From nobody Fri Oct 2 10:54:15 2026 Received: from zg8tmtyylji0my4xnjeumjiw.icoremail.net (zg8tmtyylji0my4xnjeumjiw.icoremail.net [162.243.161.220]) by smtp.subspace.kernel.org (Postfix) with ESMTP id DB037175A9C; Sun, 2 Aug 2026 05:13:48 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=162.243.161.220 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785647634; cv=none; b=QUSKdIfW4kVOyp/8jGpt0Th9Zh8ADUZ6GKHqsEmfwC6zbOm81NIuVA9MAblfJ2YOq/m16FsamUSUwJbPuj4auOb5uRt2apOjkpM8onoDXvl92AjagxJ98MK8+tidEZStQwo9P8Vkgt3mzWnhuN0AEqoqZAAyYRwpA9NfeoPHSwU= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785647634; c=relaxed/simple; bh=Bphe/gztkgkZste2rB6LVTAZedxnyYe8x0lQ+/AmSi8=; h=From:To:Cc:Subject:Date:Message-Id:MIME-Version; b=qeH3OWptAaGDoF3nnwUi3KB6mODpVJMRfJKI7qC7HW5fRz71RN/3xGjOZVBth3w7G0s5cu8wdY3rNNciFozWnrGsSnajNeV3Eyy9B5E72XqLpsfSv809UOJ1HoN71ddvnKD4IdFF+A7H9WwbZ1dAZKmpzHt5o2f/VExFAMFv8To= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=zju.edu.cn; spf=pass smtp.mailfrom=zju.edu.cn; arc=none smtp.client-ip=162.243.161.220 Authentication-Results: smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=zju.edu.cn Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=zju.edu.cn Received: from zju.edu.cn (unknown [10.98.66.117]) by mtasvr (Coremail) with SMTP id _____wB3Qn4I0m5qbYRZAA--.9887S3; Sun, 02 Aug 2026 13:13:45 +0800 (CST) Received: from localhost.localdomain (unknown [10.98.66.117]) by mail-app2 (Coremail) with SMTP id zC_KCgCH9coI0m5q5kt0Aw--.23465S2; Sun, 02 Aug 2026 13:13:44 +0800 (CST) From: Fan Wu To: linux-pm@vger.kernel.org Cc: sre@kernel.org, l.stach@pengutronix.de, linux-kernel@vger.kernel.org, stable@vger.kernel.org, Fan Wu Subject: [PATCH] power: supply: ucs1002: fix use-after-free on remove Date: Sun, 2 Aug 2026 05:12:49 +0000 Message-Id: <20260802051249.424015-1-fanwu01@zju.edu.cn> X-Mailer: git-send-email 2.34.1 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-CM-TRANSID: zC_KCgCH9coI0m5q5kt0Aw--.23465S2 X-CM-SenderInfo: qrstjiaswqq6lmxovvfxof0/ X-CM-DELIVERINFO: =?B?o9l8tAXKKxbFmtjJiESix3B1w3vZ3A9ovKVTomAyoQazvoRs/NHSP8GI2EvgeEEW7R sfncGSG+szpQCInt5Y8rbJUI3Hv0tYaE8dNZ+zZ0l0du39E4ElCCk1swWAAEcclu/XDk2J IDBj+XVh7WKsFq09fjep9E6mavGmQbzmcFsnzP86 X-Coremail-Antispam: 1Uk129KBj93XoW7CF1DJryDuF17Cr4UCF17Arc_yoW8CrWxpF Z0kFyYkrs8uryrXa42v3W2vFy3CayDGr47GrWxt34fZr1aqrs0qw1vgFWaqrZrArWF9a10 vrZ0qFy7urW3urcCm3ZEXasCq-sJn29KB7ZKAUJUUUUU529EdanIXcx71UUUUU7KY7ZEXa sCq-sGcSsGvfJ3Ic02F40EFcxC0VAKzVAqx4xG6I80ebIjqfuFe4nvWSU5nxnvy29KBjDU 0xBIdaVrnRJUUU9lb4IE77IF4wAFF20E14v26r1j6r4UM7CY07I20VC2zVCF04k26cxKx2 IYs7xG6rWj6s0DM7CIcVAFz4kK6r1j6r18M28lY4IEw2IIxxk0rwA2F7IY1VAKz4vEj48v e4kI8wA2z4x0Y4vE2Ix0cI8IcVAFwI0_tr0E3s1l84ACjcxK6xIIjxv20xvEc7CjxVAFwI 0_Cr0_Gr1UM28EF7xvwVC2z280aVAFwI0_GcCE3s1l84ACjcxK6I8E87Iv6xkF7I0E14v2 6rxl6s0DM2vYz4IE04k24VAvwVAKI4IrM2AIxVAIcxkEcVAq07x20xvEncxIr21l57IF6x kI12xvs2x26I8E6xACxx1l5I8CrVACY4xI64kE6c02F40Ex7xfMcIj6xIIjxv20xvE14v2 6r1j6r18McIj6I8E87Iv67AKxVWUJVW8JwAm72CE4IkC6x0Yz7v_Jr0_Gr1lF7xvr2IYc2 Ij64vIr41lF7xvr2IYc2Ij64vIr40E4x8a64kEw24l42xK82IYc2Ij64vIr41l4I8I3I0E 4IkC6x0Yz7v_Jr0_Gr1lx2IqxVAqx4xG67AKxVWUJVWUGwC20s026x8GjcxK67AKxVWUGV WUWwC2zVAF1VAY17CE14v26r126r1DMIIYrxkI7VAKI48JMIIF0xvE2Ix0cI8IcVAFwI0_ Jr0_JF4lIxAIcVC0I7IYx2IY6xkF7I0E14v26r1j6r4UMIIF0xvE42xK8VAvwI8IcIk0rV WUJVWUCwCI42IY6I8E87Iv67AKxVWUJVW8JwCI42IY6I8E87Iv6xkF7I0E14v26r4j6r4U JbIYCTnIWIevJa73UjIFyTuYvjxU2LIDUUUUU Content-Type: text/plain; charset="utf-8" ucs1002 has no remove callback, so unbind runs entirely through devm. The alert IRQ handler queues the health_poll delayed work, and the work reschedules itself while the chip reports a bad-health condition. devm frees the alert IRQ, which only synchronizes the handler; it does not cancel the delayed work, which can then run after devm frees the driver data and dereference it. Register health_poll with devm_delayed_work_autocancel() before the alert IRQ is requested. devm then frees the IRQ before cancelling the work, so the handler can no longer queue it and the work is cancelled before the driver data is freed. This issue was found by an in-house static analysis tool. Fixes: 81196e2e57fc ("power: supply: ucs1002: fix some health status issues= ") Cc: stable@vger.kernel.org Assisted-by: Codex:gpt-5.6 Signed-off-by: Fan Wu Reviewed-by: Lucas Stach --- drivers/power/supply/ucs1002_power.c | 6 +++++- 1 file changed, 5 insertions(+), 1 deletion(-) diff --git a/drivers/power/supply/ucs1002_power.c b/drivers/power/supply/uc= s1002_power.c index 3f44cc9..ca58c21 100644 --- a/drivers/power/supply/ucs1002_power.c +++ b/drivers/power/supply/ucs1002_power.c @@ -11,6 +11,7 @@ #include #include #include +#include #include #include #include @@ -640,7 +641,10 @@ static int ucs1002_probe(struct i2c_client *client) } =20 info->health =3D POWER_SUPPLY_HEALTH_GOOD; - INIT_DELAYED_WORK(&info->health_poll, ucs1002_health_poll); + ret =3D devm_delayed_work_autocancel(dev, &info->health_poll, + ucs1002_health_poll); + if (ret) + return ret; =20 if (irq_a_det > 0) { ret =3D devm_request_threaded_irq(dev, irq_a_det, NULL, --=20 2.34.1