto err_free_chan;
}
}
return 0;
+err_free_chan:
+ mbox_free_channel(smbox->chan);
err_clear_cinfo:
cinfo->transport_info = NULL;
smbox->cinfo = NULL;
--
2.39.5
prev parent reply other threads:[~2026-10-08 19:16 UTC|newest]
Thread overview: 3+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-10-08 19:16 [PATCH 6.6.y 0/2] firmware: backport CVE-2026-93083, CVE-2026-93093 Artem Dinaburg
2026-10-08 19:16 ` [PATCH 6.6.y 1/2] firmware: arm_scmi: Publish channel state before callbacks Artem Dinaburg
2026-10-08 19:16 ` Artem Dinaburg [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20261008191624.98532-3-artem@trailofbits.com \
--to=artem@trailofbits.com \
--cc=arm-scmi@vger.kernel.org \
--cc=cristian.marussi@arm.com \
--cc=gregkh@linuxfoundation.org \
--cc=linux-arm-kernel@lists.infradead.org \
--cc=linux-kernel@vger.kernel.org \
--cc=sashal@kernel.org \
--cc=sashiko-bot@kernel.org \
--cc=stable@vger.kernel.org \
--cc=sudeep.holla@arm.com \
--cc=sudeep.holla@kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®