From nobody Fri Oct 2 12:22:34 2026 Received: from zg8tmja2lje4os43os4xodqa.icoremail.net (zg8tmja2lje4os43os4xodqa.icoremail.net [206.189.79.184]) by smtp.subspace.kernel.org (Postfix) with ESMTP id 3E69F83A14; Sun, 2 Aug 2026 01:51:03 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=206.189.79.184 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785635469; cv=none; b=BrWpTkql/TiBAHxmst51Cvm8Oy0rm6upUCJnPuUtkS7URfTs4E2DznrKJ5hZgIGcLUXFkipgPX8UlxwufpRAxoNL58Ifew4CDSwqiIQQzNYsk3KyGApZnI0SpvP25p6kVtrEUgRC0NlN/D54ck/tCfxTEROXzuKfoMrgKbA6KnA= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785635469; c=relaxed/simple; bh=1us0727q9hpocAeDy3PrQlxJWVw8J/a/P/4v0mI+EsA=; h=From:To:Cc:Subject:Date:Message-Id:MIME-Version; b=Z0TLHORTZH5pK4p6u4ttJ/FPNj92c0PIIreY+MF5kt0+Ngh8eOKD/T5SH9+HugUdUv0FUWGzurKGL5/1fajA/bqGQiRDGka94PotnhmG59OBhY3JgdT7tSo1wtQmWC27vZ2FpU9e/P7COjEhAiohXjhq1fu8nxL2ON6KZJuERP0= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=zju.edu.cn; spf=pass smtp.mailfrom=zju.edu.cn; arc=none smtp.client-ip=206.189.79.184 Authentication-Results: smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=zju.edu.cn Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=zju.edu.cn Received: from zju.edu.cn (unknown [10.98.66.117]) by mtasvr (Coremail) with SMTP id _____wC3Hzx_om5qdgVZAA--.14746S3; Sun, 02 Aug 2026 09:50:56 +0800 (CST) Received: from localhost.localdomain (unknown [10.98.66.117]) by mail-app2 (Coremail) with SMTP id zC_KCgBn2c5+om5qdD5zAw--.15409S2; Sun, 02 Aug 2026 09:50:54 +0800 (CST) From: Fan Wu To: linux-usb@vger.kernel.org Cc: heikki.krogerus@linux.intel.com, gregkh@linuxfoundation.org, linux-kernel@vger.kernel.org, stable@vger.kernel.org, Fan Wu Subject: [PATCH] usb: typec: thunderbolt: Disable work before freeing tbt on remove Date: Sun, 2 Aug 2026 01:49:59 +0000 Message-Id: <20260802014959.416687-1-fanwu01@zju.edu.cn> X-Mailer: git-send-email 2.34.1 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-CM-TRANSID: zC_KCgBn2c5+om5qdD5zAw--.15409S2 X-CM-SenderInfo: qrstjiaswqq6lmxovvfxof0/ X-CM-DELIVERINFO: =?B?2WXfxwXKKxbFmtjJiESix3B1w3vZ3A9ovKVTomAyoQazvoRs/NHSP8GI2EvgeEEW7R sfncGSG+szpQCInt5Y8rbJUI1tfbJsdK5dvU8FUQzzw28qOlTcHMLmBbFhnccGnxXQowXF SETPXWEienVG2sSaE6vN5RPxYw6l01w8CbPzC/8w X-Coremail-Antispam: 1Uk129KBj93XoW7Cr18Cw18GFy7Ar48GFy5ZFc_yoW8GrWxpF sIgrWjkFy7GFWxt3W8Jr4I9ay8uwnrZFW3GFyIg3ySqrs8JF12qay8GrW0qFy7CF4rZFWa qF13JF13uayUArcCm3ZEXasCq-sJn29KB7ZKAUJUUUUU529EdanIXcx71UUUUU7KY7ZEXa sCq-sGcSsGvfJ3Ic02F40EFcxC0VAKzVAqx4xG6I80ebIjqfuFe4nvWSU5nxnvy29KBjDU 0xBIdaVrnRJUUU9Cb4IE77IF4wAFF20E14v26r1j6r4UM7CY07I20VC2zVCF04k26cxKx2 IYs7xG6rWj6s0DM7CIcVAFz4kK6r1j6r18M28lY4IEw2IIxxk0rwA2F7IY1VAKz4vEj48v e4kI8wA2z4x0Y4vE2Ix0cI8IcVAFwI0_Ar0_tr1l84ACjcxK6xIIjxv20xvEc7CjxVAFwI 0_Gr1j6F4UJwA2z4x0Y4vEx4A2jsIE14v26F4UJVW0owA2z4x0Y4vEx4A2jsIEc7CjxVAF wI0_Cr1j6rxdM2vYz4IE04k24VAvwVAKI4IrM2AIxVAIcxkEcVAq07x20xvEncxIr21l57 IF6xkI12xvs2x26I8E6xACxx1l5I8CrVACY4xI64kE6c02F40Ex7xfMcIj6xIIjxv20xvE 14v26r1j6r18McIj6I8E87Iv67AKxVWUJVW8JwAm72CE4IkC6x0Yz7v_Jr0_Gr1lF7xvr2 IYc2Ij64vIr41lF7xvr2IYc2Ij64vIr40E4x8a64kEw24l42xK82IYc2Ij64vIr41l4I8I 3I0E4IkC6x0Yz7v_Jr0_Gr1lx2IqxVAqx4xG67AKxVWUJVWUGwC20s026x8GjcxK67AKxV WUGVWUWwC2zVAF1VAY17CE14v26r126r1DMIIYrxkI7VAKI48JMIIF0xvE2Ix0cI8IcVAF wI0_Jr0_JF4lIxAIcVC0I7IYx2IY6xkF7I0E14v26r1j6r4UMIIF0xvE42xK8VAvwI8IcI k0rVWUJVWUCwCI42IY6I8E87Iv67AKxVWUJVW8JwCI42IY6I8E87Iv6xkF7I0E14v26r1j 6r4UYxBIdaVFxhVjvjDU0xZFpf9x07jnKsUUUUUU= Content-Type: text/plain; charset="utf-8" tbt_altmode_remove() drops the plug and cable references without draining tbt->work. The work function dereferences those references, and can also requeue itself in its error path. The VDM callbacks can queue the same work item. Disable and drain tbt->work before dropping the references. This waits for an existing invocation and prevents subsequent schedule_work() calls from queueing it during teardown. This issue was found by an in-house static analysis tool and confirmed by manual code review. Fixes: 100e25738659 ("usb: typec: Add driver for Thunderbolt 3 Alternate Mo= de") Cc: stable@vger.kernel.org Assisted-by: Codex:gpt-5.6 Signed-off-by: Fan Wu Acked-by: Heikki Krogerus --- drivers/usb/typec/altmodes/thunderbolt.c | 2 ++ 1 file changed, 2 insertions(+) diff --git a/drivers/usb/typec/altmodes/thunderbolt.c b/drivers/usb/typec/a= ltmodes/thunderbolt.c index 32250b942..601d39ee1 100644 --- a/drivers/usb/typec/altmodes/thunderbolt.c +++ b/drivers/usb/typec/altmodes/thunderbolt.c @@ -303,6 +303,8 @@ static void tbt_altmode_remove(struct typec_altmode *al= t) { struct tbt_altmode *tbt =3D typec_altmode_get_drvdata(alt); =20 + disable_work_sync(&tbt->work); + for (int i =3D TYPEC_PLUG_SOP_PP; i >=3D 0; --i) { if (tbt->plug[i]) typec_altmode_put_plug(tbt->plug[i]); --=20 2.34.1