drivers/hid/amd-sfh-hid/amd_sfh_hid.c | 1 + 1 file changed, 1 insertion(+)
In amdtp_hid_probe(), the newly allocated HID device is stored in
cli_data->hid_sensor_hubs[cur_hid_dev] before calling hid_add_device().
If hid_add_device() fails, the error path frees the HID device and its
driver_data but does not clear the array entry, leaving a dangling
pointer.
When the caller (amd_sfh_hid_client_init or
amd_sfh1_1_hid_client_init) detects the probe failure, it jumps to its
cleanup label, which unconditionally calls amd_sfh_hid_client_deinit()
and subsequently amdtp_hid_remove(). The latter iterates over all
hid_sensor_hubs[] entries and, upon encountering the non-NULL but freed
pointer, performs a use-after-free read followed by double-free of both
the HID device and its driver_data.
Clear the array entry in the error path of amdtp_hid_probe() so that
amdtp_hid_remove() skips the failed entry.
Signed-off-by: Chen Changcheng <chenchangcheng@kylinos.cn>
---
drivers/hid/amd-sfh-hid/amd_sfh_hid.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/drivers/hid/amd-sfh-hid/amd_sfh_hid.c b/drivers/hid/amd-sfh-hid/amd_sfh_hid.c
index b04f675d49b0..9eaa2785a9ac 100644
--- a/drivers/hid/amd-sfh-hid/amd_sfh_hid.c
+++ b/drivers/hid/amd-sfh-hid/amd_sfh_hid.c
@@ -162,6 +162,7 @@ int amdtp_hid_probe(u32 cur_hid_dev, struct amdtp_cl_data *cli_data)
return 0;
err_hid_device:
+ cli_data->hid_sensor_hubs[cur_hid_dev] = NULL;
kfree(hid_data);
err_hid_data:
hid_destroy_device(hid);
--
2.25.1
On 7/15/2026 3:16 PM, Chen Changcheng wrote: > [You don't often get email from chenchangcheng@kylinos.cn. Learn why this is important at https://aka.ms/LearnAboutSenderIdentification ] > > In amdtp_hid_probe(), the newly allocated HID device is stored in > cli_data->hid_sensor_hubs[cur_hid_dev] before calling hid_add_device(). > If hid_add_device() fails, the error path frees the HID device and its > driver_data but does not clear the array entry, leaving a dangling > pointer. > > When the caller (amd_sfh_hid_client_init or > amd_sfh1_1_hid_client_init) detects the probe failure, it jumps to its > cleanup label, which unconditionally calls amd_sfh_hid_client_deinit() > and subsequently amdtp_hid_remove(). The latter iterates over all > hid_sensor_hubs[] entries and, upon encountering the non-NULL but freed > pointer, performs a use-after-free read followed by double-free of both > the HID device and its driver_data. > > Clear the array entry in the error path of amdtp_hid_probe() so that > amdtp_hid_remove() skips the failed entry. > > Signed-off-by: Chen Changcheng <chenchangcheng@kylinos.cn> > --- > drivers/hid/amd-sfh-hid/amd_sfh_hid.c | 1 + > 1 file changed, 1 insertion(+) > > diff --git a/drivers/hid/amd-sfh-hid/amd_sfh_hid.c b/drivers/hid/amd-sfh-hid/amd_sfh_hid.c > index b04f675d49b0..9eaa2785a9ac 100644 > --- a/drivers/hid/amd-sfh-hid/amd_sfh_hid.c > +++ b/drivers/hid/amd-sfh-hid/amd_sfh_hid.c > @@ -162,6 +162,7 @@ int amdtp_hid_probe(u32 cur_hid_dev, struct amdtp_cl_data *cli_data) > return 0; > > err_hid_device: > + cli_data->hid_sensor_hubs[cur_hid_dev] = NULL; Acked-by: Basavaraj Natikar <Basavaraj.Natikar@amd.com> Thanks, -- Basavaraj > kfree(hid_data); > err_hid_data: > hid_destroy_device(hid); > -- > 2.25.1 >
© 2016 - 2026 Red Hat, Inc.