Received: by 2002:a05:7412:3784:b0:e2:908c:2ebd with SMTP id jk4csp627034rdb; Sat, 30 Sep 2023 20:55:37 -0700 (PDT) X-Google-Smtp-Source: AGHT+IFEtMxSmXCCnlTTRTkI619z3bEQAKz0fCydEHzcKkMQR5BicYlS728x+3H7eqacfNkZNfMO X-Received: by 2002:a05:6358:41a7:b0:142:d04e:59f0 with SMTP id w39-20020a05635841a700b00142d04e59f0mr9399362rwc.14.1696132537363; Sat, 30 Sep 2023 20:55:37 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1696132537; cv=none; d=google.com; s=arc-20160816; b=HiUoNcju6LNkDCAz1XrWpS78rXnxca94q24Fcp1pCIH9rI6Qgf5cS3s3nZcnvqt9TI MjlNCbkFzfb4GrSELQIN2GazB80c3zgArj4yGG/ZU6oUhZ6gTeTkFUiUWCWMJ8LNsPBO pTXyJKPLpzgwNlIUNlnvLbqn0Z1zmeb78b1gKaB+4J1OHHAa7HlJPklxRMFYaECEaTDZ MOi2z2TRi7DB5H/RQlpjl94BYeseKha27i3zx0vaFxYAI90O79xoRQzL0Sk6tCZLV2NX wy8qNhXef/bQuJ7FWoFLPG2QOst8qJ6Bj1sstM80gpcgkmzaPb8yNaudVQE278f/q4Mj i+sg== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:message-id:date:subject:cc:to:from; bh=Xzs2SNdmGM5g+p2xFaUqQ23aqNgfrEXqVlGl5dw6RSw=; fh=9Do3J5DCMekVW+rSTggqgvkKv731sH7QbHMhmuznXtE=; b=XixLHO9V9XCfIEeKM9A0rScqNdsqvfyDES3YbLUp/FQ7TSJ8hUMwbeLd3fr/Gl4eDF 0Fjk6Y2BBtanR+Huqwi4l3Y9Ataxil9+NzTDR5fq+KtKrN+cfEc+CwhjBNKWb8CFezUf 4bXH1ugW48vbljmZXKkcnoXXbWH+VtcyzJHEUM3CmXVCYWW16p/e/urFc3DGRMAD6ye4 pa7t8CrCe4TWdKLb9lMYruRPJXrEl4UUa09gEYJ8q5kCcl6Y7j2xmii8ryGgiEz7RlZp /n2gaK1y5y+3YtjFaon7HjJJpcVetXrsaEZWiKKCIN+i2oyvYRdfC9uoPJa13N2S9F19 ZxvQ== ARC-Authentication-Results: i=1; mx.google.com; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 23.128.96.36 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org Return-Path: Received: from pete.vger.email (pete.vger.email. [23.128.96.36]) by mx.google.com with ESMTPS id s6-20020a17090a6e4600b002777ccd05bcsi4794269pjm.25.2023.09.30.20.55.36 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sat, 30 Sep 2023 20:55:37 -0700 (PDT) Received-SPF: pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 23.128.96.36 as permitted sender) client-ip=23.128.96.36; Authentication-Results: mx.google.com; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 23.128.96.36 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org Received: from out1.vger.email (depot.vger.email [IPv6:2620:137:e000::3:0]) by pete.vger.email (Postfix) with ESMTP id C70848118761; Sat, 30 Sep 2023 20:55:34 -0700 (PDT) X-Virus-Status: Clean X-Virus-Scanned: clamav-milter 0.103.10 at pete.vger.email Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S231430AbjJADzQ (ORCPT + 99 others); Sat, 30 Sep 2023 23:55:16 -0400 Received: from lindbergh.monkeyblade.net ([23.128.96.19]:42428 "EHLO lindbergh.monkeyblade.net" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S229461AbjJADzO (ORCPT ); Sat, 30 Sep 2023 23:55:14 -0400 Received: from zju.edu.cn (mail.zju.edu.cn [61.164.42.155]) by lindbergh.monkeyblade.net (Postfix) with ESMTP id ED4CADD; Sat, 30 Sep 2023 20:55:09 -0700 (PDT) Received: from localhost.localdomain (unknown [10.192.195.11]) by mail-app3 (Coremail) with SMTP id cC_KCgBXPcCC7RhlwbwsAQ--.29716S4; Sun, 01 Oct 2023 11:54:48 +0800 (CST) From: Dinghao Liu To: dinghao.liu@zju.edu.cn Cc: Toan Le , Lorenzo Pieralisi , =?UTF-8?q?Krzysztof=20Wilczy=C5=84ski?= , Rob Herring , Bjorn Helgaas , Tanmay Inamdar , Marc Zyngier , Duc Dang , linux-pci@vger.kernel.org, linux-arm-kernel@lists.infradead.org, linux-kernel@vger.kernel.org Subject: [PATCH] [v3] PCI: xgene-msi: Fix a potential UAF in xgene_msi_probe Date: Sun, 1 Oct 2023 11:54:40 +0800 Message-Id: <20231001035441.30408-1-dinghao.liu@zju.edu.cn> X-Mailer: git-send-email 2.17.1 X-CM-TRANSID: cC_KCgBXPcCC7RhlwbwsAQ--.29716S4 X-Coremail-Antispam: 1UD129KBjvJXoW7JF13Cr4xXr15WF13Gr18uFg_yoW8JrWDpF WxCw13WFWft3yUXa1Igw18Wa4aya9rt3yDtwsxWrnrZrnxC34DuryjqFy5C34akFWrXr4j y3WxJF15uFs5JFDanT9S1TB71UUUUUUqnTZGkaVYY2UrUUUUjbIjqfuFe4nvWSU5nxnvy2 9KBjDU0xBIdaVrnRJUUUvm1xkIjI8I6I8E6xAIw20EY4v20xvaj40_Wr0E3s1l1IIY67AE w4v_Jr0_Jr4l8cAvFVAK0II2c7xJM28CjxkF64kEwVA0rcxSw2x7M28EF7xvwVC0I7IYx2 IY67AKxVW7JVWDJwA2z4x0Y4vE2Ix0cI8IcVCY1x0267AKxVWxJVW8Jr1l84ACjcxK6I8E 87Iv67AKxVW0oVCq3wA2z4x0Y4vEx4A2jsIEc7CjxVAFwI0_GcCE3s1le2I262IYc4CY6c 8Ij28IcVAaY2xG8wAqx4xG64xvF2IEw4CE5I8CrVC2j2WlYx0E2Ix0cI8IcVAFwI0_Jr0_ Jr4lYx0Ex4A2jsIE14v26r1j6r4UMcvjeVCFs4IE7xkEbVWUJVW8JwACjcxG0xvY0x0EwI xGrwACjI8F5VA0II8E6IAqYI8I648v4I1lFIxGxcIEc7CjxVA2Y2ka0xkIwI1l42xK82IY c2Ij64vIr41l42xK82IY6x8ErcxFaVAv8VW8uw4UJr1UMxC20s026xCaFVCjc4AY6r1j6r 4UMI8I3I0E5I8CrVAFwI0_Jr0_Jr4lx2IqxVCjr7xvwVAFwI0_JrI_JrWlx4CE17CEb7AF 67AKxVWUtVW8ZwCIc40Y0x0EwIxGrwCI42IY6xIIjxv20xvE14v26r1j6r1xMIIF0xvE2I x0cI8IcVCY1x0267AKxVW8JVWxJwCI42IY6xAIw20EY4v20xvaj40_Jr0_JF4lIxAIcVC2 z280aVAFwI0_Jr0_Gr1lIxAIcVC2z280aVCY1x0267AKxVW8JVW8JrUvcSsGvfC2KfnxnU UI43ZEXa7VUbXdbUUUUUU== X-CM-SenderInfo: qrrzjiaqtzq6lmxovvfxof0/1tbiAgwPBmUYLyEI2AAAsk X-Spam-Status: No, score=-0.8 required=5.0 tests=HEADER_FROM_DIFFERENT_DOMAINS, MAILING_LIST_MULTI,SPF_HELO_NONE,SPF_PASS autolearn=unavailable autolearn_force=no version=3.4.6 X-Spam-Checker-Version: SpamAssassin 3.4.6 (2021-04-09) on pete.vger.email Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org X-Greylist: Sender passed SPF test, not delayed by milter-greylist-4.6.4 (pete.vger.email [0.0.0.0]); Sat, 30 Sep 2023 20:55:35 -0700 (PDT) xgene_allocate_domains() will call irq_domain_remove() to free msi->inner_domain on failure. However, its caller, xgene_msi_probe(), will also call irq_domain_remove() through xgene_msi_remove() on the same failure, which may lead to a use-after-free. Remove the first irq_domain_remove() and let xgene_free_domains() cleanup domains. Fixes: dcd19de36775 ("PCI: xgene: Add APM X-Gene v1 PCIe MSI/MSIX termination driver") Signed-off-by: Dinghao Liu --- Changelog: v2: -Remove irq_domain_remove() instead of nulling msi_domain. v3: -Add 'v3' tag in the title. --- drivers/pci/controller/pci-xgene-msi.c | 4 +--- 1 file changed, 1 insertion(+), 3 deletions(-) diff --git a/drivers/pci/controller/pci-xgene-msi.c b/drivers/pci/controller/pci-xgene-msi.c index 3ce38dfd0d29..0f9b9394399d 100644 --- a/drivers/pci/controller/pci-xgene-msi.c +++ b/drivers/pci/controller/pci-xgene-msi.c @@ -251,10 +251,8 @@ static int xgene_allocate_domains(struct xgene_msi *msi) &xgene_msi_domain_info, msi->inner_domain); - if (!msi->msi_domain) { - irq_domain_remove(msi->inner_domain); + if (!msi->msi_domain) return -ENOMEM; - } return 0; } -- 2.17.1