[PATCH] HID: amd_sfh: clear hid_sensor_hubs entry on probe failure

Chen Changcheng posted 1 patch 1 week, 3 days ago
drivers/hid/amd-sfh-hid/amd_sfh_hid.c | 1 +
1 file changed, 1 insertion(+)
[PATCH] HID: amd_sfh: clear hid_sensor_hubs entry on probe failure
Posted by Chen Changcheng 1 week, 3 days ago
In amdtp_hid_probe(), the newly allocated HID device is stored in
cli_data->hid_sensor_hubs[cur_hid_dev] before calling hid_add_device().
If hid_add_device() fails, the error path frees the HID device and its
driver_data but does not clear the array entry, leaving a dangling
pointer.

When the caller (amd_sfh_hid_client_init or
amd_sfh1_1_hid_client_init) detects the probe failure, it jumps to its
cleanup label, which unconditionally calls amd_sfh_hid_client_deinit()
and subsequently amdtp_hid_remove(). The latter iterates over all
hid_sensor_hubs[] entries and, upon encountering the non-NULL but freed
pointer, performs a use-after-free read followed by double-free of both
the HID device and its driver_data.

Clear the array entry in the error path of amdtp_hid_probe() so that
amdtp_hid_remove() skips the failed entry.

Signed-off-by: Chen Changcheng <chenchangcheng@kylinos.cn>
---
 drivers/hid/amd-sfh-hid/amd_sfh_hid.c | 1 +
 1 file changed, 1 insertion(+)

diff --git a/drivers/hid/amd-sfh-hid/amd_sfh_hid.c b/drivers/hid/amd-sfh-hid/amd_sfh_hid.c
index b04f675d49b0..9eaa2785a9ac 100644
--- a/drivers/hid/amd-sfh-hid/amd_sfh_hid.c
+++ b/drivers/hid/amd-sfh-hid/amd_sfh_hid.c
@@ -162,6 +162,7 @@ int amdtp_hid_probe(u32 cur_hid_dev, struct amdtp_cl_data *cli_data)
 	return 0;
 
 err_hid_device:
+	cli_data->hid_sensor_hubs[cur_hid_dev] = NULL;
 	kfree(hid_data);
 err_hid_data:
 	hid_destroy_device(hid);
-- 
2.25.1
Re: [PATCH] HID: amd_sfh: clear hid_sensor_hubs entry on probe failure
Posted by Basavaraj Natikar 1 week, 1 day ago
On 7/15/2026 3:16 PM, Chen Changcheng wrote:
> [You don't often get email from chenchangcheng@kylinos.cn. Learn why this is important at https://aka.ms/LearnAboutSenderIdentification ]
>
> In amdtp_hid_probe(), the newly allocated HID device is stored in
> cli_data->hid_sensor_hubs[cur_hid_dev] before calling hid_add_device().
> If hid_add_device() fails, the error path frees the HID device and its
> driver_data but does not clear the array entry, leaving a dangling
> pointer.
>
> When the caller (amd_sfh_hid_client_init or
> amd_sfh1_1_hid_client_init) detects the probe failure, it jumps to its
> cleanup label, which unconditionally calls amd_sfh_hid_client_deinit()
> and subsequently amdtp_hid_remove(). The latter iterates over all
> hid_sensor_hubs[] entries and, upon encountering the non-NULL but freed
> pointer, performs a use-after-free read followed by double-free of both
> the HID device and its driver_data.
>
> Clear the array entry in the error path of amdtp_hid_probe() so that
> amdtp_hid_remove() skips the failed entry.
>
> Signed-off-by: Chen Changcheng <chenchangcheng@kylinos.cn>
> ---
>   drivers/hid/amd-sfh-hid/amd_sfh_hid.c | 1 +
>   1 file changed, 1 insertion(+)
>
> diff --git a/drivers/hid/amd-sfh-hid/amd_sfh_hid.c b/drivers/hid/amd-sfh-hid/amd_sfh_hid.c
> index b04f675d49b0..9eaa2785a9ac 100644
> --- a/drivers/hid/amd-sfh-hid/amd_sfh_hid.c
> +++ b/drivers/hid/amd-sfh-hid/amd_sfh_hid.c
> @@ -162,6 +162,7 @@ int amdtp_hid_probe(u32 cur_hid_dev, struct amdtp_cl_data *cli_data)
>          return 0;
>
>   err_hid_device:
> +       cli_data->hid_sensor_hubs[cur_hid_dev] = NULL;

Acked-by: Basavaraj Natikar <Basavaraj.Natikar@amd.com>

Thanks,
--
Basavaraj

>          kfree(hid_data);
>   err_hid_data:
>          hid_destroy_device(hid);
> --
> 2.25.1
>