mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
* [PATCH] nvmem: core: Fix nvmem use-after-free in nvmem_cell_put()
@ 2026-09-17 12:33 Wentao Liang
  2026-09-18 21:27 ` Srinivas Kandagatla
  0 siblings, 1 reply; 2+ messages in thread
From: Wentao Liang @ 2026-09-17 12:33 UTC (permalink / raw)
  To: gregkh; +Cc: linux-kernel, miquel.raynal, srini, Wentao Liang, stable

__nvmem_device_put() drops the last reference to the nvmem device, which
runs nvmem_device_release() and unregisters and frees the device, but
nvmem_layout_module_put() then dereferences nvmem->layout on that freed
device.

Call nvmem_layout_module_put() before __nvmem_device_put() so the layout
is still accessed while the device is alive.

Fixes: fc29fd821d9ac ("nvmem: core: Rework layouts to become regular devices")
Cc: stable@vger.kernel.org
Signed-off-by: Wentao Liang <vulab@iscas.ac.cn>
---
 drivers/nvmem/core.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/drivers/nvmem/core.c b/drivers/nvmem/core.c
index 311cb2e5a5c0..4df7efde2cd2 100644
--- a/drivers/nvmem/core.c
+++ b/drivers/nvmem/core.c
@@ -1593,8 +1593,8 @@ void nvmem_cell_put(struct nvmem_cell *cell)
 		kfree_const(cell->id);
 
 	kfree(cell);
-	__nvmem_device_put(nvmem);
 	nvmem_layout_module_put(nvmem);
+	__nvmem_device_put(nvmem);
 }
 EXPORT_SYMBOL_GPL(nvmem_cell_put);
 
-- 
2.34.1


^ permalink raw reply	[flat|nested] 2+ messages in thread

end of thread, other threads:[~2026-09-18 21:27 UTC | newest]

Thread overview: 2+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-09-17 12:33 [PATCH] nvmem: core: Fix nvmem use-after-free in nvmem_cell_put() Wentao Liang
2026-09-18 21:27 ` Srinivas Kandagatla

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®