[PATCH] PCI/P2PDMA: Fix use-after-free in pci_p2pdma_add_resource() error path

leixiang posted 1 patch 1 week ago
There is a newer version of this series
drivers/pci/p2pdma.c | 4 +++-
1 file changed, 3 insertions(+), 1 deletion(-)
[PATCH] PCI/P2PDMA: Fix use-after-free in pci_p2pdma_add_resource() error path
Posted by leixiang 1 week ago
In pci_p2pdma_add_resource(), a devm action is registered to call
pci_p2pdma_unmap_mappings() with the 'p2p_pgmap' context. If the subsequent
call to gen_pool_add_owner() fails, the code jumps to the 'pages_free'
error path.

In this error path, 'p2p_pgmap' is explicitly freed via devm_kfree().
However, the previously registered devm action is never removed. This
leaves a dangling pointer in the device's devres list. When the device
is unbound and devres is cleaning up resources, the unmap action will be
called with the already-freed 'p2p_pgmap', resulting in a use-after-free
bug.

Fix this by properly calling devm_remove_action() in the error path before
freeing 'p2p_pgmap'.

Fixes: 7e9c7ef83d78 ("PCI/P2PDMA: Allow userspace VMA allocations through sysfs")
Assisted-by: Antigravity:Gemini [tools]
Signed-off-by: leixiang <leixiang@kylinos.cn>
---
 drivers/pci/p2pdma.c | 4 +++-
 1 file changed, 3 insertions(+), 1 deletion(-)

diff --git a/drivers/pci/p2pdma.c b/drivers/pci/p2pdma.c
index b2d5266f8653..7f54532932ab 100644
--- a/drivers/pci/p2pdma.c
+++ b/drivers/pci/p2pdma.c
@@ -451,13 +451,15 @@ int pci_p2pdma_add_resource(struct pci_dev *pdev, int bar, size_t size,
 			range_len(&pgmap->range), dev_to_node(&pdev->dev),
 			&pgmap->ref);
 	if (error)
-		goto pages_free;
+		goto unmap_mappings;
 
 	pci_info(pdev, "added peer-to-peer DMA memory %#llx-%#llx\n",
 		 pgmap->range.start, pgmap->range.end);
 
 	return 0;
 
+unmap_mappings:
+	devm_remove_action(&pdev->dev, pci_p2pdma_unmap_mappings, p2p_pgmap);
 pages_free:
 	devm_memunmap_pages(&pdev->dev, pgmap);
 pgmap_free:
-- 
2.43.0
Re: [PATCH] PCI/P2PDMA: Fix use-after-free in pci_p2pdma_add_resource() error path
Posted by Greg Kroah-Hartman 1 week ago
On Fri, Jul 17, 2026 at 05:51:17PM +0800, leixiang wrote:
> In pci_p2pdma_add_resource(), a devm action is registered to call
> pci_p2pdma_unmap_mappings() with the 'p2p_pgmap' context. If the subsequent
> call to gen_pool_add_owner() fails, the code jumps to the 'pages_free'
> error path.
> 
> In this error path, 'p2p_pgmap' is explicitly freed via devm_kfree().
> However, the previously registered devm action is never removed. This
> leaves a dangling pointer in the device's devres list. When the device
> is unbound and devres is cleaning up resources, the unmap action will be
> called with the already-freed 'p2p_pgmap', resulting in a use-after-free
> bug.
> 
> Fix this by properly calling devm_remove_action() in the error path before
> freeing 'p2p_pgmap'.
> 
> Fixes: 7e9c7ef83d78 ("PCI/P2PDMA: Allow userspace VMA allocations through sysfs")
> Assisted-by: Antigravity:Gemini [tools]
> Signed-off-by: leixiang <leixiang@kylinos.cn>

We need a full name here, not just an email alias.

thanks,

greg k-h
Re: [PATCH] PCI/P2PDMA: Fix use-after-free in pci_p2pdma_add_resource() error path
Posted by Xiang Lei 5 days, 3 hours ago
On Fri, Jul 17, 2026 at 12:48:12PM +0200, Greg Kroah-Hartman wrote:
> On Fri, Jul 17, 2026 at 05:51:17PM +0800, leixiang wrote:
> > In pci_p2pdma_add_resource(), a devm action is registered to call
> > pci_p2pdma_unmap_mappings() with the 'p2p_pgmap' context. If the subsequent
> > call to gen_pool_add_owner() fails, the code jumps to the 'pages_free'
> > error path.
> > 
> > In this error path, 'p2p_pgmap' is explicitly freed via devm_kfree().
> > However, the previously registered devm action is never removed. This
> > leaves a dangling pointer in the device's devres list. When the device
> > is unbound and devres is cleaning up resources, the unmap action will be
> > called with the already-freed 'p2p_pgmap', resulting in a use-after-free
> > bug.
> > 
> > Fix this by properly calling devm_remove_action() in the error path before
> > freeing 'p2p_pgmap'.
> > 
> > Fixes: 7e9c7ef83d78 ("PCI/P2PDMA: Allow userspace VMA allocations through sysfs")
> > Assisted-by: Antigravity:Gemini [tools]
> > Signed-off-by: leixiang <leixiang@kylinos.cn>
> 
> We need a full name here, not just an email alias.

Hi Greg,

Thanks for pointing that out. I have updated my name and will send a v2 patch shortly.

Best regards,
Xiang Lei
[PATCH v2] PCI/P2PDMA: Fix use-after-free in pci_p2pdma_add_resource() error path
Posted by Xiang Lei 5 days, 3 hours ago
In pci_p2pdma_add_resource(), a devm action is registered to call
pci_p2pdma_unmap_mappings() with the 'p2p_pgmap' context. If the subsequent
call to gen_pool_add_owner() fails, the code jumps to the 'pages_free'
error path.

In this error path, 'p2p_pgmap' is explicitly freed via devm_kfree().
However, the previously registered devm action is never removed. This
leaves a dangling pointer in the device's devres list. When the device
is unbound and devres is cleaning up resources, the unmap action will be
called with the already-freed 'p2p_pgmap', resulting in a use-after-free
bug.

Fix this by properly calling devm_remove_action() in the error path before
freeing 'p2p_pgmap'.

Fixes: 7e9c7ef83d78 ("PCI/P2PDMA: Allow userspace VMA allocations through sysfs")
Assisted-by: Antigravity:Gemini [tools]
Signed-off-by: Xiang Lei <leixiang@kylinos.cn>
---
 drivers/pci/p2pdma.c | 4 +++-
 1 file changed, 3 insertions(+), 1 deletion(-)

diff --git a/drivers/pci/p2pdma.c b/drivers/pci/p2pdma.c
index b2d5266f8653..7f54532932ab 100644
--- a/drivers/pci/p2pdma.c
+++ b/drivers/pci/p2pdma.c
@@ -451,13 +451,15 @@ int pci_p2pdma_add_resource(struct pci_dev *pdev, int bar, size_t size,
 			range_len(&pgmap->range), dev_to_node(&pdev->dev),
 			&pgmap->ref);
 	if (error)
-		goto pages_free;
+		goto unmap_mappings;
 
 	pci_info(pdev, "added peer-to-peer DMA memory %#llx-%#llx\n",
 		 pgmap->range.start, pgmap->range.end);
 
 	return 0;
 
+unmap_mappings:
+	devm_remove_action(&pdev->dev, pci_p2pdma_unmap_mappings, p2p_pgmap);
 pages_free:
 	devm_memunmap_pages(&pdev->dev, pgmap);
 pgmap_free:
-- 
2.43.0