* [PATCH] nvmem: core: Fix nvmem use-after-free in nvmem_cell_put()
@ 2026-09-17 12:33 Wentao Liang
2026-09-18 21:27 ` Srinivas Kandagatla
0 siblings, 1 reply; 2+ messages in thread
From: Wentao Liang @ 2026-09-17 12:33 UTC (permalink / raw)
To: gregkh; +Cc: linux-kernel, miquel.raynal, srini, Wentao Liang, stable
__nvmem_device_put() drops the last reference to the nvmem device, which
runs nvmem_device_release() and unregisters and frees the device, but
nvmem_layout_module_put() then dereferences nvmem->layout on that freed
device.
Call nvmem_layout_module_put() before __nvmem_device_put() so the layout
is still accessed while the device is alive.
Fixes: fc29fd821d9ac ("nvmem: core: Rework layouts to become regular devices")
Cc: stable@vger.kernel.org
Signed-off-by: Wentao Liang <vulab@iscas.ac.cn>
---
drivers/nvmem/core.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/nvmem/core.c b/drivers/nvmem/core.c
index 311cb2e5a5c0..4df7efde2cd2 100644
--- a/drivers/nvmem/core.c
+++ b/drivers/nvmem/core.c
@@ -1593,8 +1593,8 @@ void nvmem_cell_put(struct nvmem_cell *cell)
kfree_const(cell->id);
kfree(cell);
- __nvmem_device_put(nvmem);
nvmem_layout_module_put(nvmem);
+ __nvmem_device_put(nvmem);
}
EXPORT_SYMBOL_GPL(nvmem_cell_put);
--
2.34.1
^ permalink raw reply [flat|nested] 2+ messages in thread
* Re: [PATCH] nvmem: core: Fix nvmem use-after-free in nvmem_cell_put()
2026-09-17 12:33 [PATCH] nvmem: core: Fix nvmem use-after-free in nvmem_cell_put() Wentao Liang
@ 2026-09-18 21:27 ` Srinivas Kandagatla
0 siblings, 0 replies; 2+ messages in thread
From: Srinivas Kandagatla @ 2026-09-18 21:27 UTC (permalink / raw)
To: Wentao Liang, gregkh; +Cc: linux-kernel, miquel.raynal, srini, stable
On 9/17/26 1:33 PM, Wentao Liang wrote:
> __nvmem_device_put() drops the last reference to the nvmem device, which
> runs nvmem_device_release() and unregisters and frees the device, but
> nvmem_layout_module_put() then dereferences nvmem->layout on that freed
> device.
>
> Call nvmem_layout_module_put() before __nvmem_device_put() so the layout
> is still accessed while the device is alive.
This is almost 3 or 4th time, am seeing patches from this email,
repeating and sending duplicate patches with out checking correct tree
and without checking mailing list.
Please do not waste maintainers time.
this is duplicate patch of 5b6b6fc49189
--srini
>
> Fixes: fc29fd821d9ac ("nvmem: core: Rework layouts to become regular devices")
> Cc: stable@vger.kernel.org
> Signed-off-by: Wentao Liang <vulab@iscas.ac.cn>
> ---
> drivers/nvmem/core.c | 2 +-
> 1 file changed, 1 insertion(+), 1 deletion(-)
>
> diff --git a/drivers/nvmem/core.c b/drivers/nvmem/core.c
> index 311cb2e5a5c0..4df7efde2cd2 100644
> --- a/drivers/nvmem/core.c
> +++ b/drivers/nvmem/core.c
> @@ -1593,8 +1593,8 @@ void nvmem_cell_put(struct nvmem_cell *cell)
> kfree_const(cell->id);
>
> kfree(cell);
> - __nvmem_device_put(nvmem);
> nvmem_layout_module_put(nvmem);
> + __nvmem_device_put(nvmem);
> }
> EXPORT_SYMBOL_GPL(nvmem_cell_put);
>
^ permalink raw reply [flat|nested] 2+ messages in thread
end of thread, other threads:[~2026-09-18 21:27 UTC | newest]
Thread overview: 2+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-09-17 12:33 [PATCH] nvmem: core: Fix nvmem use-after-free in nvmem_cell_put() Wentao Liang
2026-09-18 21:27 ` Srinivas Kandagatla
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®