From nobody Sat Jul 25 03:20:30 2026 Received: from mail-wm1-f49.google.com (mail-wm1-f49.google.com [209.85.128.49]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 887882F8E9E for ; Sun, 19 Jul 2026 22:10:39 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.128.49 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784499041; cv=none; b=mluWqdvyUIsDk2HV60I6iKGG80CHMqG6R/21Q4o6DpGW/KFvHkVTs5fb7Lxz42HlMHaS4eRp8l5gja/YJtbQeVI5G30ip18XF+pGAiOugY9pEtRVCaBOjdeeEc+dygCwms7JFWQdS4yPB2/rASEW7vN6R3NjJkpZft8Pu5607Eo= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784499041; c=relaxed/simple; bh=1RQ8k9otHSPFMO2zg/Ml6BOTg9wSwQhmSZS4Ik9eJdY=; h=From:To:Cc:Subject:Date:Message-Id:In-Reply-To:References: MIME-Version; b=If6HWmqFTet8G2gWrz0md8YaqKQ8CNIZ5PVy7a1OFFgqbepgvSjbtTaze4POFXEfvAoouwk1zvel3xRjPXzACoUZCNC0QPUDxA0sCY9IljjeX94Lf0cXYGA6MdcYJGA3HjfXoo5mQ4IAco2ouMbTtr43Mxnf/UI+VpDgYWTIa94= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=GsnXUo3H; arc=none smtp.client-ip=209.85.128.49 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="GsnXUo3H" Received: by mail-wm1-f49.google.com with SMTP id 5b1f17b1804b1-495590ba856so5996195e9.2 for ; Sun, 19 Jul 2026 15:10:39 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1784499038; x=1785103838; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=pTekW+ENVi0Z1ogLAr2oe8Uj7dHDNrRZFKBwQW5P7mc=; b=GsnXUo3HH62IyRMU0vhv1SDvJlxtrqjHCH7T3PWFbazqfoYfnmJtpsbtQphdhecLD3 FHrIxmITLvRoJEiYfA2AtK3ujlfJ7+ioi0yYd4CjQOgxFTve9wmgx92w9WLyV6RDVGvA jM3FmH0onpMjOgKZiquu58iQV9kxcgUMSjts8VOTFn0rqBp8d8AhGQD4KgFSIb1f2ju0 ZgdrGdp/jPY3fcPk8z/jVdH8p+qYcSmw8x6D/Ik1kZLFyCE+upq2NT88feSF4JffiCEZ bL70K9g/QbFohYekyZGsjkdPn7X01vc3/ecx03eZkBQkDNKWVd90Gx4gu8YmAiFHTofH eD9A== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784499038; x=1785103838; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=pTekW+ENVi0Z1ogLAr2oe8Uj7dHDNrRZFKBwQW5P7mc=; b=qTwhM0GSky9mKAAMvH0dF+DgpgaFXUVAuJALX83g1zN8na2hNjk3H4aqhkIPEBowoC QSBQ0pzJetUHWO5Hu+kMQ6bLcRKi6u6/lFBKtZD1VMdgIUNQyxHslDCriHXwkgCJ0zBx Sioj2IoAIQHy3Pd7Fl2RFl7xv4QhHspP59ybYmW/1DukoKru+XaNn5wNvSJ75CFAP8HE OaFVR5P6LLz3ko/BC5oPZO8hKA7DlhfEvZDk0mk9PV2u/ZbG02EOVGGJpFoGqk2sECJk pLdmF3P9C9IRbHI0OJWh1A9NeDxgYBFnJUK+yFEVj0hEo4Ncfs/oAdaah11wbpE3PM/a IXvg== X-Forwarded-Encrypted: i=1; AHgh+RquJHQlALdMCXbtdhwYwWDO0h0FHi7eECmgTkd1vx/+GCQBnrOmFdKHOPcQ4uCZmDZF9hE/b+AK2FAOI10=@vger.kernel.org X-Gm-Message-State: AOJu0YxEdXui0QjoLl/iRJWhmo232TJIWOmMf5Lf9olQHRCIHl9OFtMq hSIlP7ToETpfVcP7+jtNip7AaJPTGBwKpgemLMd1fp20cxI1qxAEvCXQhtHfziuk X-Gm-Gg: AfdE7clDoIgYkCALde8SaGSgHrvYIsTRym5uCa+5nsX+PxTJm3XbfszcVNJV0la3wUv Fy+CueXSHVhTZIRYZHMmCL5qwPAKfau+4CrCqgLLzq8FKYZhfBJMopJaDwhT/P4er0f+3tevI/5 q3/8/rypsysS2SNeoBEQUZd3ptYXZ863+8eVw85JnFBJjOrSa2/pfsw2+Q1EIPsczn3V9sEvxWl NMkOGxKU+vX4d7+Rm1v0+UnthlmpDKzt9f75YqgijUGbqYRp7AUZX1Fe9cNtKPCBvSzbYfIZJh8 1alAGvqbjIRZYWvjaeguvq3MfdFZ2FE/TEqLyepuJU9Ny1V8hxxr9JGM45YqTsu4S6fe+zlsLA0 s416Y8OEr9rkCixdT+eF+Nn8sqCW4vLmm2hzd3FTH2l1Sv/SGkp+fKqjfPJoQEX3M/PFhs+bHK3 LVasRA/bJ8FY5UZw5BHC6LQBdma5XvK5OGEAXXzp9gCx8xgDkxkWLnCsYb3hZMCZ1aU9Bn66YJK WJ3+iKCQ5EOa9ShJT1BhzCa440tf08YMJffh5SSav/fzLJ/nvS9VEUAAcQLfjsea5dVOiqB2J4B /k0mIGBOw2YfpNSP2k0tjNf3 X-Received: by 2002:a05:600c:3586:b0:493:e504:cbef with SMTP id 5b1f17b1804b1-4954a38def9mr127029085e9.0.1784499037536; Sun, 19 Jul 2026 15:10:37 -0700 (PDT) Received: from MacBook-Pro-von-Karl.localdomain (dynamic-2a02-3100-aeaf-bd01-78a0-2a2d-507f-c97c.310.pool.telefonica.de. [2a02:3100:aeaf:bd01:78a0:2a2d:507f:c97c]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-4955370d78csm114492445e9.12.2026.07.19.15.10.34 (version=TLS1_3 cipher=TLS_CHACHA20_POLY1305_SHA256 bits=256/256); Sun, 19 Jul 2026 15:10:36 -0700 (PDT) From: Karl Mehltretter To: Greg Kroah-Hartman , Jiri Slaby Cc: Karl Mehltretter , Frank Li , Sascha Hauer , Pengutronix Kernel Team , Fabio Estevam , linux-serial@vger.kernel.org, linux-kernel@vger.kernel.org, imx@lists.linux.dev, linux-arm-kernel@lists.infradead.org, stable@vger.kernel.org Subject: [PATCH v2 1/4] serial: core: do fallible allocations before the console can be registered Date: Mon, 20 Jul 2026 00:10:11 +0200 Message-Id: <20260719221014.44354-2-kmehltretter@gmail.com> X-Mailer: git-send-email 2.39.5 (Apple Git-154) In-Reply-To: <20260719221014.44354-1-kmehltretter@gmail.com> References: <20260719221014.44354-1-kmehltretter@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" serial_core_add_one_port() allocates uport->tty_groups after uart_configure_port() has already registered the port's console. If that allocation fails, the function returns -ENOMEM with the console still registered, and the driver's probe error path then tears down the port state the console callbacks depend on. Reproduced with fault injection on qemu's raspi1ap board. Failing the tty_groups allocation during a PL011 sysfs bind makes uart_add_one_port() return -ENOMEM. pl011_register_port() then clears amba_ports[0], but ttyAMA0 remains registered as a console. The nbcon printer thread dereferences the NULL entry and oopses: Unhandled fault: page domain fault (0x01b) at 0x00000178 CPU: 0 UID: 0 PID: 43 Comm: pr/ttyAMA0 Not tainted 7.2.0-rc3+ #1 PC is at pl011_console_write_thread+0x2c/0x168 This is not PL011-specific: the failing allocation is in serial core, after uart_configure_port() has registered the console, so any console UART driver is exposed. On i.MX the retained console references a devm-allocated port that the failed probe frees, causing a use-after-free. Reproduced on qemu's mcimx6ul-evk using the same fail-nth harness under KASAN: BUG: KASAN: slab-use-after-free in imx_uart_console_write_thread+0x50/0x2= 78 Read of size 4 at addr c5246048 by task pr/ttymxc0/63 imx_uart_console_write_thread from nbcon_emit_next_record+0x360/0x50c nbcon_emit_next_record from nbcon_emit_one+0x140/0x184 Allocated by task 1: devm_kmalloc from imx_uart_probe+0x90/0xa5c Freed by task 1: devres_release_all from device_unbind_cleanup+0x38/0xdc device_unbind_cleanup from really_probe+0x2b4/0x388 The pre-existing kasprintf() failure path has a related problem: it returns with state->uart_port already pointing at a port whose probe is about to unwind and free it. Reorder the function so the uport->name and uport->tty_groups allocations both happen before the port is linked into the driver state table and before uart_configure_port() registers the console: 1. Allocate uport->name. 2. Allocate the tty_groups array with room for three entries unconditionally (serial core group, optional driver group, NULL terminator). The optional group cannot be examined at this point: config_port() may only supply uport->attr_group during uart_configure_port(), e.g. 8250 sets it after autodetection. 3. Only then link the port into the driver state table and run uart_configure_port(). 4. Fill in the optional attr_group slot afterwards. A fail-nth sweep over the whole bind path on both boards left the console unregistered after every failed bind and did not reproduce the i.MX use-after-free. Fixes: 266dcff03eed ("Serial: allow port drivers to have a default attribut= e group") Fixes: f7048b15900f ("tty: serial_core: Add name field to uart_port struct") Cc: stable@vger.kernel.org Assisted-by: Claude:claude-fable-5 Signed-off-by: Karl Mehltretter --- drivers/tty/serial/serial_core.c | 31 +++++++++++++++++-------------- 1 file changed, 17 insertions(+), 14 deletions(-) diff --git a/drivers/tty/serial/serial_core.c b/drivers/tty/serial/serial_c= ore.c index a530ad372b43..887b1dd80ad2 100644 --- a/drivers/tty/serial/serial_core.c +++ b/drivers/tty/serial/serial_core.c @@ -3056,7 +3056,6 @@ static int serial_core_add_one_port(struct uart_drive= r *drv, struct uart_port *u struct uart_state *state; struct tty_port *port; struct device *tty_dev; - int num_groups; =20 if (uport->line >=3D drv->nr) return -EINVAL; @@ -3068,6 +3067,23 @@ static int serial_core_add_one_port(struct uart_driv= er *drv, struct uart_port *u if (state->uart_port) return -EINVAL; =20 + uport->name =3D kasprintf(GFP_KERNEL, "%s%u", drv->dev_name, + drv->tty_driver->name_base + uport->line); + if (!uport->name) + return -ENOMEM; + + /* + * uart_configure_port() may set uport->attr_group and register the + * console. Allocate room for both groups and a NULL terminator first. + */ + uport->tty_groups =3D kzalloc_objs(*uport->tty_groups, 3); + if (!uport->tty_groups) { + kfree(uport->name); + uport->name =3D NULL; + return -ENOMEM; + } + uport->tty_groups[0] =3D &tty_dev_attr_group; + /* Link the port to the driver state table and vice versa */ atomic_set(&state->refcount, 1); init_waitqueue_head(&state->remove_wait); @@ -3084,10 +3100,6 @@ static int serial_core_add_one_port(struct uart_driv= er *drv, struct uart_port *u state->pm_state =3D UART_PM_STATE_UNDEFINED; uart_port_set_cons(uport, drv->cons); uport->minor =3D drv->tty_driver->minor_start + uport->line; - uport->name =3D kasprintf(GFP_KERNEL, "%s%u", drv->dev_name, - drv->tty_driver->name_base + uport->line); - if (!uport->name) - return -ENOMEM; =20 if (uport->cons && uport->dev) of_console_check(uport->dev->of_node, uport->cons->name, uport->line); @@ -3102,15 +3114,6 @@ static int serial_core_add_one_port(struct uart_driv= er *drv, struct uart_port *u =20 port->console =3D uart_console(uport); =20 - num_groups =3D 2; - if (uport->attr_group) - num_groups++; - - uport->tty_groups =3D kzalloc_objs(*uport->tty_groups, num_groups); - if (!uport->tty_groups) - return -ENOMEM; - - uport->tty_groups[0] =3D &tty_dev_attr_group; if (uport->attr_group) uport->tty_groups[1] =3D uport->attr_group; =20 --=20 2.53.0 From nobody Sat Jul 25 03:20:30 2026 Received: from mail-wm1-f54.google.com (mail-wm1-f54.google.com [209.85.128.54]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id D36BA314D18 for ; Sun, 19 Jul 2026 22:10:42 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.128.54 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784499044; cv=none; b=TwHcmUg2YVXwzVBbs7j0bZRkCe319iUzqzU09R23R3HZL/QOtFZ5ixkZ3ckxgkYLEOg2QuUhiTawPFb1eO535TzPa7Bi2LCcUw5kfgfj+vzI5sprG1ge0IpaoAZZWywwNLzNvQcCdkCWlDl29vT6yBVHfkGhe8IOoW4AKWGvlkY= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784499044; c=relaxed/simple; bh=dUEaJRxUr1v76K2SCkn5RSwlmWHDmcrArC8H6gE7+XA=; h=From:To:Cc:Subject:Date:Message-Id:In-Reply-To:References: MIME-Version; b=OoHetSnSEZ0DNOGBIq4ZlgXbhC+yRJ+FWkGdUVI+ESVemiaztbRzP3SOuKBPL8XOu/t5/W9QxQoicRR83i6DAdR44QCIFSCNmNUrRsojD6xWGZ5l/VdbC8eHQdYdw4ae10ITadRxHWTlhBSWQgvcflGS1QI+Wyjezk3MThPebn0= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=rAG0/pVo; arc=none smtp.client-ip=209.85.128.54 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="rAG0/pVo" Received: by mail-wm1-f54.google.com with SMTP id 5b1f17b1804b1-4954a2e73a9so14655405e9.3 for ; Sun, 19 Jul 2026 15:10:42 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1784499041; x=1785103841; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=y2WnfrXCKBHilw+RfhMqIc4Ta8+VRnPx7kVZTMW2Ow4=; b=rAG0/pVoxVjxY2l/TQcjuXeD8jEmCWPDakt8X1yRht+XSuWEJ2Luaysq4JCRXCMDM9 MFmDqXTjpCXTfhRBXTzZ5KffvqnLbhgDB0udBGFahQ8J7+21tgc1KjMRi6qqMmV/XRik zcgbzI33V9rrpuBpZRUc5q+5H0aTmxnJRB6W8KQRN6Rb9ZWIa7ZqbBfnmkcd3OPm4hsQ Se391YiFhE8LUun5QrArMinBRmY9FwhxtuNquHhnIT+mAv3cwZXxgc+3XwXJF2jdoaj3 3heWFCrI9zBzW0HxrBHA20rxbLna83AKaIS53OcAi++plna9CHpEH6Tm1GOXJ5sUXFrJ BsVg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784499041; x=1785103841; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=y2WnfrXCKBHilw+RfhMqIc4Ta8+VRnPx7kVZTMW2Ow4=; b=jcPZdOX3iPWlq8LNyDL8s9YJdMJOL7/NOvO1vrO+QP/g/GB1CTIDMJEnOlgxy+QzSG iqXLhLaEWZV9ALX0Tc7PGVzuNjpDqG/rdaKIbN2XfhxrOO3Z5nIh/B3wW4f25iQ9bPmz LSd7iZdkoTK5U0itUpvZyaofpblk3cPit7YEEj/6XZ0DJ9TyYepS6JUw+PIqSFoO3eGQ 0+XogWrqHWOvp4DU42f2ephblKVAy+XZntMtuybZQeOoq9+ixcRpJsIlfbpOF47AyN7Z 28QR28hTKJPNf/E3NHXF848Za0ffXGwzyrVP5D+GFUkGB+jn8CA6IOK3f3WwFHbgknui l2Mg== X-Forwarded-Encrypted: i=1; AHgh+RoyWhFKbwXoBdcvnaUAawVTnCFoHXsPnXu/0U3DIyIUIuQnUGkIPjc9NQWT+sgQAXOrFjtm5GXHygt01+w=@vger.kernel.org X-Gm-Message-State: AOJu0YwVC7l4tBJ9/OV9hRXTSC5QvMtL7CbYWxlxXFZw7BUCrfzP8CKN wm+TzlnnOM1f18GLjMcQOvGSr2UW7HjIDN29fjR+s9jZymsRXIxWI/kf X-Gm-Gg: AfdE7cnYpAd/I2iMVi36RMu3gBYbAJjbeg2ckjLeyZlUL5em+AlGyDiUymCJ4rf5Rs0 jOfEckle0mCNF0hFwxjLdS6fmRoXIMmC4DikMCV7jUeYF/GE6gzNNVs/sK4/9e36BDuE8cZRpTG 7SHCeo9NaVK86pVX3iB2ZwG1WhOcPKbc8ojU/P09hRnkUCf4gFMS8kxHAwcb+zH4A8+j6S3vlRt 82tAz8SDYrgcWn5/M1hMZmQTb4RPjrdGXrFBHN3hdgUBtevL9GoMaBB85nR5/6SPPmzsdRd7SZc SERalWU0V2p4aJaoCb5AlROahqX6MJnLro3WAIrXNNqw9yw7KFKHYTlrBnLPTkQl6G6I+GfvK13 Xxo8x+4acvxKqhltWkZfnyeaEFaAJgD0bIevd1wsdERcN/Snj5K0bDKGQEpvDTeqY2xIDGhGVK9 PwY5YQpeo7EMy96ce7jusDKc7DJ8yTZIqIiJTkH5nfpUJlVo3LvVXkbymog45E5TBZPV4dOgBh/ wX03cV+iIwi75FIj0Yrf4TcAskUeRUtwvOj+dpE+ruM+DqFJ+1DM1w+3VgCEVuPlSBG3emI+Mw2 qk9kdx5SWQjobeddW3vjqWn5 X-Received: by 2002:a05:600c:e558:20b0:495:5cda:52ec with SMTP id 5b1f17b1804b1-4955cda5441mr19986495e9.16.1784499040980; Sun, 19 Jul 2026 15:10:40 -0700 (PDT) Received: from MacBook-Pro-von-Karl.localdomain (dynamic-2a02-3100-aeaf-bd01-78a0-2a2d-507f-c97c.310.pool.telefonica.de. [2a02:3100:aeaf:bd01:78a0:2a2d:507f:c97c]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-4955370d78csm114492445e9.12.2026.07.19.15.10.39 (version=TLS1_3 cipher=TLS_CHACHA20_POLY1305_SHA256 bits=256/256); Sun, 19 Jul 2026 15:10:40 -0700 (PDT) From: Karl Mehltretter To: Greg Kroah-Hartman , Jiri Slaby Cc: Karl Mehltretter , linux-serial@vger.kernel.org, linux-kernel@vger.kernel.org, stable@vger.kernel.org Subject: [PATCH v2 2/4] serial: core: clear freed pointers on uart_register_driver() failure Date: Mon, 20 Jul 2026 00:10:12 +0200 Message-Id: <20260719221014.44354-3-kmehltretter@gmail.com> X-Mailer: git-send-email 2.39.5 (Apple Git-154) In-Reply-To: <20260719221014.44354-1-kmehltretter@gmail.com> References: <20260719221014.44354-1-kmehltretter@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" uart_register_driver() leaves freed pointers behind on failure. If tty_alloc_driver() fails, it frees drv->state without clearing it. If tty_register_driver() fails, it also drops the tty driver reference without clearing drv->tty_driver. Several drivers register the uart_driver lazily and use drv->state as an "already registered" sentinel. After a failed registration, the next probe sees the stale pointer, skips re-registration and calls uart_add_one_port() with freed state. The resulting unwind can call uart_unregister_driver() with a NULL or dangling drv->tty_driver and oops in tty_unregister_driver(): Unhandled fault: page domain fault (0x01b) at 0x00000018 PC is at tty_unregister_driver+0x10/0x68 LR is at uart_unregister_driver+0x1c/0x60 Reproduced with failslab fail-nth injection on qemu's raspi1ap board: fail the tty_alloc_driver() allocation during a sysfs bind of the PL011 port, then bind again in the same boot. Clear drv->state after freeing the state array and clear drv->tty_driver after dropping the tty driver reference, as uart_unregister_driver() already does. The tty_register_driver() failure case predates Git history. The tty_alloc_driver() failure case was introduced by commit 9e845abfc8a8 ("serial: fix NULL pointer dereference"), which made that error path return cleanly instead of crashing in put_tty_driver(NULL). Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2") Fixes: 9e845abfc8a8 ("serial: fix NULL pointer dereference") Cc: stable@vger.kernel.org Assisted-by: Claude:claude-fable-5 Signed-off-by: Karl Mehltretter --- drivers/tty/serial/serial_core.c | 2 ++ 1 file changed, 2 insertions(+) diff --git a/drivers/tty/serial/serial_core.c b/drivers/tty/serial/serial_c= ore.c index 887b1dd80ad2..ba9145c5a38a 100644 --- a/drivers/tty/serial/serial_core.c +++ b/drivers/tty/serial/serial_core.c @@ -2777,8 +2777,10 @@ int uart_register_driver(struct uart_driver *drv) for (i =3D 0; i < drv->nr; i++) tty_port_destroy(&drv->state[i].port); tty_driver_kref_put(normal); + drv->tty_driver =3D NULL; out_kfree: kfree(drv->state); + drv->state =3D NULL; out: return retval; } --=20 2.53.0 From nobody Sat Jul 25 03:20:30 2026 Received: from mail-wm1-f47.google.com (mail-wm1-f47.google.com [209.85.128.47]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 928432E282B for ; Sun, 19 Jul 2026 22:10:48 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.128.47 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784499049; cv=none; b=mgbQ0hxUM8AD30ttjttjYyziwZWrSHbON47KzeHqTVebFcu4jqwMDfxqrxEMsUqqYrCf82sUlVZSbZ+r1Ck2CHE2fLx038enfEs0AwcFzPqLWQufylegYg/Myp/L4GpWWf1LMsivSXt3JTS7fMZy9nwhM1m8zhH/1Q9yo1nFZ8A= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784499049; c=relaxed/simple; bh=xep+DbUTODAyiI61W5CCxIKqMCWLvMAtORFdzKJXX9g=; h=From:To:Cc:Subject:Date:Message-Id:In-Reply-To:References: MIME-Version; b=SlQb+v4cMlFgb0wfiJtBHlOpdpwOpp+vNHRaxS29PlVSFQoONFWJ7UoCbvir8ecNVpGZyNysWab1yV3feyUDpC86ImrXbYoB/jFIc/1C2Pj/BWok+kZAGfJGF8TaWTcgrX21INKywLyAVydq3vuFUl+b7eU0MuY63WPjnowr0vs= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=qruG3Nyg; arc=none smtp.client-ip=209.85.128.47 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="qruG3Nyg" Received: by mail-wm1-f47.google.com with SMTP id 5b1f17b1804b1-495437bb891so23672335e9.1 for ; Sun, 19 Jul 2026 15:10:48 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1784499047; x=1785103847; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=T7BUDbPgvu4uYiB0I4Tcu6S0zkTXWIU92UBF/zE/Z4w=; b=qruG3NygUeT3MwGKkZWDoY67KUpNkZjbNfUG/HakYPVTGOE0StN/UW1O0LSYcg/6a9 8ZfS+lrz27UleaNUTfbV7XHyb7E8DQjAhjJ0w3FUtGdCWJBCoZOTIP8HpL5hD4Fuea6S TPMbLHmKBHwgde4pPMHgEmB/6ciCjpCf11vvf/f366DOAUqak70MJXMICVFFaKT5nLwh RiUgShY4q3N7rkGfOKVzw2mSUkuSrMnOM+lIeUgN3tvnHvZfmzSWrsqdI5RpXJURyFeC wB0gZopIStURMsgFrYmzHAtiYXS+qn+ELJiNsbH6ymAzUy4AiNPv16nNZML95yUFjDH6 K0Dw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784499047; x=1785103847; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=T7BUDbPgvu4uYiB0I4Tcu6S0zkTXWIU92UBF/zE/Z4w=; b=sxFGPE9aC41WWe90NSS0FU2tD/N2CM7O/i7ti51odQQ7YiGDlapvGrS4giXtF3DIt+ 0QIgM5zcjvFh5DFuKBFJAsMPzQ5ESRhAuFza97a6ORiAufg+/c9Qorv08q5REC4UlmoQ EE4fON3IpN7TX8esnwsxNOl9vJ/kgEy4V0rlUGfchbaZg6FVZVYSks4uLhWUDordwTx8 +UiOnJjCLU454Lvafe/mfwo09i0KErESpLmE7Cgm3k2L2ppKJ0R9yYhFDT41cYB6jiYZ UuC+C0hiA4+NlzL5I1P/yqByB5ee45N1r5Eab1Lc48GaAdylysttxmate1vQ7cq54pdo lMuQ== X-Forwarded-Encrypted: i=1; AHgh+RrvC/kR8cUmNTdh1ytnMGPSiWIlxHgYaERvS2E+p/u03IJ96/XgM7BXz9NVqQiLvdVSoIUxBP6dH+wrn3Q=@vger.kernel.org X-Gm-Message-State: AOJu0YydY5THvn34T0ha0FdvDd0uryAnVAuaPn2Cmnbe9Frl90vXDtM6 FtehX9wNO81/o/i7J9ERH7rStRreWw0A3Fwh5lBt7ihD84lpx894Xi8d X-Gm-Gg: AfdE7ckaZdDG6UHbXXkyRUM1kvfomPSzY60VLu/qmY76ZTTgjddK2a+xurBfq/idZIj ldlMS96HOIJ+/7Sx760Rs1OcvzOVUJ6BDXwa/eDk8ddoT80f9cKCXHrO83nhcbkfaAMIPX001YB 9P8Fj7kF/FOw5qxu7L9kTTR9XHlmNLQ48VmZrmDRt6aXhbsb/1pn3toqUnCKCL0MvIgCjSMFKzB ZAjmGI5sua8NdeAv+rhtBY9g8xO2itzdYftoAZsv0optTiyitwpj4x08gFSaw9C0AM9Re4T5cvw 4L85484nnkGPAmKsVjWU+KoaHfZ/QojYfoJ9s+s4uLuoSg3VK7q2ueGaxrFkzMIKnqUIiZBxE8r hEhgHbulwGCGSUpOgVsUfWBvTKAcmJRipLZv3Hy+EQZuVN1H33qyak1B2TdEny1Rgb7+xtn2OVy wOz8ESoUjwXvSzEyN/+uK2zQM6sTD+de1V9RraRcEnRSLgTTZvO1dpgds4NUFLZOgyQXczQh+ur DupNTzxgCKk7miLULCBY3aunBZkFyYSYmyR97djiygFlG5a/tDKMN8CxQY47qxqLVWcTFkw2VRt 9hLSR+gUAhA+2KadMNaHAFOp X-Received: by 2002:a05:600d:8443:20b0:493:ecf5:89fd with SMTP id 5b1f17b1804b1-4954a341a2bmr91369185e9.17.1784499046380; Sun, 19 Jul 2026 15:10:46 -0700 (PDT) Received: from MacBook-Pro-von-Karl.localdomain (dynamic-2a02-3100-aeaf-bd01-78a0-2a2d-507f-c97c.310.pool.telefonica.de. [2a02:3100:aeaf:bd01:78a0:2a2d:507f:c97c]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-4955370d78csm114492445e9.12.2026.07.19.15.10.44 (version=TLS1_3 cipher=TLS_CHACHA20_POLY1305_SHA256 bits=256/256); Sun, 19 Jul 2026 15:10:45 -0700 (PDT) From: Karl Mehltretter To: Greg Kroah-Hartman , Jiri Slaby Cc: Karl Mehltretter , linux-serial@vger.kernel.org, linux-kernel@vger.kernel.org, stable@vger.kernel.org Subject: [PATCH v2 3/4] tty: don't oops in tty_unregister_device() when no cdev is registered Date: Mon, 20 Jul 2026 00:10:13 +0200 Message-Id: <20260719221014.44354-4-kmehltretter@gmail.com> X-Mailer: git-send-email 2.39.5 (Apple Git-154) In-Reply-To: <20260719221014.44354-1-kmehltretter@gmail.com> References: <20260719221014.44354-1-kmehltretter@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" serial_core_add_one_port() keeps a uart_port when tty device registration fails so setserial can still use it. It marks the port UPF_DEAD and returns success. Removing the port later reaches tty_unregister_device(), which unconditionally passes driver->cdevs[index] to cdev_del(). The slot does not always contain a live cdev. A serdev registration error other than -ENODEV returns before tty_register_device_attr(), leaving the slot NULL. If cdev_add() fails, tty_cdev_add() drops the cdev reference but leaves the slot pointing at freed memory. The later cdev_del() is therefore a NULL dereference or use-after-free. The NULL path was reproduced with failslab during UART bind on qemu's mcimx6ul-evk and raspi1ap boards: Unhandled fault: page domain fault (0x01b) at 0x00000038 PC is at cdev_del+0x14/0x34 Clear the slot after cdev_add() fails and only call cdev_del() when it is non-NULL. This makes a non-NULL slot mean that a live cdev is registered. Fixes: c1a752ba2d6b ("tty: don't leak cdev in tty_cdev_add()") Fixes: 8cde11b2baa1 ("tty/serdev: add serdev registration interface") Cc: stable@vger.kernel.org Assisted-by: Claude:claude-fable-5 Signed-off-by: Karl Mehltretter --- drivers/tty/tty_io.c | 6 ++++-- 1 file changed, 4 insertions(+), 2 deletions(-) diff --git a/drivers/tty/tty_io.c b/drivers/tty/tty_io.c index 6b283fd03ff8..4889076b975f 100644 --- a/drivers/tty/tty_io.c +++ b/drivers/tty/tty_io.c @@ -3167,8 +3167,10 @@ static int tty_cdev_add(struct tty_driver *driver, d= ev_t dev, driver->cdevs[index]->ops =3D &tty_fops; driver->cdevs[index]->owner =3D driver->owner; err =3D cdev_add(driver->cdevs[index], dev, count); - if (err) + if (err) { kobject_put(&driver->cdevs[index]->kobj); + driver->cdevs[index] =3D NULL; + } return err; } =20 @@ -3305,7 +3307,7 @@ EXPORT_SYMBOL_GPL(tty_register_device_attr); void tty_unregister_device(struct tty_driver *driver, unsigned index) { device_destroy(&tty_class, MKDEV(driver->major, driver->minor_start) + in= dex); - if (!(driver->flags & TTY_DRIVER_DYNAMIC_ALLOC)) { + if (!(driver->flags & TTY_DRIVER_DYNAMIC_ALLOC) && driver->cdevs[index]) { cdev_del(driver->cdevs[index]); driver->cdevs[index] =3D NULL; } --=20 2.53.0 From nobody Sat Jul 25 03:20:30 2026 Received: from mail-wm1-f43.google.com (mail-wm1-f43.google.com [209.85.128.43]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 939F9313E00 for ; Sun, 19 Jul 2026 22:10:52 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.128.43 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784499054; cv=none; b=lUdSBLFJuixj1OrhNg6QnsQTG9pfzvDMuLZMjzUaIAixQJT0MALKYE93y+ZmPxadXaR0cyYzJu6gNjbO2YwIlj568BnuMewt7cujE/kZ1rvTDbsHEI7PmHflBEK4NimaV69i592VumaGmB15WBR1IxD6jUdLO+F1PqloHeBK4dg= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784499054; c=relaxed/simple; bh=e/TsC2jyQghy+fHjzGFRoV6KHp39YYSJL7Ig0TqCdS4=; h=From:To:Cc:Subject:Date:Message-Id:In-Reply-To:References: MIME-Version; b=QfhI+ALLrJcWPI/BCME7mVsZ9HDe2QmU5ibX7ChKb/+xMfKs5lZzLXmGBv1wwhBf9WoVYgp3sx0xz8mrRBUgX0qD3pbchTCG4N6VvH+DYyYrLKDY8rljGPmyM+VljfOvpnWpGxN6JW/qFjraCOc4Js8JJY+PoeOgGz4lh3Mt5os= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=CFVxb1dW; arc=none smtp.client-ip=209.85.128.43 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="CFVxb1dW" Received: by mail-wm1-f43.google.com with SMTP id 5b1f17b1804b1-495590ba856so5996925e9.2 for ; Sun, 19 Jul 2026 15:10:52 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1784499051; x=1785103851; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=3PWe1Y8pYuAa7B+GagSYE8D0P3UeZCJcEkhdzL5G7fY=; b=CFVxb1dWBYUtUYBD2MKGawFay9IOV2JUYjaW/oPtAcQCtENU2uAL/R21mLOWsV8xRf BAmHnND+Ml5I2QI6ZmNPV1q7Y7EztOjetIieH72FZazQv4gFd6IpZT/2Lv2mNzUhzQtb pkswJGtK0HbYud9SIRyzfp3qjISSkFDInqlG0KSunTzOcQIpgHpTQYammdZlfZJbRtxj wH4a4idmuHt5h2gTvDrq8Xlg7qQhx0buq3NxdQbFrbZzPiuDxoaVIabXLBrdGtAYLrtK fywCUGVwuSl12/smI8SFwC6qObd3JxWfQnMbNr7fKAt1yhk/aPtXC5JdkmI7JdR8qeCa JThQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1784499051; x=1785103851; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=3PWe1Y8pYuAa7B+GagSYE8D0P3UeZCJcEkhdzL5G7fY=; b=O33jvWh74eXXZZm4kjMjxItZQ7hyip6hGyH+tYPsV5EjqcrAwKWEG8bKsFkLBdxljG UiST0X1Cz+sbfyxMBXLK3z6uv9gJ48IHIeJjTYCQan7Nu7GpYRY/nnQpffjM6B3/V84L 57jgXE4nSGBiIIUFWVSE/Yky1vN7BacMJeBcBaDdG0BNvdfdilt8mH1TVVC3jsB6G8gQ +j8eQcwnRnn3meeqDWS9ABc7/6xZUYFdtmggh7G0PKD6BMAne0fktvdSjynCJbv/NBA8 kcAyyBGa2teXTHRRo8P4dV8zzWtWQX8ty0SYcdlLeByk/Z008pgor4IJFuew9bB1N3bd 8qdA== X-Forwarded-Encrypted: i=1; AHgh+RqssHci37dmqMOprOZIEGRTId1ZvjUpNo/VoyCp+3Z4awWv+G0VBnU8onUcBatCT6JFd5d2f8sxjZ/RoV0=@vger.kernel.org X-Gm-Message-State: AOJu0YxPd+rkV8AG4PQ03l1/Wf8aJF3ByaG2f9Ltbtm5tZ+T6uzo2NtE iuGvYF/ljekkpFpHI0w73Q9Gq+aruajGYo5lcUGUZ2sLVOTvHqGWKtqZ X-Gm-Gg: AfdE7cmUqCjElY9qjh2RPLU04X6SQW+tsdK006A5hCy+blTSSxsglNasFIQJClNIrn9 lljsLfQ7ReK9u+h2vUf/N368f6jLoiNqS1uNHSK3mfRK6D3VrtrhGk0GTFapJ3nicttrp78FsGi 6oApt13nvKyk9BVK1Q3iEX9wlqG4dSt+2D+WFs0r3dMTilKd2BvwWjJOnG71jiFDpNMNxgBZnSJ Fcl2Ju30qtqCOCpTlTQzPwddX3J7dawMIOgJzIxD8fT6mwLhxPz/w9qwfJI9OU8C0F/+Zao7tiv SF27DgbGI+uS7uGGiypw8CxP49tcOUZrw0roB5fz1P3eIn7yzUa+COqunJm+hfy9eS2ZTIu4IIy LEAovPv/6xE9VuOKCsWWKQrkoXgvD0MSmaIhGOmGRd62jeQAZGfYZTg9hpYlX1UaqL02F2cF3vK R48yjPOIWNGDJ59CP3SHSL1crO/P37zcem+FSyaqjTEnj3600smB4S0F1vDrGmphOfQBVJuJzyv UJgCLz+qfPRne4VWk5BJEVgJUeABfOyHEeD4QzxN31UgpkM+qJ/SxYhSLSETSA1PvKl30+fTqnI humcQbMdWMBkGYv6kvFGyt7cA+920elP1UQ= X-Received: by 2002:a05:600c:1f93:b0:493:c8c6:4989 with SMTP id 5b1f17b1804b1-4954a3d64d4mr124694595e9.6.1784499050684; Sun, 19 Jul 2026 15:10:50 -0700 (PDT) Received: from MacBook-Pro-von-Karl.localdomain (dynamic-2a02-3100-aeaf-bd01-78a0-2a2d-507f-c97c.310.pool.telefonica.de. [2a02:3100:aeaf:bd01:78a0:2a2d:507f:c97c]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-4955370d78csm114492445e9.12.2026.07.19.15.10.48 (version=TLS1_3 cipher=TLS_CHACHA20_POLY1305_SHA256 bits=256/256); Sun, 19 Jul 2026 15:10:49 -0700 (PDT) From: Karl Mehltretter To: Greg Kroah-Hartman , Jiri Slaby Cc: Karl Mehltretter , Frank Li , Sascha Hauer , Pengutronix Kernel Team , Fabio Estevam , linux-serial@vger.kernel.org, linux-kernel@vger.kernel.org, imx@lists.linux.dev, linux-arm-kernel@lists.infradead.org, Sashiko , stable@vger.kernel.org Subject: [PATCH v2 4/4] serial: imx: serialize imx_uart_ports[] lifetime Date: Mon, 20 Jul 2026 00:10:14 +0200 Message-Id: <20260719221014.44354-5-kmehltretter@gmail.com> X-Mailer: git-send-email 2.39.5 (Apple Git-154) In-Reply-To: <20260719221014.44354-1-kmehltretter@gmail.com> References: <20260719221014.44354-1-kmehltretter@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" imx_uart_probe() publishes the port in imx_uart_ports[] before uart_add_one_port(), because console setup during that call uses the table. The entry is not cleared if adding the port fails or after imx_uart_remove() removes it. The port is devm-allocated, so a failed probe or unbind leaves the table pointing at freed memory. A later registration of the shared console can then dereference the stale entry. Reproduced on QEMU's mcimx6ul-evk by unbinding a sibling UART, unbinding the console UART and rebinding the sibling: BUG: KASAN: slab-use-after-free in imx_uart_console_setup+0xd0/0x3d8 The entry must remain valid until uart_remove_one_port() unregisters the console. Clearing it afterward without serialization still races a sibling probe: the sibling can register the shared console using the dying entry before it is cleared. The next console write then dereferences NULL. Use a driver-wide mutex to serialize table publication, port addition and rollback with port removal and table clearing. Console callbacks remain lockless because uart_add_one_port() may invoke setup while probe holds the mutex. The probe-failure path also relies on "serial: core: do fallible allocations before the console can be registered", which moves the uport->name and uport->tty_groups allocations before console registration. Both changes should be backported together. Fixes: dbff4e9ea2e8 ("IMX UART: remove statically initialized tables") Fixes: 9f322ad064f9 ("imx: serial: handle initialisation failure correctly") Reported-by: Sashiko Link: https://lore.kernel.org/all/20260719162850.043B41F000E9@smtp.kernel.o= rg Cc: stable@vger.kernel.org Assisted-by: Claude:claude-fable-5 Signed-off-by: Karl Mehltretter --- drivers/tty/serial/imx.c | 21 +++++++++++++++++++-- 1 file changed, 19 insertions(+), 2 deletions(-) diff --git a/drivers/tty/serial/imx.c b/drivers/tty/serial/imx.c index 251a50c8aa38..def874f9cd00 100644 --- a/drivers/tty/serial/imx.c +++ b/drivers/tty/serial/imx.c @@ -22,6 +22,7 @@ #include #include #include +#include #include #include #include @@ -2080,6 +2081,15 @@ static const struct uart_ops imx_uart_pops =3D { =20 static struct imx_port *imx_uart_ports[UART_NR]; =20 +/* + * Store the port in imx_uart_ports[] before uart_add_one_port() and clear + * it only after uart_remove_one_port() returns. Console callbacks in both + * calls use the table, so this mutex serializes these sequences between + * sibling ports. Callbacks must not take it because uart_add_one_port() + * may invoke setup while it is held. + */ +static DEFINE_MUTEX(imx_uart_ports_lock); + #if IS_ENABLED(CONFIG_SERIAL_IMX_CONSOLE) static void imx_uart_console_putchar(struct uart_port *port, unsigned char= ch) { @@ -2632,11 +2642,14 @@ static int imx_uart_probe(struct platform_device *p= dev) } } =20 - imx_uart_ports[sport->port.line] =3D sport; - platform_set_drvdata(pdev, sport); =20 + mutex_lock(&imx_uart_ports_lock); + imx_uart_ports[sport->port.line] =3D sport; ret =3D uart_add_one_port(&imx_uart_uart_driver, &sport->port); + if (ret) + imx_uart_ports[sport->port.line] =3D NULL; + mutex_unlock(&imx_uart_ports_lock); =20 err_clk: clk_disable_unprepare(sport->clk_ipg); @@ -2647,8 +2660,12 @@ static int imx_uart_probe(struct platform_device *pd= ev) static void imx_uart_remove(struct platform_device *pdev) { struct imx_port *sport =3D platform_get_drvdata(pdev); + unsigned int line =3D sport->port.line; =20 + mutex_lock(&imx_uart_ports_lock); uart_remove_one_port(&imx_uart_uart_driver, &sport->port); + imx_uart_ports[line] =3D NULL; + mutex_unlock(&imx_uart_ports_lock); } =20 static void imx_uart_restore_context(struct imx_port *sport) --=20 2.53.0