drivers/pci/p2pdma.c | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-)
In pci_p2pdma_add_resource(), a devm action is registered to call
pci_p2pdma_unmap_mappings() with the 'p2p_pgmap' context. If the subsequent
call to gen_pool_add_owner() fails, the code jumps to the 'pages_free'
error path.
In this error path, 'p2p_pgmap' is explicitly freed via devm_kfree().
However, the previously registered devm action is never removed. This
leaves a dangling pointer in the device's devres list. When the device
is unbound and devres is cleaning up resources, the unmap action will be
called with the already-freed 'p2p_pgmap', resulting in a use-after-free
bug.
Fix this by properly calling devm_remove_action() in the error path before
freeing 'p2p_pgmap'.
Fixes: 7e9c7ef83d78 ("PCI/P2PDMA: Allow userspace VMA allocations through sysfs")
Assisted-by: Antigravity:Gemini [tools]
Signed-off-by: leixiang <leixiang@kylinos.cn>
---
drivers/pci/p2pdma.c | 4 +++-
1 file changed, 3 insertions(+), 1 deletion(-)
diff --git a/drivers/pci/p2pdma.c b/drivers/pci/p2pdma.c
index b2d5266f8653..7f54532932ab 100644
--- a/drivers/pci/p2pdma.c
+++ b/drivers/pci/p2pdma.c
@@ -451,13 +451,15 @@ int pci_p2pdma_add_resource(struct pci_dev *pdev, int bar, size_t size,
range_len(&pgmap->range), dev_to_node(&pdev->dev),
&pgmap->ref);
if (error)
- goto pages_free;
+ goto unmap_mappings;
pci_info(pdev, "added peer-to-peer DMA memory %#llx-%#llx\n",
pgmap->range.start, pgmap->range.end);
return 0;
+unmap_mappings:
+ devm_remove_action(&pdev->dev, pci_p2pdma_unmap_mappings, p2p_pgmap);
pages_free:
devm_memunmap_pages(&pdev->dev, pgmap);
pgmap_free:
--
2.43.0
On Fri, Jul 17, 2026 at 05:51:17PM +0800, leixiang wrote:
> In pci_p2pdma_add_resource(), a devm action is registered to call
> pci_p2pdma_unmap_mappings() with the 'p2p_pgmap' context. If the subsequent
> call to gen_pool_add_owner() fails, the code jumps to the 'pages_free'
> error path.
>
> In this error path, 'p2p_pgmap' is explicitly freed via devm_kfree().
> However, the previously registered devm action is never removed. This
> leaves a dangling pointer in the device's devres list. When the device
> is unbound and devres is cleaning up resources, the unmap action will be
> called with the already-freed 'p2p_pgmap', resulting in a use-after-free
> bug.
>
> Fix this by properly calling devm_remove_action() in the error path before
> freeing 'p2p_pgmap'.
>
> Fixes: 7e9c7ef83d78 ("PCI/P2PDMA: Allow userspace VMA allocations through sysfs")
> Assisted-by: Antigravity:Gemini [tools]
> Signed-off-by: leixiang <leixiang@kylinos.cn>
We need a full name here, not just an email alias.
thanks,
greg k-h
On Fri, Jul 17, 2026 at 12:48:12PM +0200, Greg Kroah-Hartman wrote:
> On Fri, Jul 17, 2026 at 05:51:17PM +0800, leixiang wrote:
> > In pci_p2pdma_add_resource(), a devm action is registered to call
> > pci_p2pdma_unmap_mappings() with the 'p2p_pgmap' context. If the subsequent
> > call to gen_pool_add_owner() fails, the code jumps to the 'pages_free'
> > error path.
> >
> > In this error path, 'p2p_pgmap' is explicitly freed via devm_kfree().
> > However, the previously registered devm action is never removed. This
> > leaves a dangling pointer in the device's devres list. When the device
> > is unbound and devres is cleaning up resources, the unmap action will be
> > called with the already-freed 'p2p_pgmap', resulting in a use-after-free
> > bug.
> >
> > Fix this by properly calling devm_remove_action() in the error path before
> > freeing 'p2p_pgmap'.
> >
> > Fixes: 7e9c7ef83d78 ("PCI/P2PDMA: Allow userspace VMA allocations through sysfs")
> > Assisted-by: Antigravity:Gemini [tools]
> > Signed-off-by: leixiang <leixiang@kylinos.cn>
>
> We need a full name here, not just an email alias.
Hi Greg,
Thanks for pointing that out. I have updated my name and will send a v2 patch shortly.
Best regards,
Xiang Lei
In pci_p2pdma_add_resource(), a devm action is registered to call
pci_p2pdma_unmap_mappings() with the 'p2p_pgmap' context. If the subsequent
call to gen_pool_add_owner() fails, the code jumps to the 'pages_free'
error path.
In this error path, 'p2p_pgmap' is explicitly freed via devm_kfree().
However, the previously registered devm action is never removed. This
leaves a dangling pointer in the device's devres list. When the device
is unbound and devres is cleaning up resources, the unmap action will be
called with the already-freed 'p2p_pgmap', resulting in a use-after-free
bug.
Fix this by properly calling devm_remove_action() in the error path before
freeing 'p2p_pgmap'.
Fixes: 7e9c7ef83d78 ("PCI/P2PDMA: Allow userspace VMA allocations through sysfs")
Assisted-by: Antigravity:Gemini [tools]
Signed-off-by: Xiang Lei <leixiang@kylinos.cn>
---
drivers/pci/p2pdma.c | 4 +++-
1 file changed, 3 insertions(+), 1 deletion(-)
diff --git a/drivers/pci/p2pdma.c b/drivers/pci/p2pdma.c
index b2d5266f8653..7f54532932ab 100644
--- a/drivers/pci/p2pdma.c
+++ b/drivers/pci/p2pdma.c
@@ -451,13 +451,15 @@ int pci_p2pdma_add_resource(struct pci_dev *pdev, int bar, size_t size,
range_len(&pgmap->range), dev_to_node(&pdev->dev),
&pgmap->ref);
if (error)
- goto pages_free;
+ goto unmap_mappings;
pci_info(pdev, "added peer-to-peer DMA memory %#llx-%#llx\n",
pgmap->range.start, pgmap->range.end);
return 0;
+unmap_mappings:
+ devm_remove_action(&pdev->dev, pci_p2pdma_unmap_mappings, p2p_pgmap);
pages_free:
devm_memunmap_pages(&pdev->dev, pgmap);
pgmap_free:
--
2.43.0
© 2016 - 2026 Red Hat, Inc.