From nobody Sun Sep 14 06:41:19 2025 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from vger.kernel.org (vger.kernel.org [23.128.96.18]) by smtp.lore.kernel.org (Postfix) with ESMTP id 5591DC38142 for ; Tue, 31 Jan 2023 13:09:15 +0000 (UTC) Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S232068AbjAaNJK (ORCPT ); Tue, 31 Jan 2023 08:09:10 -0500 Received: from lindbergh.monkeyblade.net ([23.128.96.19]:44730 "EHLO lindbergh.monkeyblade.net" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S232040AbjAaNJG (ORCPT ); Tue, 31 Jan 2023 08:09:06 -0500 Received: from mail-ej1-x635.google.com (mail-ej1-x635.google.com [IPv6:2a00:1450:4864:20::635]) by lindbergh.monkeyblade.net (Postfix) with ESMTPS id 0FA6C126D7 for ; Tue, 31 Jan 2023 05:09:03 -0800 (PST) Received: by mail-ej1-x635.google.com with SMTP id ud5so41449296ejc.4 for ; Tue, 31 Jan 2023 05:09:02 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=diag.uniroma1.it; s=google; h=cc:to:in-reply-to:references:message-id:content-transfer-encoding :mime-version:subject:date:from:from:to:cc:subject:date:message-id :reply-to; bh=uOYadJvP8u49K2x2oSYl+EYqiXssZ4idBGq/e4Tz9NY=; b=KDEKy6z9clzZ/yt+Ugm+vcRRWzEj90+XlSFk9eYXi6IC5nH1Ekl2y3Hm9QX1/VOyg6 KoU6Bt2QbVi12p9NEJGHVLQti9laMQw3q0XhRpn8RudSITu6ZnOGgKHs7nTwUuFy4XOk N1Lq/Rl18bZd0+9UEdChBzxmYVa5FEhjARYR8= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20210112; h=cc:to:in-reply-to:references:message-id:content-transfer-encoding :mime-version:subject:date:from:x-gm-message-state:from:to:cc :subject:date:message-id:reply-to; bh=uOYadJvP8u49K2x2oSYl+EYqiXssZ4idBGq/e4Tz9NY=; b=2XqWLvwh/vGR4VzPu7fC7Wg+Qp7UGeqyYRktVuGBK2ynmQgp418TLhd/H5mvVT81O9 j/NlXvoDU34ESipWPFwt4VA8xGX06LRzahRSvELaagQYWd4ccctbwOSJZo2hDVKe2Zyn +FEF1X4SY+p+5mZ2KjT6P3LPQ9qhmEt8ey1M+EtElJ7RO1yyINulXIVnDq2fREbnosRb 0H3uSZp1GR4WtOO0jfSb9SutRVOEVPsZjI2GZlrUCzPoI9EMH5BtmbcyqjmAc91uCDQs OkjzEZCO4/cweLlSyzKazXjSTF7Xua3E/4QvDNyakvVJxkgzzAJ1QxECyfK1S5UORPlQ 1sKA== X-Gm-Message-State: AO0yUKUAxBsEJLglinOPC5ZlpIBo6YIE2YKgORM2/qmCdYVH8vR7X9h7 OQ9RxfVtolZLGaoXjnDAP7Ofdg== X-Google-Smtp-Source: AK7set+TLo90zN/rggXs78IMqKvdRPq3UMM97//YKxvo/gz4hPVpUrCvA/s+uzGixpW4LfOqI22Pzg== X-Received: by 2002:a17:907:da1:b0:888:7ce4:1dc1 with SMTP id go33-20020a1709070da100b008887ce41dc1mr10015780ejc.26.1675170541590; Tue, 31 Jan 2023 05:09:01 -0800 (PST) Received: from [192.168.17.2] (wolkje-127.labs.vu.nl. [130.37.198.127]) by smtp.gmail.com with ESMTPSA id f19-20020a170906391300b0088452ca0666sm4898956eje.196.2023.01.31.05.09.00 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 31 Jan 2023 05:09:01 -0800 (PST) From: Pietro Borrello Date: Tue, 31 Jan 2023 13:08:45 +0000 Subject: [PATCH v2 1/5] HID: bigben_remove: manually unregister leds MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20230125-hid-unregister-leds-v2-1-689cc62fc878@diag.uniroma1.it> References: <20230125-hid-unregister-leds-v2-0-689cc62fc878@diag.uniroma1.it> In-Reply-To: <20230125-hid-unregister-leds-v2-0-689cc62fc878@diag.uniroma1.it> To: Jiri Kosina , Benjamin Tissoires , Hanno Zulla , Pavel Machek , Lee Jones , Roderick Colenbrander , Sven Eckelmann Cc: linux-leds@vger.kernel.org, Cristiano Giuffrida , "Bos, H.J." , Jakob Koschel , linux-input@vger.kernel.org, linux-kernel@vger.kernel.org, Jiri Kosina , Roderick Colenbrander , Pietro Borrello X-Mailer: b4 0.11.1 X-Developer-Signature: v=1; a=ed25519-sha256; t=1675170540; l=1037; i=borrello@diag.uniroma1.it; s=20221223; h=from:subject:message-id; bh=wlU1zbXd7qFTSbVqYvqS9BOVrqglVS3eHD1ePCtISHc=; b=1S4dFJ6YtEJ88InQZSjBIJqgxbqXt+T9JIgkqoLWq0NtwsubGN/Fl9VW6G07oKHBAzx9ClO/JaNt v2JlPGwtCuiFqrHoLk9QBHzG1Seo6N4LHcIZ7c4vooOoJ+dx5t6/ X-Developer-Key: i=borrello@diag.uniroma1.it; a=ed25519; pk=4xRQbiJKehl7dFvrG33o2HpveMrwQiUPKtIlObzKmdY= Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org Unregister the LED controllers before device removal, as bigben_set_led() may schedule bigben->worker after the structure has been freed, causing a use-after-free. Fixes: 4eb1b01de5b9 ("HID: hid-bigbenff: fix race condition for scheduled w= ork during removal") Signed-off-by: Pietro Borrello --- drivers/hid/hid-bigbenff.c | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/drivers/hid/hid-bigbenff.c b/drivers/hid/hid-bigbenff.c index e8b16665860d..d3201b755595 100644 --- a/drivers/hid/hid-bigbenff.c +++ b/drivers/hid/hid-bigbenff.c @@ -306,9 +306,14 @@ static enum led_brightness bigben_get_led(struct led_c= lassdev *led) =20 static void bigben_remove(struct hid_device *hid) { + int n; struct bigben_device *bigben =3D hid_get_drvdata(hid); =20 bigben->removed =3D true; + for (n =3D 0; n < NUM_LEDS; n++) { + if (bigben->leds[n]) + devm_led_classdev_unregister(&hid->dev, bigben->leds[n]); + } cancel_work_sync(&bigben->worker); hid_hw_stop(hid); } --=20 2.25.1 From nobody Sun Sep 14 06:41:19 2025 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from vger.kernel.org (vger.kernel.org [23.128.96.18]) by smtp.lore.kernel.org (Postfix) with ESMTP id 54BF2C38142 for ; Tue, 31 Jan 2023 13:09:21 +0000 (UTC) Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S232083AbjAaNJT (ORCPT ); Tue, 31 Jan 2023 08:09:19 -0500 Received: from lindbergh.monkeyblade.net ([23.128.96.19]:44730 "EHLO lindbergh.monkeyblade.net" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S232032AbjAaNJH (ORCPT ); Tue, 31 Jan 2023 08:09:07 -0500 Received: from mail-ej1-x62f.google.com (mail-ej1-x62f.google.com [IPv6:2a00:1450:4864:20::62f]) by lindbergh.monkeyblade.net (Postfix) with ESMTPS id CEBF072B2 for ; Tue, 31 Jan 2023 05:09:03 -0800 (PST) Received: by mail-ej1-x62f.google.com with SMTP id lu11so4094301ejb.3 for ; Tue, 31 Jan 2023 05:09:03 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=diag.uniroma1.it; s=google; h=cc:to:in-reply-to:references:message-id:content-transfer-encoding :mime-version:subject:date:from:from:to:cc:subject:date:message-id :reply-to; bh=OtVGZ8lsHwJ47yfcKnn1bRe6oeChLHMzfzZSc6Gf3Bk=; b=pA5e7TMvW7cwu+TT7l2Hls+dk56ZZZU4LdW2+MDQ1rJPyNuoyoaIIbboW9W2vfpw1x 5kNnqcCF5WcbT8fBUpvhAIq51qswfLSi6U1lqV9+SYOI3lJkdxs2B0me5bZCn6L47cx3 TPTHTQIUwNYyT2tDWfyXmMowMwebJsuaFs+h8= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20210112; h=cc:to:in-reply-to:references:message-id:content-transfer-encoding :mime-version:subject:date:from:x-gm-message-state:from:to:cc :subject:date:message-id:reply-to; bh=OtVGZ8lsHwJ47yfcKnn1bRe6oeChLHMzfzZSc6Gf3Bk=; b=eblRGsJLmrf/pFGiduxUNP0uQNvyGbDHYWwyEuvmcx6oWLyDOMTYI4MQ//kFe9bdwy s+WbEFPkNJXaUNoVCW82Vbu8DHTnxhqcetVz5ONMh656dNKYsRxZgBdkdlJOd2Yc16Fm JI4bgbTKFjm9GjM0lCjYZYvOusn9MFUQZaSY/CSNdogFAMF5feiM9rUiNmwTSaTd8Vav uBYyf2cpd4wzakYXRp4XDl0WdfG2udN84E5BYTqTIx+NyHGgQd6Edzp4AHq0NrT2Lgj2 a7t6euyfyUEdDzIrN89NyE5X9hwFMinaC2YHYE0VaYDVOLs1HHHpI1cJgmWHlAm8hXcE ve8g== X-Gm-Message-State: AO0yUKW3HaiMXoyBWD5Fz8mzYQNUWfZSF4qoDHeBC6x8wV92wQv2+A+6 R2cgLdwt2PVCdK4ofwn+iTSBTA== X-Google-Smtp-Source: AK7set/Cksul47Eq5LwKVVTkjIXAKGTG73njw/C2kmdOuQ3OLYqxIfQjR7bGvW2NKfHw496llf5C4w== X-Received: by 2002:a17:907:20b0:b0:87b:d376:b850 with SMTP id pw16-20020a17090720b000b0087bd376b850mr15363396ejb.10.1675170542167; Tue, 31 Jan 2023 05:09:02 -0800 (PST) Received: from [192.168.17.2] (wolkje-127.labs.vu.nl. [130.37.198.127]) by smtp.gmail.com with ESMTPSA id f19-20020a170906391300b0088452ca0666sm4898956eje.196.2023.01.31.05.09.01 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 31 Jan 2023 05:09:01 -0800 (PST) From: Pietro Borrello Date: Tue, 31 Jan 2023 13:08:46 +0000 Subject: [PATCH v2 2/5] HID: asus_remove: manually unregister led MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20230125-hid-unregister-leds-v2-2-689cc62fc878@diag.uniroma1.it> References: <20230125-hid-unregister-leds-v2-0-689cc62fc878@diag.uniroma1.it> In-Reply-To: <20230125-hid-unregister-leds-v2-0-689cc62fc878@diag.uniroma1.it> To: Jiri Kosina , Benjamin Tissoires , Hanno Zulla , Pavel Machek , Lee Jones , Roderick Colenbrander , Sven Eckelmann Cc: linux-leds@vger.kernel.org, Cristiano Giuffrida , "Bos, H.J." , Jakob Koschel , linux-input@vger.kernel.org, linux-kernel@vger.kernel.org, Jiri Kosina , Roderick Colenbrander , Pietro Borrello X-Mailer: b4 0.11.1 X-Developer-Signature: v=1; a=ed25519-sha256; t=1675170540; l=841; i=borrello@diag.uniroma1.it; s=20221223; h=from:subject:message-id; bh=6oFA70DnzD6hxYzPyFU4oYw2osDEjulwpyTezPO1v4g=; b=LzdPeS7nVFRpo8VU64kao203h0vMfO08dDdS4pMuCfp8K26oNi2WN4aYBXEv1EMMlBBQasjjEP2T c2hJTcoeAT73y7sOHiri1/kUbKWKBhOqOKL2ZerGBDgo+vBVjtga X-Developer-Key: i=borrello@diag.uniroma1.it; a=ed25519; pk=4xRQbiJKehl7dFvrG33o2HpveMrwQiUPKtIlObzKmdY= Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org Unregister the LED controller before device removal, as asus_kbd_backlight_set() may schedule led->work after the structure has been freed, causing a use-after-free. Fixes: af22a610bc38 ("HID: asus: support backlight on USB keyboards") Signed-off-by: Pietro Borrello --- drivers/hid/hid-asus.c | 1 + 1 file changed, 1 insertion(+) diff --git a/drivers/hid/hid-asus.c b/drivers/hid/hid-asus.c index f99752b998f3..0f274c8d1bef 100644 --- a/drivers/hid/hid-asus.c +++ b/drivers/hid/hid-asus.c @@ -1122,6 +1122,7 @@ static void asus_remove(struct hid_device *hdev) =20 if (drvdata->kbd_backlight) { drvdata->kbd_backlight->removed =3D true; + devm_led_classdev_unregister(&hdev->dev, &drvdata->kbd_backlight->cdev); cancel_work_sync(&drvdata->kbd_backlight->work); } =20 --=20 2.25.1 From nobody Sun Sep 14 06:41:19 2025 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from vger.kernel.org (vger.kernel.org [23.128.96.18]) by smtp.lore.kernel.org (Postfix) with ESMTP id 0C2C2C38142 for ; Tue, 31 Jan 2023 13:09:24 +0000 (UTC) Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S232093AbjAaNJW (ORCPT ); Tue, 31 Jan 2023 08:09:22 -0500 Received: from lindbergh.monkeyblade.net ([23.128.96.19]:44786 "EHLO lindbergh.monkeyblade.net" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S232051AbjAaNJH (ORCPT ); Tue, 31 Jan 2023 08:09:07 -0500 Received: from mail-ej1-x635.google.com (mail-ej1-x635.google.com [IPv6:2a00:1450:4864:20::635]) by lindbergh.monkeyblade.net (Postfix) with ESMTPS id 41DA6E395 for ; Tue, 31 Jan 2023 05:09:04 -0800 (PST) Received: by mail-ej1-x635.google.com with SMTP id ml19so17873261ejb.0 for ; Tue, 31 Jan 2023 05:09:04 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=diag.uniroma1.it; s=google; h=cc:to:in-reply-to:references:message-id:content-transfer-encoding :mime-version:subject:date:from:from:to:cc:subject:date:message-id :reply-to; bh=eVbivV8EGu+km89gAq7ikjZD9Nt9wLtDAtt21fJbyIE=; b=pJVMbn/vZRNaPQe0/Pfzxri/P1+RByqeFUJ9/umN+VsPxL3e3/bBzc6h668t114S/u sW0RQ1vPA/6lSs5n+Rn3J70dvTRtFZbVX8QiMjDTuDt7ZIOIuevWut63gXisf4/2autT pzVkokK1srC+UOM9kbemm2181pRPbr+c1pDBU= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20210112; h=cc:to:in-reply-to:references:message-id:content-transfer-encoding :mime-version:subject:date:from:x-gm-message-state:from:to:cc :subject:date:message-id:reply-to; bh=eVbivV8EGu+km89gAq7ikjZD9Nt9wLtDAtt21fJbyIE=; b=WcbC41YnoeWZaHKabiOgf+YIOu2uA2kHhEk01INv+8TDc80y57670mEpvXzpXhS0nZ WdZB5gx3qn/krTK4iCotzghGu7d4eN5sE95yd5fd7dUv3goQzcFRUQqC57SZAz7lO8R1 trYlySvaHhjxGzWvKLgTSR2B1NYrdlWIjGvaDvGjeBNvT7uT3y7xo6O8yepaj9mbJwqz +n1/Dah14Wt6BUoOIyq1o5cgPDlYeV6ANwtXyWZmjgK/wfLVRHtMcXx9S0ywo8oR7+cL bJSHEnLFzwLQoZZ2yd39Ll4JHwH13iAa94coZVN89PHOLLztqNX7TDgPDCiNy/CBFhJq /N5g== X-Gm-Message-State: AO0yUKWtWQ+3TCvJBzIyvmKFw2g7xKKN7Ik94cU/6Mss4xYCgx6u4Xjk 4bd6u/vO16w4tac+t9mqfTUalQ== X-Google-Smtp-Source: AK7set8/dsb0DwLaEBtLxuVxd2bPqNpGLBTx6byaW3iLpH0RJzEEdVF24gASNLKt0q4ByhBIplGh5g== X-Received: by 2002:a17:906:208b:b0:885:d02f:d4ad with SMTP id 11-20020a170906208b00b00885d02fd4admr12778878ejq.43.1675170542716; Tue, 31 Jan 2023 05:09:02 -0800 (PST) Received: from [192.168.17.2] (wolkje-127.labs.vu.nl. [130.37.198.127]) by smtp.gmail.com with ESMTPSA id f19-20020a170906391300b0088452ca0666sm4898956eje.196.2023.01.31.05.09.02 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 31 Jan 2023 05:09:02 -0800 (PST) From: Pietro Borrello Date: Tue, 31 Jan 2023 13:08:47 +0000 Subject: [PATCH v2 3/5] HID: dualsense_remove: manually unregister leds MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20230125-hid-unregister-leds-v2-3-689cc62fc878@diag.uniroma1.it> References: <20230125-hid-unregister-leds-v2-0-689cc62fc878@diag.uniroma1.it> In-Reply-To: <20230125-hid-unregister-leds-v2-0-689cc62fc878@diag.uniroma1.it> To: Jiri Kosina , Benjamin Tissoires , Hanno Zulla , Pavel Machek , Lee Jones , Roderick Colenbrander , Sven Eckelmann Cc: linux-leds@vger.kernel.org, Cristiano Giuffrida , "Bos, H.J." , Jakob Koschel , linux-input@vger.kernel.org, linux-kernel@vger.kernel.org, Jiri Kosina , Roderick Colenbrander , Pietro Borrello X-Mailer: b4 0.11.1 X-Developer-Signature: v=1; a=ed25519-sha256; t=1675170540; l=1556; i=borrello@diag.uniroma1.it; s=20221223; h=from:subject:message-id; bh=I/aK9DcIPRri1R7+BoQmPFot08oQLGwMbJpqlNV1B8M=; b=5sp2HxZcrnV1R0s9GQ65lRPDmAjbbTrzRLu2QOtJ2rZ+CPXfd6lM34SYzoZQTTz5wcKpPq3+C4Rz xTnnHicND5nqprX0be6N1UIrfJQbhy+wplZo58FC2enoRBiPpDC4 X-Developer-Key: i=borrello@diag.uniroma1.it; a=ed25519; pk=4xRQbiJKehl7dFvrG33o2HpveMrwQiUPKtIlObzKmdY= Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org Unregister the LED controllers before device removal, to prevent unnecessary runs of dualsense_player_led_set_brightness(). Fixes: 8c0ab553b072 ("HID: playstation: expose DualSense player LEDs throug= h LED class.") Signed-off-by: Pietro Borrello --- Contrary to the other patches in this series, failing to unregister the led controller does not results into a use-after-free thanks to the output_worker_initialized variable and the spinlock checks. Changes in v2: - Unregister multicolor led controller - Clarify UAF - Link to v1: https://lore.kernel.org/all/20230125-hid-unregister-leds-v1-3= -9a5192dcef16@diag.uniroma1.it/ --- drivers/hid/hid-playstation.c | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/drivers/hid/hid-playstation.c b/drivers/hid/hid-playstation.c index 27c40894acab..f23186ca2d76 100644 --- a/drivers/hid/hid-playstation.c +++ b/drivers/hid/hid-playstation.c @@ -1503,11 +1503,17 @@ static void dualsense_remove(struct ps_device *ps_d= ev) { struct dualsense *ds =3D container_of(ps_dev, struct dualsense, base); unsigned long flags; + int i; =20 spin_lock_irqsave(&ds->base.lock, flags); ds->output_worker_initialized =3D false; spin_unlock_irqrestore(&ds->base.lock, flags); =20 + for (i =3D 0; i < ARRAY_SIZE(ds->player_leds); i++) + devm_led_classdev_unregister(&ps_dev->hdev->dev, &ds->player_leds[i]); + + devm_led_classdev_multicolor_unregister(&ps_dev->hdev->dev, &ds->lightbar= ); + cancel_work_sync(&ds->output_worker); } =20 --=20 2.25.1 From nobody Sun Sep 14 06:41:19 2025 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from vger.kernel.org (vger.kernel.org [23.128.96.18]) by smtp.lore.kernel.org (Postfix) with ESMTP id CAAD1C636CC for ; Tue, 31 Jan 2023 13:09:31 +0000 (UTC) Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S232153AbjAaNJa (ORCPT ); Tue, 31 Jan 2023 08:09:30 -0500 Received: from lindbergh.monkeyblade.net ([23.128.96.19]:45502 "EHLO lindbergh.monkeyblade.net" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S232095AbjAaNJZ (ORCPT ); Tue, 31 Jan 2023 08:09:25 -0500 Received: from mail-ed1-x534.google.com (mail-ed1-x534.google.com [IPv6:2a00:1450:4864:20::534]) by lindbergh.monkeyblade.net (Postfix) with ESMTPS id BA45A4ED32 for ; Tue, 31 Jan 2023 05:09:04 -0800 (PST) Received: by mail-ed1-x534.google.com with SMTP id z11so14360514ede.1 for ; Tue, 31 Jan 2023 05:09:04 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=diag.uniroma1.it; s=google; h=cc:to:in-reply-to:references:message-id:content-transfer-encoding :mime-version:subject:date:from:from:to:cc:subject:date:message-id :reply-to; bh=Q79upilYUaTabLjtO3bZo14lYpmZpgLc63/mP4eG9WA=; b=Jiv6RUxvmV3Ufd8uoYWmd1situOGY4NhVV6W3e8iX/gSnI5hNoydnRNmL6pvCh8dSp 8eGfWvxqWz8zd3of7EcGBXL41UT07GSlYrxg5SjhiHyP+oXMvTPrRuVAlouhz4+y9We6 18ytUHl0u33LcDQGVwMctqXQbHTO04YiVQkmc= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20210112; h=cc:to:in-reply-to:references:message-id:content-transfer-encoding :mime-version:subject:date:from:x-gm-message-state:from:to:cc :subject:date:message-id:reply-to; bh=Q79upilYUaTabLjtO3bZo14lYpmZpgLc63/mP4eG9WA=; b=CY9j+m3ogqoyNq7FcmM3CJe1PZEfKYgyZYzPBIZQmPOvA3x1r7TkNZcrv3mze1NmUJ e2F4V58HITStch+7/FZDnIvpvN3vhT2RxeU+TNu3kqjAJKsXHi6MPDZycX9z+cVBMNSe BRqqO9tqSfNP2QuQmg2pYJt/hZcmFEBB1W8jDzkVODRflI/ix6CV1nd1sPv1iZ+/kTfq RoOtihNSNXQkGD7hjrLXWTJzBzJHdpmz2E+Qpk8jGAotOg6hYR9QPbplAs2jSXoQenW+ biAC4k+odQS221BAiHLQGFIiW5DYjBwM0MjtXjEg6NP7d3znapWVVigDQtGJbdxFvcSq kFpg== X-Gm-Message-State: AFqh2krtgg2b0yTA4uvhSGbtfeffjfZ7X18XMehYS8NOJLhZuZZn7UNa NpW1jDx0w46AfvFEqqtTZJWgSQ== X-Google-Smtp-Source: AMrXdXtiGqkeWKlRDAoIO4sROri5jyb0nQOOYcVpEPXewNUDAsDU6bDYl4l7r4L+LJVAOmVrweQMoA== X-Received: by 2002:aa7:c052:0:b0:475:dddc:374a with SMTP id k18-20020aa7c052000000b00475dddc374amr56004206edo.18.1675170543237; Tue, 31 Jan 2023 05:09:03 -0800 (PST) Received: from [192.168.17.2] (wolkje-127.labs.vu.nl. [130.37.198.127]) by smtp.gmail.com with ESMTPSA id f19-20020a170906391300b0088452ca0666sm4898956eje.196.2023.01.31.05.09.02 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 31 Jan 2023 05:09:02 -0800 (PST) From: Pietro Borrello Date: Tue, 31 Jan 2023 13:08:48 +0000 Subject: [PATCH v2 4/5] HID: dualshock4_remove: manually unregister leds MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20230125-hid-unregister-leds-v2-4-689cc62fc878@diag.uniroma1.it> References: <20230125-hid-unregister-leds-v2-0-689cc62fc878@diag.uniroma1.it> In-Reply-To: <20230125-hid-unregister-leds-v2-0-689cc62fc878@diag.uniroma1.it> To: Jiri Kosina , Benjamin Tissoires , Hanno Zulla , Pavel Machek , Lee Jones , Roderick Colenbrander , Sven Eckelmann Cc: linux-leds@vger.kernel.org, Cristiano Giuffrida , "Bos, H.J." , Jakob Koschel , linux-input@vger.kernel.org, linux-kernel@vger.kernel.org, Jiri Kosina , Roderick Colenbrander , Pietro Borrello X-Mailer: b4 0.11.1 X-Developer-Signature: v=1; a=ed25519-sha256; t=1675170540; l=1491; i=borrello@diag.uniroma1.it; s=20221223; h=from:subject:message-id; bh=VPrVVBqqogjSwkjTCQxGFur+jXJWf031MbQaC/naVuk=; b=a5Fi08feBch0WK2QkEw6jb2k0YeWIxIy0TOvIlH4YFQDjzx5YCPMMBiXJ+X1wwE3U5mdz9JHAVyg S53Yt4moDbGRX18ytJbn1h1YkW4eu7pgIyCWWt7/3d1Y4VCSvbfP X-Developer-Key: i=borrello@diag.uniroma1.it; a=ed25519; pk=4xRQbiJKehl7dFvrG33o2HpveMrwQiUPKtIlObzKmdY= Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org Unregister the LED controllers before device removal, to prevent unnecessary runs of dualshock4_led_set_brightness(). Fixes: 4521109a8f40 ("HID: playstation: support DualShock4 lightbar.") Signed-off-by: Pietro Borrello --- Contrary to the other patches in this series, failing to unregister the led controller does not results into a use-after-free thanks to the output_worker_initialized variable and the spinlock checks. Changes in v2: - Clarify UAF - Link to v1: https://lore.kernel.org/all/20230125-hid-unregister-leds-v1-4= -9a5192dcef16@diag.uniroma1.it/ --- drivers/hid/hid-playstation.c | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/drivers/hid/hid-playstation.c b/drivers/hid/hid-playstation.c index f23186ca2d76..b41657842e26 100644 --- a/drivers/hid/hid-playstation.c +++ b/drivers/hid/hid-playstation.c @@ -2434,11 +2434,15 @@ static void dualshock4_remove(struct ps_device *ps_= dev) { struct dualshock4 *ds4 =3D container_of(ps_dev, struct dualshock4, base); unsigned long flags; + int i; =20 spin_lock_irqsave(&ds4->base.lock, flags); ds4->output_worker_initialized =3D false; spin_unlock_irqrestore(&ds4->base.lock, flags); =20 + for (i =3D 0; i < ARRAY_SIZE(ds4->lightbar_leds); i++) + devm_led_classdev_unregister(&ps_dev->hdev->dev, &ds4->lightbar_leds[i]); + cancel_work_sync(&ds4->output_worker); =20 if (ps_dev->hdev->product =3D=3D USB_DEVICE_ID_SONY_PS4_CONTROLLER_DONGLE) --=20 2.25.1 From nobody Sun Sep 14 06:41:19 2025 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from vger.kernel.org (vger.kernel.org [23.128.96.18]) by smtp.lore.kernel.org (Postfix) with ESMTP id 593C8C636CC for ; Tue, 31 Jan 2023 13:09:34 +0000 (UTC) Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S232164AbjAaNJc (ORCPT ); Tue, 31 Jan 2023 08:09:32 -0500 Received: from lindbergh.monkeyblade.net ([23.128.96.19]:44728 "EHLO lindbergh.monkeyblade.net" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S232022AbjAaNJZ (ORCPT ); Tue, 31 Jan 2023 08:09:25 -0500 Received: from mail-ej1-x633.google.com (mail-ej1-x633.google.com [IPv6:2a00:1450:4864:20::633]) by lindbergh.monkeyblade.net (Postfix) with ESMTPS id 689304F359 for ; Tue, 31 Jan 2023 05:09:05 -0800 (PST) Received: by mail-ej1-x633.google.com with SMTP id mf7so22699407ejc.6 for ; Tue, 31 Jan 2023 05:09:05 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=diag.uniroma1.it; s=google; h=cc:to:in-reply-to:references:message-id:content-transfer-encoding :mime-version:subject:date:from:from:to:cc:subject:date:message-id :reply-to; bh=nSLU5NXnF595gyXxeWDSi1UUOJiT0ePoBW3kFPldqJg=; b=TgjBsUPIIAq4tN9feRGWSXFsbMEDj58nrNmhPLcm8UYtMOHOp4/0TGiQxOfrEr5e1R IjpmRHyrmvjbBOn01c4NOZnltIE5kHzrr4/H5ipgdZvT1HfDziI25QxWLil3DqTlYXbc SUELTdzKzqxqmohf9wyt67/3HN3HQX2YnoJUs= X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20210112; h=cc:to:in-reply-to:references:message-id:content-transfer-encoding :mime-version:subject:date:from:x-gm-message-state:from:to:cc :subject:date:message-id:reply-to; bh=nSLU5NXnF595gyXxeWDSi1UUOJiT0ePoBW3kFPldqJg=; b=QWbulO6NjJ+yxnSqo1ZU4IGJaUpvcyucGtPPrdEnwI5APUNkPge6CDHcx4VmxrPVaz QAhjRjRJgKhOuqhsx2bxmF2RsY1U7ihBMowI0bro6KNTwhud9loub/+KnCWN8aAa47J9 sELFoG+SF43Rv3yhtEReeMcGk/Y2ycQ2djqKHmeltGiXx56HqDuZ8EAoLvATXHaTgxmt ZJMuw29YzDnY0YrVYBJiDgbly6jBqGIMd3zxulvoUSQ7Mvrkc+2jwOI8Fz0ofSEq+QyN EiU6cNVXVcLoMaRYMR62QOsrT1StsMj5wzSkpcVfmYK8UIXszd6MhLF+CpEc3yzHKx0U 82MA== X-Gm-Message-State: AFqh2kqFz6Ss9jwBTvPAn2dbTuL631UTSFWFN8ObVXAeZHIWqviRiEBt BJ5bDkkjt2exsguThvP6Eo0fcQ== X-Google-Smtp-Source: AMrXdXuJ9cWrU1GrTo9lhXJQpnCgMCNtO38vDPa2itSyQ5DYq1ObFWX83kJ8A2Kg/awK6/VUMpmpYg== X-Received: by 2002:a17:906:6846:b0:84d:2fdf:a41b with SMTP id a6-20020a170906684600b0084d2fdfa41bmr54522936ejs.50.1675170543813; Tue, 31 Jan 2023 05:09:03 -0800 (PST) Received: from [192.168.17.2] (wolkje-127.labs.vu.nl. [130.37.198.127]) by smtp.gmail.com with ESMTPSA id f19-20020a170906391300b0088452ca0666sm4898956eje.196.2023.01.31.05.09.03 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 31 Jan 2023 05:09:03 -0800 (PST) From: Pietro Borrello Date: Tue, 31 Jan 2023 13:08:49 +0000 Subject: [PATCH v2 5/5] HID: sony_remove: manually unregister leds MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20230125-hid-unregister-leds-v2-5-689cc62fc878@diag.uniroma1.it> References: <20230125-hid-unregister-leds-v2-0-689cc62fc878@diag.uniroma1.it> In-Reply-To: <20230125-hid-unregister-leds-v2-0-689cc62fc878@diag.uniroma1.it> To: Jiri Kosina , Benjamin Tissoires , Hanno Zulla , Pavel Machek , Lee Jones , Roderick Colenbrander , Sven Eckelmann Cc: linux-leds@vger.kernel.org, Cristiano Giuffrida , "Bos, H.J." , Jakob Koschel , linux-input@vger.kernel.org, linux-kernel@vger.kernel.org, Jiri Kosina , Roderick Colenbrander , Pietro Borrello X-Mailer: b4 0.11.1 X-Developer-Signature: v=1; a=ed25519-sha256; t=1675170540; l=1360; i=borrello@diag.uniroma1.it; s=20221223; h=from:subject:message-id; bh=229FyOXnrqPun6wciRAitLA27itC/9x6aEmACwn1+hs=; b=8Ck9ho6y0MkvQj3h5QlnwTwQENcRw2KZSkxXIkbaRHd+HTbXacBdbpF7ABf3bbxtN28DrLjQFpZW TSYqKYoFCrzdxPZgCRpFzFuRuSjrIes+qSrrPtSh6ehgPH3grT0O X-Developer-Key: i=borrello@diag.uniroma1.it; a=ed25519; pk=4xRQbiJKehl7dFvrG33o2HpveMrwQiUPKtIlObzKmdY= Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org Unregister the LED controller before device removal, as sony_led_set_brightness() may schedule sc->state_worker after the structure has been freed, causing a use-after-free. Fixes: 0a286ef27852 ("HID: sony: Add LED support for Sixaxis/Dualshock3 USB= ") Signed-off-by: Pietro Borrello Reviewed-by: Sven Eckelmann --- drivers/hid/hid-sony.c | 8 ++++++++ 1 file changed, 8 insertions(+) diff --git a/drivers/hid/hid-sony.c b/drivers/hid/hid-sony.c index 13125997ab5e..146677c8319c 100644 --- a/drivers/hid/hid-sony.c +++ b/drivers/hid/hid-sony.c @@ -3083,6 +3083,7 @@ static int sony_probe(struct hid_device *hdev, const = struct hid_device_id *id) static void sony_remove(struct hid_device *hdev) { struct sony_sc *sc =3D hid_get_drvdata(hdev); + int n; =20 if (sc->quirks & (GHL_GUITAR_PS3WIIU | GHL_GUITAR_PS4)) { del_timer_sync(&sc->ghl_poke_timer); @@ -3100,6 +3101,13 @@ static void sony_remove(struct hid_device *hdev) if (sc->hw_version_created) device_remove_file(&sc->hdev->dev, &dev_attr_hardware_version); =20 + if (sc->quirks & SONY_LED_SUPPORT) { + for (n =3D 0; n < sc->led_count; n++) { + if (sc->leds[n]) + devm_led_classdev_unregister(&hdev->dev, sc->leds[n]); + } + } + sony_cancel_work_sync(sc); =20 sony_remove_dev_list(sc); --=20 2.25.1