From nobody Sat Jul 25 03:46:50 2026 Received: from mail-wm1-f42.google.com (mail-wm1-f42.google.com [209.85.128.42]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 1A23C3AC0C2 for ; Sun, 19 Jul 2026 16:08:28 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.128.42 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784477310; cv=none; b=EfoOFzQoKeCMUujnYCwMLONV7EqyT392YdoUOlLTgquphRFTE95MuSFtINbHYOi1BVAlBHffT8Z9m9KMAd0FumG5tKufFwUeH0c0eiBierRyYVOJk2VFWyT0heXHDQlM/Z+dEYHqi8P0ga7hCUGooLZdZia+QY269Pn7dWhib2U= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784477310; c=relaxed/simple; bh=1RQ8k9otHSPFMO2zg/Ml6BOTg9wSwQhmSZS4Ik9eJdY=; h=From:To:Cc:Subject:Date:Message-Id:In-Reply-To:References: MIME-Version; b=Uh7JT1kZVX7HOrTi/HBx78BOPlLARLlE7Bv0s83DJF6azr1Lvepa3uILGSW3kUJhLfPS+Gjp3EuCnF89XZz1pP9Mma8f/F92Ow4CABvqLu98nmb5uSyea37L+e2f1/0FSvoRwpKC/43Yu7RVldKlQ0s1DK8q7yoBzsVXKn/Huzc= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=n2/24m7i; arc=none smtp.client-ip=209.85.128.42 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="n2/24m7i" Received: by mail-wm1-f42.google.com with SMTP id 5b1f17b1804b1-49554ebb87dso9763415e9.3 for ; Sun, 19 Jul 2026 09:08:28 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1784477307; x=1785082107; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=pTekW+ENVi0Z1ogLAr2oe8Uj7dHDNrRZFKBwQW5P7mc=; b=n2/24m7igcT86/OwKcy9PyVJ60Nwp2RG+NscSGqB1VejOI/YGzDR782iHHQnz9IutU KpI/4FNSF+e1I4q7ap6ugEkx8RDsR7lgscwgGY3Riaxddk2777hJP6jTc8k0MMwAr/n5 M0TrvBP+iidk7v6mb/v+qj2C4n2YkqqZnoi667RizTXZSsT3Fm9D68Fy4iOCNlw5wjt2 JbGnh1Bmur/RunMGoR1eZ2isNrShJj+VeTHwTiq6q3uN38FDadkiJpxeGG4rWz4SNT9L AMYuCJ5vs0fZN5wmtvzcrO65OC90Kz/BacSyaKU72oRENfEldw+VY4+5z/G4/Bgz2efC 8HVQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784477307; x=1785082107; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=pTekW+ENVi0Z1ogLAr2oe8Uj7dHDNrRZFKBwQW5P7mc=; b=fdds3r/dSgQBAux1lZ002tA+f5JO5cvuFA9dLaUZCw4bK/pbZq9KAfsuq7NJewZuS7 JewZP/lJQq01v0dsJ7at6RXlPZ71j2E4nmuPXnczrA4Q9knJ1BOm+X5Ff112lOdvSnCL J3UyVlowPWz88BEjPznyTJ3TjYMavWZZi1AgafPBqeWcJhHHHrRSYhfOZvlaQcpszq8B n7qdjZzj/Ggx2hwkyyhmxGsU1NHXl6+IFQ7YMrSceEyJTSBx3KXZFRik9VRFQl8pm39Y 6VySELPbj5fMddWM94ZwzDk5nSjaZ2FonjrvxXIVpbylbFwUa7MKIEEyKrUxbhUlZlid owng== X-Forwarded-Encrypted: i=1; AHgh+Rovjsb1S7v+AepEHDQfRXeew5l/XA4cv3zb7Uc5R33+bEeWxIzUkMYClPnkA/7OLFkCSQFD2mU/4NRnEyQ=@vger.kernel.org X-Gm-Message-State: AOJu0Yxg1M8pzrGkHCZJLCILYiRoTMh0RMySi6QvxXZj08LQJwr6ncd1 jZKt0WSo3t5GC9gYbMceKhxObvo/HSFEWk3XeJ8/R8zCBH6ySZ3aVVLn X-Gm-Gg: AfdE7cliSRPaog+gbMMqZdVTYSyIaxUEf7opcC4mg/yrdiRkcts1f1SrT5JxxzUEtsj Sai3117Pp617E3CYl83ulnOmWQU4/zR8lFDruy3TBCpsQDtxsnzYnM5/3zdr9YAnepYI5hQlmDc U7Ge8kl/RW/O5l1DeKYzF8QKBQ8s/LxQ0OBvTyyFSZfzRH5jjhlJZd9CkvFmxP3mtcL9BlRuIeW O0tC6Xynx6OzGsixfrTduQOXymfNoLqOfZwgOFkMhxNbSS/qpfGQFJpGG+to4t12kirGNG+nb67 hXxOEmOIhFfr+5pvXqdFlX9PwF9RxZ0yORbRKZzFpuDE99OKW5UydnWlV8mfSS5ir24FbivIJXw IwRO/mtryjcIa0zfA2E1L/T342EGplTsWI+w0XXbpAfstETxNi/9v0ZPY5ll617+ePC075IrUb3 55ZpOI6KuJLvQFA19pqsdXtCpa97nAbuOtGgkBAou0CFDhnlAiNFErJKr+Fy5V1XGQQ0fe3O9zt 8jZt/36411pUGf3p9kBcIsq5gG/kZTV+bIZPXE8LFBDsDt/460Ot07MylRmSTLks+LhMpXjUQkx EkjvuAP9pA== X-Received: by 2002:a05:600d:6413:10b0:495:573e:1c5a with SMTP id 5b1f17b1804b1-495573e1e23mr29049745e9.13.1784477306815; Sun, 19 Jul 2026 09:08:26 -0700 (PDT) Received: from localhost.localdomain (dynamic-2a02-3100-aeaf-bd01-78a0-2a2d-507f-c97c.310.pool.telefonica.de. [2a02:3100:aeaf:bd01:78a0:2a2d:507f:c97c]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-4954a2edbe4sm223826745e9.12.2026.07.19.09.08.25 (version=TLS1_3 cipher=TLS_CHACHA20_POLY1305_SHA256 bits=256/256); Sun, 19 Jul 2026 09:08:26 -0700 (PDT) From: Karl Mehltretter To: Greg Kroah-Hartman , Jiri Slaby Cc: Karl Mehltretter , Frank Li , Sascha Hauer , Pengutronix Kernel Team , Fabio Estevam , linux-serial@vger.kernel.org, linux-kernel@vger.kernel.org, imx@lists.linux.dev, linux-arm-kernel@lists.infradead.org, stable@vger.kernel.org Subject: [PATCH 1/4] serial: core: do fallible allocations before the console can be registered Date: Sun, 19 Jul 2026 18:08:09 +0200 Message-Id: <20260719160812.35407-2-kmehltretter@gmail.com> X-Mailer: git-send-email 2.39.5 (Apple Git-154) In-Reply-To: <20260719160812.35407-1-kmehltretter@gmail.com> References: <20260719160812.35407-1-kmehltretter@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" serial_core_add_one_port() allocates uport->tty_groups after uart_configure_port() has already registered the port's console. If that allocation fails, the function returns -ENOMEM with the console still registered, and the driver's probe error path then tears down the port state the console callbacks depend on. Reproduced with fault injection on qemu's raspi1ap board. Failing the tty_groups allocation during a PL011 sysfs bind makes uart_add_one_port() return -ENOMEM. pl011_register_port() then clears amba_ports[0], but ttyAMA0 remains registered as a console. The nbcon printer thread dereferences the NULL entry and oopses: Unhandled fault: page domain fault (0x01b) at 0x00000178 CPU: 0 UID: 0 PID: 43 Comm: pr/ttyAMA0 Not tainted 7.2.0-rc3+ #1 PC is at pl011_console_write_thread+0x2c/0x168 This is not PL011-specific: the failing allocation is in serial core, after uart_configure_port() has registered the console, so any console UART driver is exposed. On i.MX the retained console references a devm-allocated port that the failed probe frees, causing a use-after-free. Reproduced on qemu's mcimx6ul-evk using the same fail-nth harness under KASAN: BUG: KASAN: slab-use-after-free in imx_uart_console_write_thread+0x50/0x2= 78 Read of size 4 at addr c5246048 by task pr/ttymxc0/63 imx_uart_console_write_thread from nbcon_emit_next_record+0x360/0x50c nbcon_emit_next_record from nbcon_emit_one+0x140/0x184 Allocated by task 1: devm_kmalloc from imx_uart_probe+0x90/0xa5c Freed by task 1: devres_release_all from device_unbind_cleanup+0x38/0xdc device_unbind_cleanup from really_probe+0x2b4/0x388 The pre-existing kasprintf() failure path has a related problem: it returns with state->uart_port already pointing at a port whose probe is about to unwind and free it. Reorder the function so the uport->name and uport->tty_groups allocations both happen before the port is linked into the driver state table and before uart_configure_port() registers the console: 1. Allocate uport->name. 2. Allocate the tty_groups array with room for three entries unconditionally (serial core group, optional driver group, NULL terminator). The optional group cannot be examined at this point: config_port() may only supply uport->attr_group during uart_configure_port(), e.g. 8250 sets it after autodetection. 3. Only then link the port into the driver state table and run uart_configure_port(). 4. Fill in the optional attr_group slot afterwards. A fail-nth sweep over the whole bind path on both boards left the console unregistered after every failed bind and did not reproduce the i.MX use-after-free. Fixes: 266dcff03eed ("Serial: allow port drivers to have a default attribut= e group") Fixes: f7048b15900f ("tty: serial_core: Add name field to uart_port struct") Cc: stable@vger.kernel.org Assisted-by: Claude:claude-fable-5 Signed-off-by: Karl Mehltretter --- drivers/tty/serial/serial_core.c | 31 +++++++++++++++++-------------- 1 file changed, 17 insertions(+), 14 deletions(-) diff --git a/drivers/tty/serial/serial_core.c b/drivers/tty/serial/serial_c= ore.c index a530ad372b43..887b1dd80ad2 100644 --- a/drivers/tty/serial/serial_core.c +++ b/drivers/tty/serial/serial_core.c @@ -3056,7 +3056,6 @@ static int serial_core_add_one_port(struct uart_drive= r *drv, struct uart_port *u struct uart_state *state; struct tty_port *port; struct device *tty_dev; - int num_groups; =20 if (uport->line >=3D drv->nr) return -EINVAL; @@ -3068,6 +3067,23 @@ static int serial_core_add_one_port(struct uart_driv= er *drv, struct uart_port *u if (state->uart_port) return -EINVAL; =20 + uport->name =3D kasprintf(GFP_KERNEL, "%s%u", drv->dev_name, + drv->tty_driver->name_base + uport->line); + if (!uport->name) + return -ENOMEM; + + /* + * uart_configure_port() may set uport->attr_group and register the + * console. Allocate room for both groups and a NULL terminator first. + */ + uport->tty_groups =3D kzalloc_objs(*uport->tty_groups, 3); + if (!uport->tty_groups) { + kfree(uport->name); + uport->name =3D NULL; + return -ENOMEM; + } + uport->tty_groups[0] =3D &tty_dev_attr_group; + /* Link the port to the driver state table and vice versa */ atomic_set(&state->refcount, 1); init_waitqueue_head(&state->remove_wait); @@ -3084,10 +3100,6 @@ static int serial_core_add_one_port(struct uart_driv= er *drv, struct uart_port *u state->pm_state =3D UART_PM_STATE_UNDEFINED; uart_port_set_cons(uport, drv->cons); uport->minor =3D drv->tty_driver->minor_start + uport->line; - uport->name =3D kasprintf(GFP_KERNEL, "%s%u", drv->dev_name, - drv->tty_driver->name_base + uport->line); - if (!uport->name) - return -ENOMEM; =20 if (uport->cons && uport->dev) of_console_check(uport->dev->of_node, uport->cons->name, uport->line); @@ -3102,15 +3114,6 @@ static int serial_core_add_one_port(struct uart_driv= er *drv, struct uart_port *u =20 port->console =3D uart_console(uport); =20 - num_groups =3D 2; - if (uport->attr_group) - num_groups++; - - uport->tty_groups =3D kzalloc_objs(*uport->tty_groups, num_groups); - if (!uport->tty_groups) - return -ENOMEM; - - uport->tty_groups[0] =3D &tty_dev_attr_group; if (uport->attr_group) uport->tty_groups[1] =3D uport->attr_group; =20 --=20 2.53.0 From nobody Sat Jul 25 03:46:50 2026 Received: from mail-wm1-f43.google.com (mail-wm1-f43.google.com [209.85.128.43]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 8960B3AC0E6 for ; Sun, 19 Jul 2026 16:08:31 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.128.43 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784477313; cv=none; b=du4A1zNItcE/gZeRD7gJnwzKtvrfkg2rmySc+SOKfF1qPkIHLIvacty0e4SkfiMLIye1n1qbe+hWlU/44F4wmamaPCnHbZC2hvlQPJ3nYld0oLxoRxKHfPl+2yYW5/GIulF9LQVm9Vo5kkbIq9aHuikdkXVXqrav+sWZfm8bBiU= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784477313; c=relaxed/simple; bh=dUEaJRxUr1v76K2SCkn5RSwlmWHDmcrArC8H6gE7+XA=; h=From:To:Cc:Subject:Date:Message-Id:In-Reply-To:References: MIME-Version; b=c4EDYUtLRslHQEvqcZ21Qq+vLeSfBEk6XYLSxIq0pF36Ovkr3nzs4Sr1Gd/MS5DtSf4p2IlgIf3uvmQAY+7OomZ+f+1V3qA/PQ83oOCxc/gIA4NhQb4m799sDCutwoqvV0C8gcjA6wLUkwhtRON7JlP4CpuHqKO89p44qLNtsvg= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=FaUKXbaD; arc=none smtp.client-ip=209.85.128.43 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="FaUKXbaD" Received: by mail-wm1-f43.google.com with SMTP id 5b1f17b1804b1-49548aebcd8so14335205e9.3 for ; Sun, 19 Jul 2026 09:08:31 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1784477310; x=1785082110; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=y2WnfrXCKBHilw+RfhMqIc4Ta8+VRnPx7kVZTMW2Ow4=; b=FaUKXbaD2xS8CpVouYiuQBwUs4dxWJL7p8xKThYj0pqrUjEuBuDwC84z11byA5zT+/ 5eyibtyJSquCWcq6vhuLARojMPINnlobb7xZeWIs/tmb8m/+kmmrzvb3tVQdXQn+c4d1 WNYCSNGKsZkezmtQYc17DQLAd1Kv2bJN0by6JZnRBWc+p+VnakJeTY4GSQgOzVdh5iGe lY1XfI01OY7hdtFm3sV8I32IHRJN/3MJlkNSKVehIlcbpQEs9G1gTVOdKcdFAsYli89J KJUZyT2XH1fFdlgOBX/31hZebv4rbhYHSqollW6WoyHAYYtaivfgCNBluoSxJIAC0M9r UdpA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784477310; x=1785082110; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=y2WnfrXCKBHilw+RfhMqIc4Ta8+VRnPx7kVZTMW2Ow4=; b=N+VOdEFz1+EDB1VSVIkAnE2gGXvsLi4r3V/5ws4P4MKkGTYa1yUfiC8MlpAd65uNc5 iEfH+JGxZUNEr73Urwin9Z/aQxRdhMiLeBUz/DAuJWuL1nxFZa8Uw6OHV71+VynuQp/g ZPSxmeFx1dTfmyfIdTcH22mpNgcDCeh67Fo35Cguv3NSaOJYjq9MrLiv3jFgI09VK4BI EnyJOjOSq0md+9jPA3OA4O5DogFXdITmJOoCgSed4Wy0xkHtaU60oRQJ7c1NYXfSz7SW dxcJdDweYGpgth+/XUWXegCIPoF1d1troP58sD7U1WEM6kGoQne8YxBg+hLS4tfzraps Y5ow== X-Forwarded-Encrypted: i=1; AHgh+Rruf46hzDss5up/veewBq5/1MlOM+6k+h9RnD5bZuthCJ9CmOpSnhUQ2CL/abrBI21+81ZxTfqaHJol2y0=@vger.kernel.org X-Gm-Message-State: AOJu0Yxs0EG2ok8oLFMSZB549dF568XbJ+tbyR08VWAZujF2DC4RojsN Y3pBC8jh55rhHdi8RJKucvBSvuZab2Okh9iOTm6hHORc+EoAAQahv9bX X-Gm-Gg: AfdE7cmIMJ9DYRuBI74TrhvadKtunsYRuc+m6d9LCKDAuYYJXmPqtI0d9eih3SKDo4s SZT44z6IhAsxhBuvEe2/Z5Tis+puLcCZZME+1/pwOEPJQ+5r22gYTPTDQQGgXizapX7SAVejroz a9VVPhyFkbuU7lj6DjSLfceJ3TKYEeSfln24SMhAsM9ikSPlXlF89tEOI3wv4Wsc0y6XJ93NCBr yIUIfcuJX+bRT4COfUxHK5DgvOyMIEn3s6B+/TjfaX531xISnqxkTKcrFADuSjgbT90H++eQPUt Y1OHuM4VvJHj1SBogI1UVZ1OFx9njSRqy/wy5BZv+0UUkXlXKaHHWn+whyKXxjxUmvf/utrtdJ4 kRj2K9zt9mXc29sZ6LXY0gcmD2jStZbptl/xSHs2dj+RzWPXRvQ3eSuX5bg6cLm+4bVDmcVBrIw xG6p5X7MsZ2qD2ZzMgUGFjoK54VOmLhexeKoXTDxvcf0gWLH6KNtG6cBzQlDea12ts50SjIU6ii rwgp+iKBV8uC/GC2cGcTxKeiqtn7y338D+Axem4rv3Q+DTW82jRpUQcv0hdfeR0b6aak10Us+KO 8qPt10ohGw== X-Received: by 2002:a05:600c:4685:b0:495:4a77:1327 with SMTP id 5b1f17b1804b1-4954a771521mr125054115e9.33.1784477309565; Sun, 19 Jul 2026 09:08:29 -0700 (PDT) Received: from localhost.localdomain (dynamic-2a02-3100-aeaf-bd01-78a0-2a2d-507f-c97c.310.pool.telefonica.de. [2a02:3100:aeaf:bd01:78a0:2a2d:507f:c97c]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-4954a2edbe4sm223826745e9.12.2026.07.19.09.08.28 (version=TLS1_3 cipher=TLS_CHACHA20_POLY1305_SHA256 bits=256/256); Sun, 19 Jul 2026 09:08:29 -0700 (PDT) From: Karl Mehltretter To: Greg Kroah-Hartman , Jiri Slaby Cc: Karl Mehltretter , linux-serial@vger.kernel.org, linux-kernel@vger.kernel.org, stable@vger.kernel.org Subject: [PATCH 2/4] serial: core: clear freed pointers on uart_register_driver() failure Date: Sun, 19 Jul 2026 18:08:10 +0200 Message-Id: <20260719160812.35407-3-kmehltretter@gmail.com> X-Mailer: git-send-email 2.39.5 (Apple Git-154) In-Reply-To: <20260719160812.35407-1-kmehltretter@gmail.com> References: <20260719160812.35407-1-kmehltretter@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" uart_register_driver() leaves freed pointers behind on failure. If tty_alloc_driver() fails, it frees drv->state without clearing it. If tty_register_driver() fails, it also drops the tty driver reference without clearing drv->tty_driver. Several drivers register the uart_driver lazily and use drv->state as an "already registered" sentinel. After a failed registration, the next probe sees the stale pointer, skips re-registration and calls uart_add_one_port() with freed state. The resulting unwind can call uart_unregister_driver() with a NULL or dangling drv->tty_driver and oops in tty_unregister_driver(): Unhandled fault: page domain fault (0x01b) at 0x00000018 PC is at tty_unregister_driver+0x10/0x68 LR is at uart_unregister_driver+0x1c/0x60 Reproduced with failslab fail-nth injection on qemu's raspi1ap board: fail the tty_alloc_driver() allocation during a sysfs bind of the PL011 port, then bind again in the same boot. Clear drv->state after freeing the state array and clear drv->tty_driver after dropping the tty driver reference, as uart_unregister_driver() already does. The tty_register_driver() failure case predates Git history. The tty_alloc_driver() failure case was introduced by commit 9e845abfc8a8 ("serial: fix NULL pointer dereference"), which made that error path return cleanly instead of crashing in put_tty_driver(NULL). Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2") Fixes: 9e845abfc8a8 ("serial: fix NULL pointer dereference") Cc: stable@vger.kernel.org Assisted-by: Claude:claude-fable-5 Signed-off-by: Karl Mehltretter --- drivers/tty/serial/serial_core.c | 2 ++ 1 file changed, 2 insertions(+) diff --git a/drivers/tty/serial/serial_core.c b/drivers/tty/serial/serial_c= ore.c index 887b1dd80ad2..ba9145c5a38a 100644 --- a/drivers/tty/serial/serial_core.c +++ b/drivers/tty/serial/serial_core.c @@ -2777,8 +2777,10 @@ int uart_register_driver(struct uart_driver *drv) for (i =3D 0; i < drv->nr; i++) tty_port_destroy(&drv->state[i].port); tty_driver_kref_put(normal); + drv->tty_driver =3D NULL; out_kfree: kfree(drv->state); + drv->state =3D NULL; out: return retval; } --=20 2.53.0 From nobody Sat Jul 25 03:46:50 2026 Received: from mail-wm1-f41.google.com (mail-wm1-f41.google.com [209.85.128.41]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id BD4F53ACA5A for ; Sun, 19 Jul 2026 16:08:34 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.128.41 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784477316; cv=none; b=mpCNXweRo7WjBHKWA1EbIvcFRMhhghMYmq3odU+qXIcediaerFQf86nDuOf0j95JRBjHtvnL7EMxS8zR82f0Vn0cQKlUXICR4YT5w9CZXEPUqSpn84Ga9S3dXWy/nljvL83W/q0LjLjXkYc6zOSt6N0UGor4SVDrqsKdGOGKa7Q= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784477316; c=relaxed/simple; bh=xep+DbUTODAyiI61W5CCxIKqMCWLvMAtORFdzKJXX9g=; h=From:To:Cc:Subject:Date:Message-Id:In-Reply-To:References: MIME-Version; b=jM+AvAYIJR90LN2v3x0jvptKBDuZyxSCXQlNcqXGGOYUdwkz4kqaX8AZP6v7YJUxb0f0bxZP3mflW47oPigCcTm7HI93pytCF3H0cq9fcRb4kILuSIoT5VrqbYsMjlNeACkoCGCHLL5cLHZQC58Jdk2fZexomyuS33PyS+hM3CI= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=SjMADF1t; arc=none smtp.client-ip=209.85.128.41 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="SjMADF1t" Received: by mail-wm1-f41.google.com with SMTP id 5b1f17b1804b1-4954c0833b4so11653935e9.1 for ; Sun, 19 Jul 2026 09:08:34 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1784477313; x=1785082113; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=T7BUDbPgvu4uYiB0I4Tcu6S0zkTXWIU92UBF/zE/Z4w=; b=SjMADF1tT0usbm7wnGnkIj1TQk1PFlrmf7UpAX6ZxPtSTvo+iSsa2MevZoaGPX661i cZsBtHzdEWDUeq92jJVJwUcevx8ZHtKQzk4TG+ussm5Tp3nKo6v5y5rTQosTsm+mU207 /t0ytK70budYwCQ/m466hM3B7uGo5qExOJTROHS7Pws6qTXZJ05ZAQIsUUMo536SNoYv /MjAUTCCaLmTt3QL1Ezp40sUdQ2lFzOP08SKwJqpYx70jBWvNsrMRwAuYvXLyNo31GXG 8baPzVay1CyBznmdn/IcbW+D78dYSoIZnIU+0uI9T3zYVtiJWHT/L/72dmXkSlUa/RRy CdLg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784477313; x=1785082113; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=T7BUDbPgvu4uYiB0I4Tcu6S0zkTXWIU92UBF/zE/Z4w=; b=KrrnVsiUIuqr04xu9wop9w31somjr2JTh+rrCMxwtLk1XDZweJptSTBXwknqgRu47K pWcmQ2hNXPXKgwHduQ5dUNbEHEbfenGi5UTadEmJ4ZdlDl26q6IZUuLIyyMk3vvGEQle x7ahUcn0/kNs9dWvvpFyaCNfcO9UZuzY0cttgXaSjVxBdozGb9ES2LtQNQ5Bnjuh+Bdc VP3a4qkSKN9b5rwEB4VcfuKR9ujE4Hw/sb+FImoVsmSZBFnfa2u+913OGfXlrhxPSL5Z WD0Xvoa8F57LhXoG97+6PvkZ2XYgvx9XaW5VK9Ud8Q5R2cHbLJ0Vcf5BS2Vmo7M3mBzW R3Fw== X-Forwarded-Encrypted: i=1; AHgh+RphI2fC64TYIBuju1IhP8JzouCEms4SN0g9ceapDyzbGMsoOKH7RfTclTfDRyFNuUtBYW6QxdEHGh3gFTY=@vger.kernel.org X-Gm-Message-State: AOJu0Ywd8fCHZRMzTV10t/vKvyc+FjdLR5z1oql/evI0ywMydsej+1T4 QNXV42+rtRMa15cVCXFqdQR9EJrX67IwHZyfE0DsTgvtkhKMXa4BU1Rg X-Gm-Gg: AfdE7clYBA7cCEyCTpb2Qnjj0/acqA5J6x3tO/uC1Tde00Gzl1kJH/aXArmKgtn5L/z b9ol9AcTJUulNedKJWtZdXO/HELE1vo2tT8UHdTSzox5wb9P1Yn9rKxhFDrNbeZSDP4iWt7dy8M 1gLxL3nKy+zsq7ZgAXUKTmTFjyyar38haelrI30Wyax9bg0CR1F7Vn0L3Vzuu5jNJBRgWPxsZGQ zZK7nd0sIg3WDzQob/1xjJNqkAWRPHFIin8cWfpgBycR5odJWJ8zpGWOd5500P3Irh0yKdv7txy n+pRlUr41CLACLCWlorkemrUhsLQ7cjAs1eYkO0ROImmen6o0cgBMeKSP0bxkrt/6Yf1N57Y05k QaFpFJJfOO0OkShv8cTAMIbXatzyX0W2IbKn1tiKy6UyLm0OBNKfe6RBxqDkBoAvNJALcvMZIf9 ZelRanvwWdvHZgZLdp17ys/qNT2fYrllQT8xvTNG0l1RnnSolAGjp15zpEN9UG0pGJ+h5xtZ0mt Zt02ax5vrRtLHNfZ7Le+e0rfaniczrdzkKpye4skTLllTyBkzU80lxaKyhaScQLTexUeoFkF2LJ 2NHnfVnU2g== X-Received: by 2002:a05:600d:104:b0:495:4182:4442 with SMTP id 5b1f17b1804b1-4954a50c563mr76711935e9.22.1784477312656; Sun, 19 Jul 2026 09:08:32 -0700 (PDT) Received: from localhost.localdomain (dynamic-2a02-3100-aeaf-bd01-78a0-2a2d-507f-c97c.310.pool.telefonica.de. [2a02:3100:aeaf:bd01:78a0:2a2d:507f:c97c]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-4954a2edbe4sm223826745e9.12.2026.07.19.09.08.31 (version=TLS1_3 cipher=TLS_CHACHA20_POLY1305_SHA256 bits=256/256); Sun, 19 Jul 2026 09:08:31 -0700 (PDT) From: Karl Mehltretter To: Greg Kroah-Hartman , Jiri Slaby Cc: Karl Mehltretter , linux-serial@vger.kernel.org, linux-kernel@vger.kernel.org, stable@vger.kernel.org Subject: [PATCH 3/4] tty: don't oops in tty_unregister_device() when no cdev is registered Date: Sun, 19 Jul 2026 18:08:11 +0200 Message-Id: <20260719160812.35407-4-kmehltretter@gmail.com> X-Mailer: git-send-email 2.39.5 (Apple Git-154) In-Reply-To: <20260719160812.35407-1-kmehltretter@gmail.com> References: <20260719160812.35407-1-kmehltretter@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" serial_core_add_one_port() keeps a uart_port when tty device registration fails so setserial can still use it. It marks the port UPF_DEAD and returns success. Removing the port later reaches tty_unregister_device(), which unconditionally passes driver->cdevs[index] to cdev_del(). The slot does not always contain a live cdev. A serdev registration error other than -ENODEV returns before tty_register_device_attr(), leaving the slot NULL. If cdev_add() fails, tty_cdev_add() drops the cdev reference but leaves the slot pointing at freed memory. The later cdev_del() is therefore a NULL dereference or use-after-free. The NULL path was reproduced with failslab during UART bind on qemu's mcimx6ul-evk and raspi1ap boards: Unhandled fault: page domain fault (0x01b) at 0x00000038 PC is at cdev_del+0x14/0x34 Clear the slot after cdev_add() fails and only call cdev_del() when it is non-NULL. This makes a non-NULL slot mean that a live cdev is registered. Fixes: c1a752ba2d6b ("tty: don't leak cdev in tty_cdev_add()") Fixes: 8cde11b2baa1 ("tty/serdev: add serdev registration interface") Cc: stable@vger.kernel.org Assisted-by: Claude:claude-fable-5 Signed-off-by: Karl Mehltretter --- drivers/tty/tty_io.c | 6 ++++-- 1 file changed, 4 insertions(+), 2 deletions(-) diff --git a/drivers/tty/tty_io.c b/drivers/tty/tty_io.c index 6b283fd03ff8..4889076b975f 100644 --- a/drivers/tty/tty_io.c +++ b/drivers/tty/tty_io.c @@ -3167,8 +3167,10 @@ static int tty_cdev_add(struct tty_driver *driver, d= ev_t dev, driver->cdevs[index]->ops =3D &tty_fops; driver->cdevs[index]->owner =3D driver->owner; err =3D cdev_add(driver->cdevs[index], dev, count); - if (err) + if (err) { kobject_put(&driver->cdevs[index]->kobj); + driver->cdevs[index] =3D NULL; + } return err; } =20 @@ -3305,7 +3307,7 @@ EXPORT_SYMBOL_GPL(tty_register_device_attr); void tty_unregister_device(struct tty_driver *driver, unsigned index) { device_destroy(&tty_class, MKDEV(driver->major, driver->minor_start) + in= dex); - if (!(driver->flags & TTY_DRIVER_DYNAMIC_ALLOC)) { + if (!(driver->flags & TTY_DRIVER_DYNAMIC_ALLOC) && driver->cdevs[index]) { cdev_del(driver->cdevs[index]); driver->cdevs[index] =3D NULL; } --=20 2.53.0 From nobody Sat Jul 25 03:46:50 2026 Received: from mail-wm1-f51.google.com (mail-wm1-f51.google.com [209.85.128.51]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 09F773ACA7B for ; Sun, 19 Jul 2026 16:08:37 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.128.51 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784477319; cv=none; b=sGl4FJeNLL5sRtG2YpE4h+xJoCiPay4+eGyGq7dgZNtd5KSoLNRuQ2B8A4ALJ/CfJXoc+tYR1oAvNONV0GmODkjaEpDPy5ztZbtwxdoK1eAohCoIc6N28xVj1g13reNNJVLW+PLnciH+x+KQJmJr8k3C40C92cs8smVFq4VYE6U= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784477319; c=relaxed/simple; bh=8sdnQwIMdO7CwPShC74pX/gtmmBu9zvdCtaHEui32XA=; h=From:To:Cc:Subject:Date:Message-Id:In-Reply-To:References: MIME-Version; b=EVIcZECa3yvEZ31GbIZ9V7rT3j2u4wC3S1YOdWIj7GvWI5hHwx3TYNLN9mLHIobU3Z+nhV8IDnekRdRPP2p4lJFWnwXmaVXbbLi4DmsFhX4Xm4BZepZgoTB5coW6pb8aerGa/XMYb4Vl+qSinyyhRkNSxKBX8KaLflcMSVnBtII= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=DW/jTCV2; arc=none smtp.client-ip=209.85.128.51 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="DW/jTCV2" Received: by mail-wm1-f51.google.com with SMTP id 5b1f17b1804b1-49548aebcd8so14335965e9.3 for ; Sun, 19 Jul 2026 09:08:37 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1784477316; x=1785082116; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=/SUAt/6zWUy8VxjfuD7LmHF2gwOSZYdtNqcx/e+ByoY=; b=DW/jTCV2S3HFHpdNmnAIJkQh4qaLZdmdU7SPXoSzy60dW+KfNOWheL9rwc3lDTc0L5 P57PNBce04KyoJbgkW3kjcLplQzQjFE8DeeCcsVHOZkdPns002m6eXUd/Rd2tTavOUeU mIvzvcqnfx+AtJqWdSINxguTSHdSkDzOPmVFYa9VPHiOcI6z3o2ee2Jyqb6ZoA5/vgPl GgKFAEQgRulpwAzR7ndpymy3x9G26foYf2l810mq8vGKll24roFyrqm0BVBtKiKsd0I0 T7QC/Z025fvlRKC1tm8Rm96SritzUqkxV6SynBuIdgcfA9gYVC5qeriPt1NWwNMROyfC xN8Q== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784477316; x=1785082116; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=/SUAt/6zWUy8VxjfuD7LmHF2gwOSZYdtNqcx/e+ByoY=; b=oJa6vDmBYiZIBJFYY0JHZHKhrMy04KNzk11/IsvnoVvg32mbMbxQFmrP3qp/vOs6BB DSMPbDpAtQgRPSnF9B16/kWkN8tfRpsWx14nCBiRDLepBrUmO8srnmm02BW3oiM0A/KT xdg+1PMRj3qXgcMSbQt/hH/CKXox3INf9Jd1HHjy1LSXuf/VKlwcOeph2lYQip5mYKOi hvDPx0vBFj3dOvn9T/sVnVIwZgyV3NrRSayDz41LzKiwMY8LWfdFxFDs374zGLAnRwM6 Zg3/UjhpDbye7FZRl7IqpXbY+HlRdIZ1dcBH/uQnyibzTTVvwmsCm2sKSBw1Ih5BFLdU H3dw== X-Forwarded-Encrypted: i=1; AHgh+RrGnKhVjL8Qvj7SsggJxILSTssy4zqAUh+GchQEPYkSGu+Rl4At7yOJPY7f9nQWfthtSO7br8Mf6y6WlSY=@vger.kernel.org X-Gm-Message-State: AOJu0Yx9Ym5FNKpLKf1zAx0yRlrvgyQlE4M4DYlwnklqqmwVR05/tD6y 98i7NF8PMI7372I80/5I0MqHJYXKFH4DtcKlY+R3mfOwb3nVTJPUutAy X-Gm-Gg: AfdE7cmez0Oi3gcYC43vqaypwziLn48IxL9cz78j3I2flA+gwSZp+Iu21wkqZhCKXho Ul5/PccdHrsnpAajB6gYzfj11lwqJ5ufsGnDQDT/EgGj5827rQ2eiJHGmjTifepgTkLJxq+tzsu F8WrTvduxrlCxWQ5Qee+cXpc0vIk81NrxxTlkif9nXB01QGWT66ieq2wNrRlegmFrJbcZjUmDVR iBhz5ar+K0pNiqxegUa8TjzxoVanJt/atJIGOSN67i0kIXH3rWn3lIcMBR6xaX+GEv1MRmHN3Sk wuTZF6ONsvEUX/Xtl+hHajby2KJ+RwnGOmfdE8vFoMDLRtjtwDt9NByLsKJnRw3pMlAEfG31I49 cLR1IM/lnY6l5T5LIYjTuBfrhpNwhEgV5XNfuOniA2OVDwzynjT9iK2QezG5wYA5QQxedVi4obW 6rGEe4EGaTDLW9Me+fpmAUFh62CvGNTHiLW6NmbpnqcDq6yK34wiRh7n9bHhuO5t0I5n6mVHKU/ 4RhZpU492rzIpYVSiTyYUa6LqPWI3g44d4W+EIgdULvdlAWA6B89ZqMZs7SS6UmgBcBT6+Xf3e8 422l0bDOyw== X-Received: by 2002:a05:600c:4504:b0:493:eb71:5cc6 with SMTP id 5b1f17b1804b1-4954a40bbc8mr113521195e9.27.1784477315903; Sun, 19 Jul 2026 09:08:35 -0700 (PDT) Received: from localhost.localdomain (dynamic-2a02-3100-aeaf-bd01-78a0-2a2d-507f-c97c.310.pool.telefonica.de. [2a02:3100:aeaf:bd01:78a0:2a2d:507f:c97c]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-4954a2edbe4sm223826745e9.12.2026.07.19.09.08.34 (version=TLS1_3 cipher=TLS_CHACHA20_POLY1305_SHA256 bits=256/256); Sun, 19 Jul 2026 09:08:35 -0700 (PDT) From: Karl Mehltretter To: Greg Kroah-Hartman , Jiri Slaby Cc: Karl Mehltretter , Frank Li , Sascha Hauer , Pengutronix Kernel Team , Fabio Estevam , linux-serial@vger.kernel.org, linux-kernel@vger.kernel.org, imx@lists.linux.dev, linux-arm-kernel@lists.infradead.org, stable@vger.kernel.org Subject: [PATCH 4/4] serial: imx: clear imx_uart_ports[] entry on probe failure and removal Date: Sun, 19 Jul 2026 18:08:12 +0200 Message-Id: <20260719160812.35407-5-kmehltretter@gmail.com> X-Mailer: git-send-email 2.39.5 (Apple Git-154) In-Reply-To: <20260719160812.35407-1-kmehltretter@gmail.com> References: <20260719160812.35407-1-kmehltretter@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" imx_uart_probe() stores the port in imx_uart_ports[] before calling uart_add_one_port() because console setup during that call uses the table. The entry remains set if uart_add_one_port() fails. imx_uart_remove() also leaves it set after uart_remove_one_port(). sport is devm-allocated, so a failed probe or unbind frees it while imx_uart_ports[] still points to it. A later sibling probe can register the shared console with the old preferred index and dereference the stale entry in imx_uart_console_setup(). Reproduced on qemu's mcimx6ul-evk by unbinding a sibling UART, unbinding the console UART and rebinding the sibling: BUG: KASAN: slab-use-after-free in imx_uart_console_setup+0xd0/0x3d8 Read of size 4 at addr c49ad9d4 by task init/1 Call trace: ... imx_uart_console_setup from try_enable_preferred_console+0x158/0x1f8 try_enable_preferred_console from register_console+0x1cc/0x80c register_console from serial_core_register_port+0xe58/0xeb0 ... Freed by task 1: ... devres_release_all+0x100/0x18c device_unbind_cleanup+0x38/0xdc device_release_driver_internal+0x230/0x288 unbind_store+0x64/0xa8 ... The entry must remain visible while uart_add_one_port() and uart_remove_one_port() run. Clear it when adding the port fails and after removing the port. Save the line index before removal because the uart_port is no longer valid afterward. The probe-failure cleanup relies on the preceding serial-core change "serial: core: do fallible allocations before the console can be registered", which ensures that uart_add_one_port() cannot fail after registering the console. For complete coverage, both changes should be backported together. Fixes: dbff4e9ea2e8 ("IMX UART: remove statically initialized tables") Fixes: 9f322ad064f9 ("imx: serial: handle initialisation failure correctly") Cc: stable@vger.kernel.org Assisted-by: Claude:claude-fable-5 Signed-off-by: Karl Mehltretter --- drivers/tty/serial/imx.c | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/drivers/tty/serial/imx.c b/drivers/tty/serial/imx.c index 251a50c8aa38..617c35772056 100644 --- a/drivers/tty/serial/imx.c +++ b/drivers/tty/serial/imx.c @@ -2637,6 +2637,8 @@ static int imx_uart_probe(struct platform_device *pde= v) platform_set_drvdata(pdev, sport); =20 ret =3D uart_add_one_port(&imx_uart_uart_driver, &sport->port); + if (ret) + imx_uart_ports[sport->port.line] =3D NULL; =20 err_clk: clk_disable_unprepare(sport->clk_ipg); @@ -2647,8 +2649,10 @@ static int imx_uart_probe(struct platform_device *pd= ev) static void imx_uart_remove(struct platform_device *pdev) { struct imx_port *sport =3D platform_get_drvdata(pdev); + unsigned int line =3D sport->port.line; =20 uart_remove_one_port(&imx_uart_uart_driver, &sport->port); + imx_uart_ports[line] =3D NULL; } =20 static void imx_uart_restore_context(struct imx_port *sport) --=20 2.53.0