From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-oa1-f72.google.com (mail-oa1-f72.google.com [209.85.160.72]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 159FE3148DA for ; Sat, 1 Aug 2026 01:02:25 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.160.72 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785546147; cv=none; b=QsqXb5xvWWz4/yUVR45aXVBASefasa8qEMMUoVqr360UFwHfIsUVwj2vVpP3raYK73OOst6RjXcI5msv7ItcpvEC4EEXaqWIhYYKBhVEe/rL/zveQcJDgISxMJRE28gvSt7kzfaeIKz/Ny5XjqQn9Q8MfOnx5NibaA3NL8LRkEQ= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785546147; c=relaxed/simple; bh=qELnRmZVIdEUacVqfjEsy7rgFUiM8vSnjV5PSBvZKCs=; h=MIME-Version:Date:In-Reply-To:Message-ID:Subject:From:To:Cc: Content-Type; b=gg2nZ5PLxY04xAj9utCe+/cMuJV0cWhsboUm2dJqwHKJhop9LyWBhWtFOmz4JZsPo16tjKK9yepoZ7wbGRNEXWljS4bO56rpFt+emuhwPOUnOqsBoaf3YunsJ/lUhaYEurappJHnCJxPWl0fqeiwFMORXBdg/rjOsScNIFBe9cE= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=fail (p=none dis=none) header.from=syzkaller.appspotmail.com; spf=pass smtp.mailfrom=M3KW2WVRGUFZ5GODRSRYTGD7.apphosting.bounces.google.com; arc=none smtp.client-ip=209.85.160.72 Authentication-Results: smtp.subspace.kernel.org; dmarc=fail (p=none dis=none) header.from=syzkaller.appspotmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=M3KW2WVRGUFZ5GODRSRYTGD7.apphosting.bounces.google.com Received: by mail-oa1-f72.google.com with SMTP id 586e51a60fabf-44899f99756so2082163fac.2 for ; Fri, 31 Jul 2026 18:02:25 -0700 (PDT) X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785546145; x=1786150945; h=content-type:cc:to:from:subject:message-id:in-reply-to:date :mime-version:x-gm-message-state:from:to:cc:subject:date:message-id :reply-to:content-type; bh=UHKog/zy6y2c6tMxkVNbDp4JjxgvmhU1XTc/6DKVKI0=; b=r/qg+dJDrhp/n0GeJY6Fkh0Ft/frooccLsjGGwl66QWI/MJ0jqdo6TtrC7R29rFfuz 1cFeLw/lseW0a/FXz9LMmME768V08xdko2OJ+FFpwcIx6G2rZVfZcuQiPF7eJplfJcFR OPZuPAx9LzvLxmexmK9eNSDRJ7U7LlKteUZf1ocAZAS1Z7AD4jK1jicExveMwS8UfqoP O+txfmV40iu5bDs0L4jejX+DfV6/aFpSYLaRuanRNk3C08ShE0aTdHEhnqwRLYqE2y6Z wBXMNtpAIcLTiBb/3j/GyvZ61T8B2hIuGT8eeNimhjN9zXls1ex9POQ1ccVTNv1jb7Jm vQsg== X-Forwarded-Encrypted: i=1; AHgh+RrFir1vW94uWtt3yO5Nmh+Iw72R9NK1I20DttGQwKo3yJaz5pD+mkmEoVonwqz7DTlxB8awPCQMWmBwmvE=@vger.kernel.org X-Gm-Message-State: AOJu0YyZYH6X5h2x2sbkqdeLHRtXPcr/1RT3XQ2m/WCFSbVgaxvKk6y8 vhwgX+d4xneyZtSvAqoon3dWlNmaH4gMBJljyGiN8s60ItIC7jI9SWkf8NPOeAW6ddjiuhSIzY2 01XsDnltSu59xWBTRXOl7y9t+jD/J2KbkKINyotfm/U/hK3flDBcv/cJ8JLY= Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 X-Received: by 2002:a05:6808:1797:b0:494:18ad:8a5b with SMTP id 5614622812f47-4af5e34efd0mr3367628b6e.17.1785546145005; Fri, 31 Jul 2026 18:02:25 -0700 (PDT) Date: Fri, 31 Jul 2026 18:02:24 -0700 In-Reply-To: X-Google-Appengine-App-Id: s~syzkaller X-Google-Appengine-App-Id-Alias: syzkaller Message-ID: <6a6d45a0.2d659fcc.1d46f5.01ae.GAE@google.com> Subject: Re: [syzbot] [kernel?] KASAN: slab-use-after-free Read in __release_resource From: syzbot To: include@grrlz.net Cc: include@grrlz.net, linux-kernel@vger.kernel.org, syzkaller-bugs@googlegroups.com Content-Type: text/plain; charset="UTF-8" > #syz test: From 9cd23575828ada0a338a2dd0019e97476c4f5d23 Mon Sep 17 I've failed to parse your command. Did you perhaps forget to provide the branch name, or added an extra ':'? Please use one of the two supported formats: 1. #syz test 2. #syz test: repo branch-or-commit-hash Note the lack of ':' in option 1. > 00:00:00 2001 > From: Bradley Morgan > Date: Sat, 1 Aug 2026 00:58:20 +0000 > Subject: [PATCH] driver core: platform: use remove_resource() to properly reparent children > > platform_device_add() inserts resources into the global iomem/ioport > trees via insert_resource(), which may reparent existing resources as > children of the newly inserted one. > > The teardown paths in platform_device_add() (error path) and > platform_device_del() use release_resource() to remove these > resources. However, release_resource() calls __release_resource() > with release_child=true, which simply unlinks the resource from its > parent's child list without reparenting its children. Any child > resources that were moved under it by insert_resource() are left > with dangling ->parent pointers. > > When the platform device's kmemdup'd resource array is subsequently > freed by platform_device_release(), those children (e.g. a PCI BAR > resource that was reparented under the platform device's resource) > end up with ->parent pointing to freed memory. A later > release_resource() on such a child dereferences the stale pointer in > __release_resource(), causing a slab-use-after-free. > > Fix it by using remove_resource() instead, which is the proper > counterpart to insert_resource(). remove_resource() calls > __release_resource() with release_child=false, which reparents > children up to the removed resource's parent before unlinking it, > keeping all ->parent pointers valid. > > Reported-by: syzbot+ee1062851b628d722093@syzkaller.appspotmail.com > Closes: https://lore.kernel.org/all/6a6d39e7.f794c993.27aeb.0009.GAE@google.com/ > Assisted-by: GLM:glm-5.2 > Signed-off-by: Bradley Morgan > --- > drivers/base/platform.c | 4 ++-- > 1 file changed, 2 insertions(+), 2 deletions(-) > > diff --git a/drivers/base/platform.c b/drivers/base/platform.c > index a71015f1d915..9a6932d50ee5 100644 > --- a/drivers/base/platform.c > +++ b/drivers/base/platform.c > @@ -830,7 +830,7 @@ int platform_device_add(struct platform_device *pdev) > while (i--) { > struct resource *r = &pdev->resource[i]; > if (r->parent) > - release_resource(r); > + remove_resource(r); > } > > return ret; > @@ -860,7 +860,7 @@ void platform_device_del(struct platform_device *pdev) > for (i = 0; i < pdev->num_resources; i++) { > struct resource *r = &pdev->resource[i]; > if (r->parent) > - release_resource(r); > + remove_resource(r); > } > } > } > -- > 2.47.3 > > > Note: AI generated. > Thanks!