* [PATCH 6.6.y 0/2] gpio: backport CVE-2026-53226, CVE-2026-64241
@ 2026-10-08 19:18 Artem Dinaburg
2026-10-08 19:18 ` [PATCH 6.6.y 1/2] gpio: rockchip: teardown bugs and resource leaks Artem Dinaburg
` (2 more replies)
0 siblings, 3 replies; 4+ messages in thread
From: Artem Dinaburg @ 2026-10-08 19:18 UTC (permalink / raw)
To: stable
Cc: Artem Dinaburg, Greg Kroah-Hartman, Sasha Levin, Marco Scardovi,
Bartosz Golaszewski, Linus Walleij, Bartosz Golaszewski,
Andy Shevchenko, Heiko Stuebner, linux-gpio, linux-arm-kernel,
linux-rockchip, linux-kernel, Linus Walleij, Bartosz Golaszewski,
jay.xu
Hi Greg, Sasha, and maintainers,
I'm working through the smaller CVE backports still missing from 6.6.y.
These 2 upstream changes belong together for CVE-2026-53226,
CVE-2026-64241. They must be applied in this order because the later change
depends on or completes the earlier one.
The complete series is already present in 6.12.y, 6.18.y, and 7.2.y.
Could you please consider this series for 6.6.y?
Thanks,
Artem Dinaburg
Series:
1. gpio: rockchip: teardown bugs and resource leaks
2. gpio: rockchip: fix generic IRQ chip leak on remove
base: v6.6.157 (79643295eba17affbd16ca97f3ef04c90266b28c) plus stable-queue
revision 958ddf240a33ef26b1771be944f0ea6c3b597472
^ permalink raw reply [flat|nested] 4+ messages in thread
* [PATCH 6.6.y 1/2] gpio: rockchip: teardown bugs and resource leaks
2026-10-08 19:18 [PATCH 6.6.y 0/2] gpio: backport CVE-2026-53226, CVE-2026-64241 Artem Dinaburg
@ 2026-10-08 19:18 ` Artem Dinaburg
2026-10-08 19:18 ` [PATCH 6.6.y 2/2] gpio: rockchip: fix generic IRQ chip leak on remove Artem Dinaburg
2026-10-09 17:09 ` [PATCH 6.6.y 0/2] gpio: backport CVE-2026-53226, CVE-2026-64241 Sasha Levin
2 siblings, 0 replies; 4+ messages in thread
From: Artem Dinaburg @ 2026-10-08 19:18 UTC (permalink / raw)
To: stable
Cc: Artem Dinaburg, Greg Kroah-Hartman, Sasha Levin, Marco Scardovi,
Bartosz Golaszewski, Linus Walleij, Bartosz Golaszewski,
Andy Shevchenko, Heiko Stuebner, linux-gpio, linux-arm-kernel,
linux-rockchip, linux-kernel, Linus Walleij, Bartosz Golaszewski,
jay.xu
From: Marco Scardovi <scardracs@disroot.org>
[ Upstream commit 9500077678230e36d22bf16d2b9539c13e59a801 ]
Address several teardown issues and resource leaks in the driver's remove
path and error handling:
1. Debounce clock reference leak: The debounce clock (bank->db_clk) is
obtained using of_clk_get() which increments the clock's reference
count, but clk_put() is never called. Register a devm action to
cleanly release it on unbind. Note that of_clk_get(..., 1) remains
necessary over devm_clk_get() because the DT binding does not define
clock-names, precluding name-based lookup.
2. Unregistered chained IRQ handler: The chained IRQ handler is not
disconnected in remove(). If a stray interrupt fires after the driver
is removed, the kernel attempts to execute a stale handler, leading
to a panic. Fix this by clearing the handler in remove().
3. IRQ domain leak: The linear IRQ domain and its generic chips are
allocated manually during probe but never removed. Remove the IRQ
domain during driver teardown to free the associated generic chips
and mappings.
[ Backport to 6.6.y: For 6.6.y, send with 1c1e0fc88d6e (CVE-2026-53226)
so generic chips are explicitly removed before irq_domain_remove().
6.1.y lacks irq_domain_remove_generic_chips(), so it needs a
separately reviewed older generic-chip teardown backport. ]
Fixes: 936ee2675eee ("gpio/rockchip: add driver for rockchip gpio")
Assisted-by: Antigravity:gemini-3.5-flash
Signed-off-by: Marco Scardovi <scardracs@disroot.org>
Link: https://patch.msgid.link/20260526171050.12785-3-scardracs@disroot.org
[Bartosz: don't emit an error message on devres allocation failure]
Signed-off-by: Bartosz Golaszewski <bartosz.golaszewski@oss.qualcomm.com>
Assisted-by: LLM
Signed-off-by: Artem Dinaburg <artem@trailofbits.com>
---
This is patch 1 of 2 in the ordered 6.6.y backport series.
This change addresses CVE-2026-64241. Releases the debounce-clock
reference, disconnects the chained IRQ handler, and removes the IRQ domain
during driver teardown.
The fix is already present in 6.12.y, 6.18.y, and 7.2.y, but not in 6.6.y.
drivers/gpio/gpio-rockchip.c | 17 ++++++++++++++++-
1 file changed, 16 insertions(+), 1 deletion(-)
diff --git a/drivers/gpio/gpio-rockchip.c b/drivers/gpio/gpio-rockchip.c
index ff9a4b8611d7..e0e4f3ed5fdd 100644
--- a/drivers/gpio/gpio-rockchip.c
+++ b/drivers/gpio/gpio-rockchip.c
@@ -629,10 +629,17 @@ static int rockchip_gpiolib_register(struct rockchip_pin_bank *bank)
return ret;
}
+static void rockchip_clk_put(void *data)
+{
+ struct clk *clk = data;
+
+ clk_put(clk);
+}
+
static int rockchip_get_bank_data(struct rockchip_pin_bank *bank)
{
struct resource res;
- int id = 0;
+ int id = 0, ret;
if (of_address_to_resource(bank->of_node, 0, &res)) {
dev_err(bank->dev, "cannot find IO resource for bank\n");
@@ -662,6 +669,11 @@ static int rockchip_get_bank_data(struct rockchip_pin_bank *bank)
dev_err(bank->dev, "cannot find debounce clk\n");
return -EINVAL;
}
+
+ ret = devm_add_action_or_reset(bank->dev, rockchip_clk_put,
+ bank->db_clk);
+ if (ret)
+ return ret;
} else {
bank->gpio_regs = &gpio_regs_v1;
bank->gpio_type = GPIO_TYPE_V1;
@@ -773,6 +785,9 @@ static int rockchip_gpio_remove(struct platform_device *pdev)
{
struct rockchip_pin_bank *bank = platform_get_drvdata(pdev);
+ irq_set_chained_handler_and_data(bank->irq, NULL, NULL);
+ if (bank->domain)
+ irq_domain_remove(bank->domain);
gpiochip_remove(&bank->gpio_chip);
return 0;
--
2.39.5
^ permalink raw reply [flat|nested] 4+ messages in thread
* [PATCH 6.6.y 2/2] gpio: rockchip: fix generic IRQ chip leak on remove
2026-10-08 19:18 [PATCH 6.6.y 0/2] gpio: backport CVE-2026-53226, CVE-2026-64241 Artem Dinaburg
2026-10-08 19:18 ` [PATCH 6.6.y 1/2] gpio: rockchip: teardown bugs and resource leaks Artem Dinaburg
@ 2026-10-08 19:18 ` Artem Dinaburg
2026-10-09 17:09 ` [PATCH 6.6.y 0/2] gpio: backport CVE-2026-53226, CVE-2026-64241 Sasha Levin
2 siblings, 0 replies; 4+ messages in thread
From: Artem Dinaburg @ 2026-10-08 19:18 UTC (permalink / raw)
To: stable
Cc: Artem Dinaburg, Greg Kroah-Hartman, Sasha Levin, Marco Scardovi,
Bartosz Golaszewski, Linus Walleij, Bartosz Golaszewski,
Andy Shevchenko, Heiko Stuebner, linux-gpio, linux-arm-kernel,
linux-rockchip, linux-kernel, Linus Walleij, Bartosz Golaszewski,
jay.xu
From: Marco Scardovi <scardracs@disroot.org>
[ Upstream commit 1c1e0fc88d6ef65bf15d517853251f75ab9d18c3 ]
The driver allocates domain generic chips using
irq_alloc_domain_generic_chips() during probe. However, on driver
remove/teardown, the generic chips are not automatically freed when the
IRQ domain is removed because the domain flags do not include
IRQ_DOMAIN_FLAG_DESTROY_GC.
This causes both the domain generic chips structure and the associated
generic chips to be leaked. Additionally, the generic chips remain on
the global gc_list and may later be visited by generic IRQ chip suspend,
resume, or shutdown callbacks after the GPIO bank has been removed,
potentially resulting in a use-after-free and kernel crash.
Fix the resource leak by explicitly calling
irq_domain_remove_generic_chips() before removing the IRQ domain in
rockchip_gpio_remove().
[ Backport to 6.6.y: Use the upstream teardown helper on 6.6. Defer 6.1
because irq_domain_remove_generic_chips() is absent and needs a
prerequisite or reviewed target-native cleanup. ]
Fixes: 936ee2675eee ("gpio/rockchip: add driver for rockchip gpio")
Assisted-by: Antigravity:gemini-3.5-flash
Signed-off-by: Marco Scardovi <scardracs@disroot.org>
Link: https://patch.msgid.link/20260607230504.35392-2-scardracs@disroot.org
Signed-off-by: Bartosz Golaszewski <bartosz.golaszewski@oss.qualcomm.com>
Assisted-by: LLM
Signed-off-by: Artem Dinaburg <artem@trailofbits.com>
---
This is patch 2 of 2 in the ordered 6.6.y backport series.
This change addresses CVE-2026-53226. The target creates generic IRQ chips
and omits their removal; the prerequisite supplies a complete teardown
helper and the CVE fix invokes it before removing the IRQ domain.
The fix is already present in 6.12.y, 6.18.y, and 7.2.y, but not in 6.6.y.
drivers/gpio/gpio-rockchip.c | 4 +++-
1 file changed, 3 insertions(+), 1 deletion(-)
diff --git a/drivers/gpio/gpio-rockchip.c b/drivers/gpio/gpio-rockchip.c
index e0e4f3ed5fdd..86cf3cbcdb40 100644
--- a/drivers/gpio/gpio-rockchip.c
+++ b/drivers/gpio/gpio-rockchip.c
@@ -786,8 +786,10 @@ static int rockchip_gpio_remove(struct platform_device *pdev)
struct rockchip_pin_bank *bank = platform_get_drvdata(pdev);
irq_set_chained_handler_and_data(bank->irq, NULL, NULL);
- if (bank->domain)
+ if (bank->domain) {
+ irq_domain_remove_generic_chips(bank->domain);
irq_domain_remove(bank->domain);
+ }
gpiochip_remove(&bank->gpio_chip);
return 0;
--
2.39.5
^ permalink raw reply [flat|nested] 4+ messages in thread
* Re: [PATCH 6.6.y 0/2] gpio: backport CVE-2026-53226, CVE-2026-64241
2026-10-08 19:18 [PATCH 6.6.y 0/2] gpio: backport CVE-2026-53226, CVE-2026-64241 Artem Dinaburg
2026-10-08 19:18 ` [PATCH 6.6.y 1/2] gpio: rockchip: teardown bugs and resource leaks Artem Dinaburg
2026-10-08 19:18 ` [PATCH 6.6.y 2/2] gpio: rockchip: fix generic IRQ chip leak on remove Artem Dinaburg
@ 2026-10-09 17:09 ` Sasha Levin
2 siblings, 0 replies; 4+ messages in thread
From: Sasha Levin @ 2026-10-09 17:09 UTC (permalink / raw)
To: stable
Cc: Sasha Levin, Artem Dinaburg, Greg Kroah-Hartman, Marco Scardovi,
Bartosz Golaszewski, Linus Walleij, Bartosz Golaszewski,
Andy Shevchenko, Heiko Stuebner, linux-gpio, linux-arm-kernel,
linux-rockchip, linux-kernel, Linus Walleij, Bartosz Golaszewski,
jay.xu
> Could you please consider this series for 6.6.y?
Queued the series for 6.6, thanks.
--
Thanks,
Sasha
^ permalink raw reply [flat|nested] 4+ messages in thread
end of thread, other threads:[~2026-10-09 17:10 UTC | newest]
Thread overview: 4+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-10-08 19:18 [PATCH 6.6.y 0/2] gpio: backport CVE-2026-53226, CVE-2026-64241 Artem Dinaburg
2026-10-08 19:18 ` [PATCH 6.6.y 1/2] gpio: rockchip: teardown bugs and resource leaks Artem Dinaburg
2026-10-08 19:18 ` [PATCH 6.6.y 2/2] gpio: rockchip: fix generic IRQ chip leak on remove Artem Dinaburg
2026-10-09 17:09 ` [PATCH 6.6.y 0/2] gpio: backport CVE-2026-53226, CVE-2026-64241 Sasha Levin
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®