From nobody Tue Sep 29 14:54:10 2026 Received: from mail-qk1-f170.google.com (mail-qk1-f170.google.com [209.85.222.170]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id E49084B0482 for ; Thu, 6 Aug 2026 23:51:02 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.222.170 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786060264; cv=none; b=WXLiM1ltOTUWzl3yVfngnLm/xLlexlGiOTuhPR5fynzmkgNOA49TcSWAGdKTwYIA52ptJgHVs7vFEyVt/b/McpQryoSrbQlYSRY/r8fkfqPpU9T1w8CwwtIXeEIfh2grRtR9gTc5WIxBqjdxTRolGUsVV+Ck3EBMoao7D41jq+c= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786060264; c=relaxed/simple; bh=Ql00Gi/e8s8Cd29IU6YwV4wqY3+xR87GYOT9JJAAcV8=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=CG2kEX36kVtTVUamJup4oOl+XcO5LZLcaeKDlT1TvrFbePdrZaomUPsMAxVimvpKq/8h93BEEE0HQKDTO4Nh8sVoRtO8Yk3jXbGXH7PINP6IUeeJtiMaCcfnd10wolqwtLqWNfY3JfZEeGc3g8jv5HzHyFzCm6gLlWI+/2K3hYk= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=pb2g+u36; arc=none smtp.client-ip=209.85.222.170 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="pb2g+u36" Received: by mail-qk1-f170.google.com with SMTP id af79cd13be357-92e54f8c051so152696285a.3 for ; Thu, 06 Aug 2026 16:51:02 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1786060262; x=1786665062; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to:content-type; bh=Jn5M2DPxWkJRuSOq4XRDkDeVAclvZgLB7USjbXRxmNs=; b=pb2g+u36qzatmH24RdEXd0BPAB1TXR2UywaSh1mNK4qEatxFDA7o6Sh6N5zzn165Nk yGav3rXApxbUTpJs9GK0bC0hs7F5JPdUqwDxz6jQq9hVcSoPhWDorvsvvBKXNKLsFZ1i x4VneSYG38U0Q08xrz3kvapN6g3/jDJUkjv2o1BPcMvrtot6IxCIsePJMkfZtyRLnJLJ C/5M3JgxxqhJqtPESjvM7ysIsLl5BcZddE2jzS7vKJPPjx2E18li+jH7v3C1wG7u0I4m NzDCi7/E4hHW9m9NvsyU29+mqW6Xd8OTDAk//zfTifs82jgr2QS7ZtITeRP873qnFvWX 7CTw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1786060262; x=1786665062; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=Jn5M2DPxWkJRuSOq4XRDkDeVAclvZgLB7USjbXRxmNs=; b=XDKvRzE7RzXmhRjZ3NBF5LiXB5r3Lp9fGXXvAY/C+KVkj83/MmuQ+w6Ys0IcmHAAAS kY4u29kDTo4jI5mthveTupcABwZLkYaQiEwfh5skOSqIbqavkn8H5mOjG8XhcRU8YisK XlYnNDNR6k/Fv/9qNrYn91fqdKEoWIK88zQW4ZNlf4Efk8UKwX9LYGd0qikC/M4+K18o /Wx0PbfHCrnQNc+gN5svSWPhWRz4nsstFo4L1PtZ1DfLSNh/EOu3Gkkv0roFZlvj8TrQ +sMtS/h4Q0j6FK98IcAAE+BwKpr8FUnmPYyuv/jCadtLaDu4FQijv9Skw8j4PyiD0Q5J y5dA== X-Forwarded-Encrypted: i=1; AHgh+Rr9Q0vOXLXCktl9yW00ojxwEUF3VsGSrXVkqmoDfr14CuPYsyO8kgiGTQtlU016rQ09H0SftgLlDZga4WY=@vger.kernel.org X-Gm-Message-State: AOJu0YzHA+OmgUwcRZgAC4X38fs+WckhGZLJ4e+VCSeTp1CgcThQqQLO HjRWRN/SavOr/CGAYGdQ/clgn7Yem112nT5B5lXpct3J4q2/YgVkXoNYEZKWERxP X-Gm-Gg: AR+sD10jAkLsFb7TiwYY+B0EoHQy7gI1OP+PuHohfspkx2Wi7/DNNOBVP8EVz9MuE23 ocfhU38M41yLzEA/GZvNkv5FSeibfiPOneWoMZmOD/E+nxbVKrvyp6oKjQcUkelaZPHtl0a/xZH qH8ErYEc8d+Bxu3BPw/ejFvPHHHH2juir+CNlTPUWKy9oh4XTxwXlLW3VQwF1KGMh6iV6dyIV7r VCRrD23zerbOjwoQ8zV3qYoSfxx3Ih4g4fAa7WH0FNC4WcCp93h9rdHNNB09aCfNB/O6Ybz09dp 980v/CORXHX/ilHkNnt2ln/RXvgsXHQK8uZlYfvo3EcVuSh+at5c+xKgJuToSweK7WOaz889Nkc 7D1AnZpNNwkVjXawyUByySFlp4MN8Q9oZfHQgr19UiMSCHXBrzyIuRW7DdhegWoQfICRxy91H8X VQOWYHRfoLLGaGrEAyjm2BR+elbRskjFujW9ytPEoxCgvVL8vvZyvNNFqNIaActu1meZsvJrgbU 6lSsXC1NCTsN3DXUyEKRwghuLC6xTivkDPeDYDlDoEY46NjI+xruWI= X-Received: by 2002:a05:620a:a2dc:20b0:92e:8aed:4785 with SMTP id af79cd13be357-936490e7a4bmr1535882085a.25.1786060261714; Thu, 06 Aug 2026 16:51:01 -0700 (PDT) Received: from LAPTOP-DPAKMOI4.it.purdue.edu (pal-210-106-74.itap.purdue.edu. [128.210.106.74]) by smtp.gmail.com with ESMTPSA id af79cd13be357-9366e258edesm25793285a.32.2026.08.06.16.51.00 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 06 Aug 2026 16:51:01 -0700 (PDT) From: Yifei Gao To: Srinivas Kandagatla , Amol Maheshwari Cc: Greg Kroah-Hartman , Arnd Bergmann , Abel Vesa , Ekansh Gupta , linux-arm-msm@vger.kernel.org, dri-devel@lists.freedesktop.org, linaro-mm-sig@lists.linaro.org, linux-kernel@vger.kernel.org, Yifei Gao , stable@vger.kernel.org Subject: [PATCH] misc: fastrpc: fix use-after-free in fastrpc_map_attach() error path Date: Thu, 6 Aug 2026 23:50:54 +0000 Message-ID: <20260806235056.456341-1-gyf161023@gmail.com> X-Mailer: git-send-email 2.43.0 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" map->table is set right after the attachment is mapped, before the len > map->size check. When that check fails and jumps to map_err, the error path manually calls dma_buf_detach() and dma_buf_put(), then falls through to fastrpc_map_put() -> fastrpc_free_map(). Since map->table is still non-NULL, fastrpc_free_map() repeats the cleanup: dma_buf_unmap_attachment_unlocked() dereferences the map->attach already freed by dma_buf_detach() (use-after-free read), and a second dma_buf_put() drops an extra reference on map->buf. As the exporting fd is typically still held by userspace, this imbalance can later lead to premature destruction of the dma_buf and a use-after-free. The branch is reachable by an unprivileged process via FASTRPC_IOCTL_MEM_MAP with an fd whose dma-buf is smaller than the requested length, before any DSP invocation. Clear map->table in the map_err path so the fastrpc_map_put() fallthrough does not operate on the already released attachment and buffer. Fixes: 334f1a1cbe03 ("misc: fastrpc: Use fastrpc_map_put in fastrpc_map_cre= ate on fail") Cc: stable@vger.kernel.org Assisted-by: Claude:claude-opus-4-8 Signed-off-by: Yifei Gao --- drivers/misc/fastrpc.c | 1 + 1 file changed, 1 insertion(+) diff --git a/drivers/misc/fastrpc.c b/drivers/misc/fastrpc.c index f3a49384586d..d6be951d5538 100644 --- a/drivers/misc/fastrpc.c +++ b/drivers/misc/fastrpc.c @@ -915,6 +915,7 @@ static int fastrpc_map_attach(struct fastrpc_user *fl, = int fd, =20 map_err: dma_buf_detach(map->buf, map->attach); + map->table =3D NULL; attach_err: dma_buf_put(map->buf); get_err: --=20 2.43.0