From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from us-smtp-delivery-124.mimecast.com (us-smtp-delivery-124.mimecast.com [170.10.129.124]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 3C77F241139 for ; Thu, 12 Feb 2026 12:13:26 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=170.10.129.124 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1770898408; cv=none; b=nTWo9vcyXJpHdsgNdQJFTbGQWohVNmIB6fdSzO7J+gTvNYoSt4a9FYnVFC9CEtAKLVMEq1gn7FokxAEni7gXBHhx93cPwZHwPzKypzdGgzq2Q1m1yxXFJ5YFttGxhV5hcaOlY1JlbHvNvfLWN2XTdBL81EtdJaRHVwjSZ1HTZdw= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1770898408; c=relaxed/simple; bh=lKvpeJi7uNV0Ih3JqfJpszylxumkmE+gwrTj1Z8q4po=; h=Message-ID:Date:MIME-Version:Subject:To:Cc:References:From: In-Reply-To:Content-Type; b=J/Emjeq7szaa7sIdDn94cyIYzP5oPKvr94bJoSfJEzNqKjs+5YcCRxyejzD52uoLZ4d2HAMaGurXptfotwKaHI11/seoLLXqI8JuptIVZMtRimnwUxnhMrkx/XbDGUnuB0kcMRYacuww3CITBAuoMlMP+JcSdjGsgtqO5uxsg4Q= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com; spf=pass smtp.mailfrom=redhat.com; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b=emFqgm05; dkim=pass (2048-bit key) header.d=redhat.com header.i=@redhat.com header.b=gjDE/VkB; arc=none smtp.client-ip=170.10.129.124 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=redhat.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=redhat.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=redhat.com header.i=@redhat.com header.b="emFqgm05"; dkim=pass (2048-bit key) header.d=redhat.com header.i=@redhat.com header.b="gjDE/VkB" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=mimecast20190719; t=1770898406; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=RhlNTtPjb8WNYnzKWJ5DsTLwzJj2iKNDqtguIqmgVrY=; b=emFqgm05oJC3IE66wEmUMQdblg/GI/ivOIJSEOgGdyE1NosVWSCYW/YqR34qVEHKPgfi6v oqyVDCrEhgMcCTWZOBGCpGw2q1wMkseA/PPuJXSJ/OhkxeW09LBNeeb7YvhhTw97AR96IK GwIEVLER0AGJNpV/igFdJhqYwbe5whM= Received: from mail-wm1-f69.google.com (mail-wm1-f69.google.com [209.85.128.69]) by relay.mimecast.com with ESMTP with STARTTLS (version=TLSv1.3, cipher=TLS_AES_256_GCM_SHA384) id us-mta-61-Y2GADXlpPdyqKdFGTgdw5A-1; Thu, 12 Feb 2026 07:13:25 -0500 X-MC-Unique: Y2GADXlpPdyqKdFGTgdw5A-1 X-Mimecast-MFC-AGG-ID: Y2GADXlpPdyqKdFGTgdw5A_1770898404 Received: by mail-wm1-f69.google.com with SMTP id 5b1f17b1804b1-482eec44485so23694845e9.3 for ; Thu, 12 Feb 2026 04:13:24 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=redhat.com; s=google; t=1770898403; x=1771503203; darn=vger.kernel.org; h=content-transfer-encoding:in-reply-to:from:content-language :references:cc:to:subject:user-agent:mime-version:date:message-id :from:to:cc:subject:date:message-id:reply-to; bh=RhlNTtPjb8WNYnzKWJ5DsTLwzJj2iKNDqtguIqmgVrY=; b=gjDE/VkB/zjNhBTNLR2RKXXNqmMXAqUIOFjJu4Z3Sn0GF92zNyO17tOGcNLjJVzafu 0oOCzY4pWJ6rjdGlA4USjARScWWkDzbzvOoZZAg+ToF3g30SX2wEISIZjZ6hlybFAqrl 1dsQ8iG7+mu4HDcHVyrgxjm/nRpeavBRhOdTn8sMSduXGng3eunpI1gxs86NGSHmAcQk mCLkE8e2qjEpHLwqxxYDORYS60KP3wqX4Am+xqehwGTrhaU/8iEkDd7vCwFKDkTT483p lSk1jL6+Z8yyeFEKiP+g1D3ku59QgEsam5BVZbAUrzmWD363KmoUuW2harvEf2EZE2xs yvqQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1770898403; x=1771503203; h=content-transfer-encoding:in-reply-to:from:content-language :references:cc:to:subject:user-agent:mime-version:date:message-id :x-gm-gg:x-gm-message-state:from:to:cc:subject:date:message-id :reply-to; bh=RhlNTtPjb8WNYnzKWJ5DsTLwzJj2iKNDqtguIqmgVrY=; b=hjIn+5cJFbOC4mY0rhA/t9UZcC9Mi5sPgO5foHBoE/GQbqdSiSGEkhIyoQ0WBbyLt3 Meg0OjepDMzHLDOEu8S8X1VOXeXY6YmZIIQX/IiivJf3/ZVn+IFPQx98czocm+csT/mp viMF+IldAfdIKlDeSsX1bmAj2aM/HkK2u5L1UgCXLuj2gGTswR0jFerBeAj0rFraROjF mUftmsf7xWCgMQx/teKjIiDs2vi4NaCewnfgaMC7SwFWLU9dhPClqHSVnAHsbU84uwPp iKTlasgNrqkjYA6CWFJ3fUMh+yQNCr3MfJ1qpz2/TpA4K90v32hIE/OQG42R396Not1D fI/w== X-Forwarded-Encrypted: i=1; AJvYcCW0OMR/TbQDyDG9f5GXW1qnZoKx6uFN41bUSQeiXYw5Nhi07CcWNTU2sVXgi8drPIM+3JVaFqjD70yd8JM=@vger.kernel.org X-Gm-Message-State: AOJu0YxcI06r7O22qJEqtfNnd8f8ticr6tuwKEhkb1xTO7lbGPV96r1Q bZNuzsnJtKzeFqscgdx8OFxcd6D7Y9wrA1ofe+qcVZkn0BQpsza9qJPUMjjOW7EF4hSwz/kISRE NOKcUWb20zd+YUWC7WNg1S/8E+zfpiDrA4fImb/4qLeI7qJdRFEmu2Bby0LWwbEjMgs9cZGUrSA == X-Gm-Gg: AZuq6aI7Vrv1gRLM/fRU5sNab6yNs9ihJIH9q/N3fP7CRfwDtiroRTAFqQxjUGRJ3QB zyeEBfePljFpOG3yparrBFgJKbTsEyguzM3yB38NZLLX8R9zLstnJQpDDEtmEnN1XDX3RaQWN47 To+sVKdElFruYCD4yAG+qyz0udBC3EOTHSpC6ofl/FGBeR1/8jKbMB4arl6x1TeiJw51wyikXx0 M7YF7BujozRSVGtklNjDNkD+oNN6+LnwgX+T6GUgG77cejw6ZrDpSkb3Wen2ydMnn8KXFwytPYj tZ1lWADxJbafbOfp/tpZEH+bpkfQGReBrLQxYFSU73pV2wXYAAaiX2S7mnUVY/tfPA1VgiWzsJh Ida2xqBRaroUzlX3eu6b35ZwnwQ== X-Received: by 2002:a05:600c:4511:b0:47f:8c05:786b with SMTP id 5b1f17b1804b1-4836717341bmr26321455e9.28.1770898403475; Thu, 12 Feb 2026 04:13:23 -0800 (PST) X-Received: by 2002:a05:600c:4511:b0:47f:8c05:786b with SMTP id 5b1f17b1804b1-4836717341bmr26320955e9.28.1770898402985; Thu, 12 Feb 2026 04:13:22 -0800 (PST) Received: from [192.168.88.32] ([212.105.155.220]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-4835dd20519sm193863435e9.15.2026.02.12.04.13.22 (version=TLS1_3 cipher=TLS_AES_128_GCM_SHA256 bits=128/128); Thu, 12 Feb 2026 04:13:22 -0800 (PST) Message-ID: <4ce73296-a6da-47d9-8483-5bbe564f20c6@redhat.com> Date: Thu, 12 Feb 2026 13:13:21 +0100 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 User-Agent: Mozilla Thunderbird Subject: Re: [PATCH] net: caif: serial: fix TX UAF on ser->tty To: Shuangpeng Bai , netdev@vger.kernel.org Cc: andrew+netdev@lunn.ch, davem@davemloft.net, edumazet@google.com, kuba@kernel.org, linux-kernel@vger.kernel.org, Shuangpeng Bai References: <20260212042236.639174-1-shuangpeng.kernel@gmail.com> Content-Language: en-US From: Paolo Abeni In-Reply-To: <20260212042236.639174-1-shuangpeng.kernel@gmail.com> Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 7bit On 2/12/26 5:22 AM, Shuangpeng Bai wrote: > KASAN reported a slab-use-after-free in tty_write_room() reachable from > caif_serial's TX path. The TX handler dereferences ser->tty while > ldisc_close() can drop the driver's tty reference. Since ser->tty was > not cleared and accesses were not synchronized, the TX path could race > with tty teardown and dereference a stale ser->tty pointer. > > Fix it by serializing accesses to ser->tty with a dedicated lock. The TX > path grabs a tty kref under the lock and drops it after the TX attempt, > while ldisc_close() clears ser->tty under the same lock before putting > the old tty reference. This prevents the TX path from observing a freed > tty object via ser->tty. > > Reported-by: Shuangpeng Bai > Closes: https://groups.google.com/g/syzkaller/c/usNe0oKtoXw/m/x8qUc3yUAQAJ > Please, no empty lines in the tag area. You must include a fixes tag and specify the target tree in the subj prefix Does not apply cleanly to net nor net-next Please read carefully the process documentation under: Documentation/process/ and especially Documentation/process/maintainer-netdev.rst before resubmitting /P