* [PATCH] tty: fix saved termios reset race
@ 2026-09-30 9:19 Johan Hovold
2026-09-30 9:28 ` Johan Hovold
0 siblings, 1 reply; 2+ messages in thread
From: Johan Hovold @ 2026-09-30 9:19 UTC (permalink / raw)
To: Greg Kroah-Hartman, Jiri Slaby
Cc: David Lin, Alex Elder, Oliver Neukum, linux-usb, linux-serial,
linux-kernel, Johan Hovold, Chengfeng Ye, stable
Resetting saved termios state on device registration is needed where a
minor number can be reused for an entirely different device and where
the old settings may prevent the port from even being opened (e.g. when
CLOCAL is not set).
Not all TTY drivers guarantee that the minor number is no longer in use
when registering devices however, something which can lead to a
use-after-free when closing a TTY (and saving its termios) races with
re-registration.
Add a new TTY_DRIVER_RESET_SAVED_TERMIOS flag to request that any saved
termios state is reset on registration and only set it for drivers that
make sure that the minor number is no longer in use.
Fixes: 93857edd9829 ("tty: reset termios state on device registration")
Reported-by: Chengfeng Ye <nicoyip.dev@gmail.com>
Link: https://lore.kernel.org/20260926184154.3017929-1-nicoyip.dev@gmail.com
Cc: stable@vger.kernel.org # 4.12
Signed-off-by: Johan Hovold <johan@kernel.org>
---
drivers/staging/greybus/uart.c | 3 ++-
drivers/tty/tty_io.c | 18 ++++++++++--------
drivers/usb/class/cdc-acm.c | 2 +-
drivers/usb/serial/usb-serial.c | 3 ++-
include/linux/tty_driver.h | 6 ++++++
5 files changed, 21 insertions(+), 11 deletions(-)
diff --git a/drivers/staging/greybus/uart.c b/drivers/staging/greybus/uart.c
index f2810b5ec824..d7df65088ef7 100644
--- a/drivers/staging/greybus/uart.c
+++ b/drivers/staging/greybus/uart.c
@@ -962,7 +962,8 @@ static int gb_tty_init(void)
int retval = 0;
gb_tty_driver = tty_alloc_driver(GB_NUM_MINORS, TTY_DRIVER_REAL_RAW |
- TTY_DRIVER_DYNAMIC_DEV);
+ TTY_DRIVER_DYNAMIC_DEV |
+ TTY_DRIVER_RESET_SAVED_TERMIOS);
if (IS_ERR(gb_tty_driver)) {
pr_err("Can not allocate tty driver\n");
retval = PTR_ERR(gb_tty_driver);
diff --git a/drivers/tty/tty_io.c b/drivers/tty/tty_io.c
index 1c30faae9ec1..c9da7b25e3fb 100644
--- a/drivers/tty/tty_io.c
+++ b/drivers/tty/tty_io.c
@@ -3256,14 +3256,16 @@ struct device *tty_register_device_attr(struct tty_driver *driver,
goto err_put;
if (!(driver->flags & TTY_DRIVER_DYNAMIC_ALLOC)) {
- /*
- * Free any saved termios data so that the termios state is
- * reset when reusing a minor number.
- */
- tp = driver->termios[index];
- if (tp) {
- driver->termios[index] = NULL;
- kfree(tp);
+ if (driver->flags && TTY_DRIVER_RESET_SAVED_TERMIOS) {
+ /*
+ * Free any saved termios data so that the termios state is
+ * reset when reusing a minor number.
+ */
+ tp = driver->termios[index];
+ if (tp) {
+ driver->termios[index] = NULL;
+ kfree(tp);
+ }
}
retval = tty_cdev_add(driver, devt, index, 1);
diff --git a/drivers/usb/class/cdc-acm.c b/drivers/usb/class/cdc-acm.c
index 7edda9019d54..bf6ef1ecf2c5 100644
--- a/drivers/usb/class/cdc-acm.c
+++ b/drivers/usb/class/cdc-acm.c
@@ -2150,7 +2150,7 @@ static int __init acm_init(void)
{
int retval;
acm_tty_driver = tty_alloc_driver(ACM_TTY_MINORS, TTY_DRIVER_REAL_RAW |
- TTY_DRIVER_DYNAMIC_DEV);
+ TTY_DRIVER_DYNAMIC_DEV | TTY_DRIVER_RESET_SAVED_TERMIOS);
if (IS_ERR(acm_tty_driver))
return PTR_ERR(acm_tty_driver);
acm_tty_driver->driver_name = "acm",
diff --git a/drivers/usb/serial/usb-serial.c b/drivers/usb/serial/usb-serial.c
index f3c594f1a806..4a19621f08ba 100644
--- a/drivers/usb/serial/usb-serial.c
+++ b/drivers/usb/serial/usb-serial.c
@@ -1372,7 +1372,8 @@ static int __init usb_serial_init(void)
int result;
usb_serial_tty_driver = tty_alloc_driver(USB_SERIAL_TTY_MINORS,
- TTY_DRIVER_REAL_RAW | TTY_DRIVER_DYNAMIC_DEV);
+ TTY_DRIVER_REAL_RAW | TTY_DRIVER_DYNAMIC_DEV |
+ TTY_DRIVER_RESET_SAVED_TERMIOS);
if (IS_ERR(usb_serial_tty_driver))
return PTR_ERR(usb_serial_tty_driver);
diff --git a/include/linux/tty_driver.h b/include/linux/tty_driver.h
index 1f2896e56e77..62e459c5d3ae 100644
--- a/include/linux/tty_driver.h
+++ b/include/linux/tty_driver.h
@@ -73,6 +73,11 @@ struct serial_struct;
* @TTY_DRIVER_NO_WORKQUEUE:
* Do not create workqueue when tty_register_driver(). Whenever set, flip
* buffer workqueue can be set by tty_port_link_wq() for every port.
+ *
+ * @TTY_DRIVER_RESET_SAVED_TERMIOS
+ * Reset any saved termios settings on device registration when reusing a
+ * minor number. Must only be set by drivers that guarantee that the minor
+ * number is no longer in use.
*/
enum tty_driver_flag {
TTY_DRIVER_INSTALLED = BIT(0),
@@ -84,6 +89,7 @@ enum tty_driver_flag {
TTY_DRIVER_DYNAMIC_ALLOC = BIT(6),
TTY_DRIVER_UNNUMBERED_NODE = BIT(7),
TTY_DRIVER_NO_WORKQUEUE = BIT(8),
+ TTY_DRIVER_RESET_SAVED_TERMIOS = BIT(9),
};
enum tty_driver_type {
--
2.55.0
^ permalink raw reply [flat|nested] 2+ messages in thread
* Re: [PATCH] tty: fix saved termios reset race
2026-09-30 9:19 [PATCH] tty: fix saved termios reset race Johan Hovold
@ 2026-09-30 9:28 ` Johan Hovold
0 siblings, 0 replies; 2+ messages in thread
From: Johan Hovold @ 2026-09-30 9:28 UTC (permalink / raw)
To: Greg Kroah-Hartman, Jiri Slaby
Cc: David Lin, Alex Elder, Oliver Neukum, linux-usb, linux-serial,
linux-kernel, Chengfeng Ye, stable
On Wed, Sep 30, 2026 at 11:19:38AM +0200, Johan Hovold wrote:
> Resetting saved termios state on device registration is needed where a
> minor number can be reused for an entirely different device and where
> the old settings may prevent the port from even being opened (e.g. when
> CLOCAL is not set).
>
> Not all TTY drivers guarantee that the minor number is no longer in use
> when registering devices however, something which can lead to a
> use-after-free when closing a TTY (and saving its termios) races with
> re-registration.
>
> Add a new TTY_DRIVER_RESET_SAVED_TERMIOS flag to request that any saved
> termios state is reset on registration and only set it for drivers that
> make sure that the minor number is no longer in use.
>
> Fixes: 93857edd9829 ("tty: reset termios state on device registration")
> Reported-by: Chengfeng Ye <nicoyip.dev@gmail.com>
> Link: https://lore.kernel.org/20260926184154.3017929-1-nicoyip.dev@gmail.com
> Cc: stable@vger.kernel.org # 4.12
> Signed-off-by: Johan Hovold <johan@kernel.org>
> ---
> if (!(driver->flags & TTY_DRIVER_DYNAMIC_ALLOC)) {
> - /*
> - * Free any saved termios data so that the termios state is
> - * reset when reusing a minor number.
> - */
> - tp = driver->termios[index];
> - if (tp) {
> - driver->termios[index] = NULL;
> - kfree(tp);
> + if (driver->flags && TTY_DRIVER_RESET_SAVED_TERMIOS) {
This was of course meant to be a bitwise & as Sashiko noted.
I'll wait a bit before sending a v2.
Johan
^ permalink raw reply [flat|nested] 2+ messages in thread
end of thread, other threads:[~2026-09-30 9:28 UTC | newest]
Thread overview: 2+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-09-30 9:19 [PATCH] tty: fix saved termios reset race Johan Hovold
2026-09-30 9:28 ` Johan Hovold
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®