From nobody Fri Oct 2 07:46:57 2026 Received: from va-2-43.ptr.blmpb.com (va-2-43.ptr.blmpb.com [209.127.231.43]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id D8227384CEB for ; Mon, 3 Aug 2026 23:15:54 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.127.231.43 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785798958; cv=none; b=fmimejzB7SfJGNWZU9gXeHFpuTXv+6RfTTdiM2WmlZJF7KQz7QvnKdRYmpaqGziu5Jge6q6a79wQkhq34oYK9pzxJbmk3eqi+GqEQrchF3Ai3VJbkc5EM9i8LgugBQCxh0LZ/4E8tdnDLDu0utQMp1vZIr7rKKyvPNta0fGhrrQ= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785798958; c=relaxed/simple; bh=OuyjxBWgEpGzFof5aUCl4B4FVBpU/yyef9DnNzJ/Hrc=; h=From:Message-Id:Mime-Version:Cc:Subject:Date:To:Content-Type; b=mH8gd6cY0D4KxK7ErZVgVBV15PtvNjnmeFT6wO4JYkSkoS+Tchc/j/xLNVDvaFXIeGaUnRs1rK8pGpLPD4e3LklmgiKyMX/4XJ5y7p0yu4s9+UydXlt5KbqzVl0Xmkhond0woBGRcnzEBjlhP8uYC5hcMlMFHwOcKJ9LpnL5LeQ= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=cherr.cc; spf=pass smtp.mailfrom=cherr.cc; dkim=pass (2048-bit key) header.d=cherr.cc header.i=@cherr.cc header.b=EZyszHLL; arc=none smtp.client-ip=209.127.231.43 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=cherr.cc Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=cherr.cc Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=cherr.cc header.i=@cherr.cc header.b="EZyszHLL" DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; s=feishu2604220257; d=cherr.cc; t=1785798942; h=from:subject: mime-version:from:date:message-id:subject:to:cc:reply-to:content-type: mime-version:in-reply-to:message-id; bh=u5odJSIa/si0f6OfyBko5IXp2Ehgx5VfQJD3r16gr4Y=; b=EZyszHLLfWeVfdR/kwyYwoOhR1VbR80O6TvxLfjr7siiTxmPDg4aESBuw6vzCzzd8Cj4I0 mnVqTW6NfPi/IYs9qic4N/EaJkJw5C/1CK2sqRsNlteWkyhaImByTazWzjp/9yUGDHoMpC KDE2ENDwXpu+sv782HbRWrwgxt/3aprIJVL3eMlTub7K9wuhlRo0NJhunsLqFyDHAYCjLz pfLT51oW8U721F1iVw43TaVfwcpg6g6Nx2l5RYt59Nmi5BK8SYDDFkwyU4HkjMUb3oxMJ0 NhPvrWiJZ67FjSACinYSWv2wbREviO/qKx4sxlIj9lz/Wz/jJfv7SAMNK/HhoQ== From: "Shengzhuo Wei" Message-Id: <20260804-oxp-fix-v1-1-51a4fe787167@cherr.cc> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 X-Change-Id: 20260804-oxp-fix-879390c5e47f Cc: , , , "Shengzhuo Wei" Subject: [PATCH] HID: hid-oxp: fix UAF on pending work in remove() Date: Tue, 04 Aug 2026 07:15:32 +0800 X-Mailer: b4 0.14.2 X-Lms-Return-Path: To: "Derek J. Clark" , "Jiri Kosina" , "Benjamin Tissoires" , "Zhouwang Huang" X-B4-Tracking: v=1; b=H4sIABMhcWoC/6tWKk4tykwtVrJSqFYqSi3LLM7MzwNyDHUUlJIzE vPSU3UzU4B8JSMDIzMDCwMT3fyKAt20zApdC3NLY0uDZNNUE/M0JaDqgqJUoDDYpOjY2loARyl bLlkAAAA= Received: from [192.168.9.107] ([111.42.148.195]) by smtp.feishu.cn with ESMTPS; Tue, 04 Aug 2026 07:15:39 +0800 X-Original-From: Shengzhuo Wei Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" oxp_cfg_probe() arms drvdata.oxp_mcu_init to run 50 ms after probe, and oxp_mcu_init_fn() dereferences drvdata.hdev to issue MCU output reports (oxp_set_buttons()/oxp_gen_2_property_out() -> hid_hw_output_report(), each followed by msleep(200)). oxp_hid_remove() cancels it with the non-synchronising cancel_delayed_work(), so a worker already running is not waited for; removing the device while the worker is asleep then frees the hid_device underneath it, leaving drvdata.hdev stale -- a use-after-free when the worker wakes. The oxp_rgb_queue and oxp_btn_queue workers, wired up the same way and also cancelled with cancel_delayed_work() in oxp_hid_remove(), have the same problem. Drain all three works with cancel_delayed_work_sync() in oxp_hid_remove() so they have exited before the hid_device is freed. Fixes: 84910c459d65 ("HID: hid-oxp: Add OneXPlayer configuration driver") Fixes: e4c850a6e750 ("HID: hid-oxp: Add Button Mapping Interface") Fixes: 2f424f28fb39 ("HID: hid-oxp: Add Second Generation Gamepad Mode Swit= ch") Cc: stable@vger.kernel.org Signed-off-by: Shengzhuo Wei --- Same delayed-work use-after-free class as the 7.2-rc6 sweep (hid-lenovo-go, hid-lenovo-go-s, hid-lg-g15, hid-appleir, hid-letsketch); hid-oxp was missed. The fix mirrors the cancel_delayed_work_sync() approach already used by hid-lenovo-go / hid-lenovo-go-s. --- drivers/hid/hid-oxp.c | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/drivers/hid/hid-oxp.c b/drivers/hid/hid-oxp.c index 20a54f337220dc2aee3483a14d542b66c487bd60..d8fb6a69d40d43f2595179df106= 7d42b4b3e166a 100644 --- a/drivers/hid/hid-oxp.c +++ b/drivers/hid/hid-oxp.c @@ -1552,9 +1552,9 @@ static int oxp_hid_probe(struct hid_device *hdev, =20 static void oxp_hid_remove(struct hid_device *hdev) { - cancel_delayed_work(&drvdata.oxp_rgb_queue); - cancel_delayed_work(&drvdata.oxp_btn_queue); - cancel_delayed_work(&drvdata.oxp_mcu_init); + cancel_delayed_work_sync(&drvdata.oxp_rgb_queue); + cancel_delayed_work_sync(&drvdata.oxp_btn_queue); + cancel_delayed_work_sync(&drvdata.oxp_mcu_init); hid_hw_close(hdev); hid_hw_stop(hdev); } --- base-commit: 075b74841bd0065a3bda3440873c747938e69b68 change-id: 20260804-oxp-fix-879390c5e47f Best regards, --=20 Shengzhuo Wei