From nobody Fri Oct 2 01:12:58 2026 Received: from foss.arm.com (foss.arm.com [217.140.110.172]) by smtp.subspace.kernel.org (Postfix) with ESMTP id 9C2B84503E3 for ; Thu, 6 Aug 2026 14:46:45 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=217.140.110.172 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786027608; cv=none; b=rACBzFjCtRnNqz2JVby+AXp7uB/SrixxjjKKHN74LpE7Q/DRmKvk/XdDzXCPoY6CrmpJqRfyF+bPWfA03+STxTZdKDHJh6oFQpa5+qoIUDVG/GEnef+MHXJ7ESJ+TTgkp4bvkpqi7Tz2hfc6kZGwJwVFpApcQ8cJSVRBexeyy6Q= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786027608; c=relaxed/simple; bh=YEqhi0ns9dOGIwkKaThAPGwuXkqZjMn1/micDNziDLY=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=Zja056x/7jTChj0AO0ZY+0zx8bcQahYzPIM5ANOgGJExLAoyKA6VzYUuMRwsxM+qRpvrzg4KqpjtceyDhEr849qsVJDOICTWTjQhpdRhgfsudRJUpgMzfH+EOmVn2HGUI5PWqPSqE/XAeqfjKIah/WSUKRURjhl8J0VVL4J7gQc= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=arm.com; spf=pass smtp.mailfrom=arm.com; dkim=pass (1024-bit key) header.d=arm.com header.i=@arm.com header.b=j4qyDf51; arc=none smtp.client-ip=217.140.110.172 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=arm.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=arm.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=arm.com header.i=@arm.com header.b="j4qyDf51" Received: from usa-sjc-imap-foss1.foss.arm.com (unknown [10.121.207.14]) by usa-sjc-mx-foss1.foss.arm.com (Postfix) with ESMTP id 1BAC419F0; Thu, 6 Aug 2026 07:46:41 -0700 (PDT) Received: from e134344.cambridge.arm.com (e134344.arm.com [10.2.212.8]) by usa-sjc-imap-foss1.foss.arm.com (Postfix) with ESMTPA id 7CEE63F9A2; Thu, 6 Aug 2026 07:46:43 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=simple/simple; d=arm.com; s=foss; t=1786027605; bh=YEqhi0ns9dOGIwkKaThAPGwuXkqZjMn1/micDNziDLY=; h=From:To:Cc:Subject:Date:In-Reply-To:References:From; b=j4qyDf51HPdHHwZ35q1LnwXeGXMd+tqFMfkZh8KVXk806CqCOX4YXKR1PzJvd+ck+ Af1EUm+0rhxhjXMqXOjclSpKqmpf5FrDpzDI55QTwpTzsC0CCAFJpnrjqrpkPsaqMU ESnfaRRardigZ3zp2H0nxM9EGleAssHJi3ePJLos= From: Ben Horgan To: ben.horgan@arm.com Cc: james.morse@arm.com, reinette.chatre@intel.com, fenghuay@nvidia.com, linux-kernel@vger.kernel.org, linux-arm-kernel@lists.infradead.org, dave.martin@arm.com, andre.przywara@arm.com, will@kernel.org, catalin.marinas@kernel.org Subject: [PATCH v1 1/2] arm_mpam: Fix a NULL pointer dereference on unbinding after an error interrupt Date: Thu, 6 Aug 2026 15:46:30 +0100 Message-ID: <20260806144631.2502918-2-ben.horgan@arm.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260806144631.2502918-1-ben.horgan@arm.com> References: <20260806144631.2502918-1-ben.horgan@arm.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" If a user unbinds an MSC after mpam_disable() has been run in response to an error interrupt then a dereference of a NULL pointer occurs as mpam_disable() sets the drvdata to NULL. Add an early return to the driver remove callback to avoid this. Fixes: f04046f2577a ("arm_mpam: Add probe/remove for mpam msc driver and kb= uild boiler plate") Signed-off-by: Ben Horgan --- drivers/resctrl/mpam_devices.c | 3 +++ 1 file changed, 3 insertions(+) diff --git a/drivers/resctrl/mpam_devices.c b/drivers/resctrl/mpam_devices.c index 2f09f4b78bd3..bc6cc0b5c96b 100644 --- a/drivers/resctrl/mpam_devices.c +++ b/drivers/resctrl/mpam_devices.c @@ -2025,6 +2025,9 @@ static void mpam_msc_drv_remove(struct platform_devic= e *pdev) { struct mpam_msc *msc =3D platform_get_drvdata(pdev); =20 + if (!msc) + return; + mutex_lock(&mpam_list_lock); mpam_msc_destroy(msc); mutex_unlock(&mpam_list_lock); --=20 2.43.0 From nobody Fri Oct 2 01:12:58 2026 Received: from foss.arm.com (foss.arm.com [217.140.110.172]) by smtp.subspace.kernel.org (Postfix) with ESMTP id 998644570DC for ; Thu, 6 Aug 2026 14:46:47 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=217.140.110.172 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786027609; cv=none; b=N1yKbikEs87gv2hCnPk1gNdZ/FITCWbbl59xO6/jVasI1OIk8c2Zkfk1fn1uDUzuxlgI0PrLf+uv0n+WI/Qvq4MXjAWZxKao+3+n6S+cjjuetVjAJT1oryn/YhIVrGjY3DpaOToEHo2EY3xEVd8wcN3cx8l2sWwRmvnfP8eteCk= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786027609; c=relaxed/simple; bh=KpzBNNdjie/RT5x1nlv2BU0lhNMLTEMSa3pYVPX9Ksg=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=kgnA1eLuAU2pIXpubwRAfFIsunnNALfW4lyCyYspRURuzTcFEDd7OvkVzCxgwkiMpFHC1jQ5sPPQtg/5YtQYIUtoRstvo5xe0jd6LNniQKHCrXNNEJFDZ0aXW8v2mWsQXoLKG0ejYAwMiay7h+lc7gcEfCNsHJWcWT8VLGH/tNA= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=arm.com; spf=pass smtp.mailfrom=arm.com; dkim=pass (1024-bit key) header.d=arm.com header.i=@arm.com header.b=RmRxN+14; arc=none smtp.client-ip=217.140.110.172 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=arm.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=arm.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=arm.com header.i=@arm.com header.b="RmRxN+14" Received: from usa-sjc-imap-foss1.foss.arm.com (unknown [10.121.207.14]) by usa-sjc-mx-foss1.foss.arm.com (Postfix) with ESMTP id 0AE4B1A25; Thu, 6 Aug 2026 07:46:43 -0700 (PDT) Received: from e134344.cambridge.arm.com (e134344.arm.com [10.2.212.8]) by usa-sjc-imap-foss1.foss.arm.com (Postfix) with ESMTPA id 704183F9A2; Thu, 6 Aug 2026 07:46:45 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=simple/simple; d=arm.com; s=foss; t=1786027607; bh=KpzBNNdjie/RT5x1nlv2BU0lhNMLTEMSa3pYVPX9Ksg=; h=From:To:Cc:Subject:Date:In-Reply-To:References:From; b=RmRxN+14Fh8+XZre+iNVDUkx6Ja/a4Z57JnwfU82wpvaYX+kwQP34IAFqhvSjmYZi Hxf0AWMhIfnxm2S3pBzqS0/+/XjtH4LS1JzzJlbFIf8PzMhfS3kS0oUG4yuo+vDuWz Tu1mdld5OK150e7TPFhxJF4kjwVm7YjeqVQoCWzI= From: Ben Horgan To: ben.horgan@arm.com Cc: james.morse@arm.com, reinette.chatre@intel.com, fenghuay@nvidia.com, linux-kernel@vger.kernel.org, linux-arm-kernel@lists.infradead.org, dave.martin@arm.com, andre.przywara@arm.com, will@kernel.org, catalin.marinas@kernel.org Subject: [PATCH v1 2/2] arm_mpam: Disable driver unbind to avoid UAF Date: Thu, 6 Aug 2026 15:46:31 +0100 Message-ID: <20260806144631.2502918-3-ben.horgan@arm.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260806144631.2502918-1-ben.horgan@arm.com> References: <20260806144631.2502918-1-ben.horgan@arm.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" When a user unbinds an MSC and that MSC is the only MSC left for a component then the corresponding mpam_component will be freed. If the user then goes on to read the schemata file in the resctrl filesystem then the mpam_component will be accessed from resctrl_arch_get_config() leading to a use after free. As the MPAM driver is not a module the unbind sysfs interface is the only way to trigger the remove. Instead of dealing with the complexity of allowing some unused MSC to unbind just remove the unbind sysfs interface. Fixes: f04046f2577a ("arm_mpam: Add probe/remove for mpam msc driver and kb= uild boiler plate") Signed-off-by: Ben Horgan --- drivers/resctrl/mpam_devices.c | 1 + 1 file changed, 1 insertion(+) diff --git a/drivers/resctrl/mpam_devices.c b/drivers/resctrl/mpam_devices.c index bc6cc0b5c96b..e888de8d4896 100644 --- a/drivers/resctrl/mpam_devices.c +++ b/drivers/resctrl/mpam_devices.c @@ -2141,6 +2141,7 @@ static int mpam_msc_drv_probe(struct platform_device = *pdev) static struct platform_driver mpam_msc_driver =3D { .driver =3D { .name =3D "mpam_msc", + .suppress_bind_attrs =3D true, }, .probe =3D mpam_msc_drv_probe, .remove =3D mpam_msc_drv_remove, --=20 2.43.0