Thread (1 message) 1 message, 1 author, 2020-11-12

Re: [PATCH] rfkill: Fix use-after-free in rfkill_resume()

From: Johannes Berg <johannes@sipsolutions.net>
Date: 2020-11-12 08:18:24
Also in: linux-wireless, lkml

On Wed, 2020-11-11 at 11:23 +0800, Claire Chang wrote:
On Wed, Nov 11, 2020 at 1:35 AM Johannes Berg [off-list ref] wrote:
quoted
On Tue, 2020-11-10 at 16:49 +0800, Claire Chang wrote:
quoted
If a device is getting removed or reprobed during resume, use-after-free
might happen. For example, h5_btrtl_resume()[drivers/bluetooth/hci_h5.c]
schedules a work queue for device reprobing. During the reprobing, if
rfkill_set_block() in rfkill_resume() is called after the corresponding
*_unregister() and kfree() are called, there will be an use-after-free
in hci_rfkill_set_block()[net/bluetooth/hci_core.c].
Not sure I understand. So you're saying

 * something (h5_btrtl_resume) schedules a worker
 * said worker run, when it runs, calls rfkill_unregister()
 * somehow rfkill_resume() still gets called after this

But that can't really be right, device_del() removes it from the PM
lists?
If device_del() is called right before the device_lock() in device_resume()[1],
it's possible the rfkill device is unregistered, but rfkill_resume is
still called.
OK, I see, thanks for the clarification!

I'll try to add that to the commit message.

Thanks,
johannes
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help