From nobody Tue Sep 29 09:09:55 2026 Received: from mail-24428.protonmail.ch (mail-24428.protonmail.ch [109.224.244.28]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 384A93B6367 for ; Mon, 10 Aug 2026 09:58:18 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=109.224.244.28 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786355901; cv=none; b=SkeGQoZiMejrFxAghR+wADgjcaSSEhe69FUNydylq85GAFC5rLYd45K9upyMfHKEKN+9RpE+E6xsjCkoYGIqoMF2iVJoCHQeoUJII9p3UXQCRv3mNZ1ZL7UqjJT1eqH1W3FkBsfMMZK7Fu2iHEw0tTJg3uxVGT6yVJGiaF/uURg= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786355901; c=relaxed/simple; bh=FjkEHMV8CZWrCpqrknnBFBiHfGfqn8UHNDmsIRcjvwo=; h=Date:To:From:Cc:Subject:Message-ID:MIME-Version:Content-Type; b=O2MsESyPjXaOr8rwxQJLeRBvmbaiVG+IJMzXE1pRHlwimXMfcTJoJq+rBpiH/+K3BR2zg+G+3obuj7a45OaJn/tR6N6Ubd/e5/SGG5CEIp6PC1DWfGt7lvkb+jaZrMq+15XTK8hbbep4FAmynZDiXbA85LyLkuA+lbOeEChmnGg= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=protonmail.com; spf=pass smtp.mailfrom=protonmail.com; dkim=pass (2048-bit key) header.d=protonmail.com header.i=@protonmail.com header.b=urbdkUTW; arc=none smtp.client-ip=109.224.244.28 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=quarantine dis=none) header.from=protonmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=protonmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=protonmail.com header.i=@protonmail.com header.b="urbdkUTW" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=protonmail.com; s=protonmail3; t=1786355887; x=1786615087; bh=FjkEHMV8CZWrCpqrknnBFBiHfGfqn8UHNDmsIRcjvwo=; h=Date:To:From:Cc:Subject:Message-ID:Feedback-ID:From:To:Cc:Date: Subject:Reply-To:Feedback-ID:Message-ID:BIMI-Selector; b=urbdkUTWmyojU0WvGdgllvJ/SVQwOK61hFZoP8bbC19X70dBFjdjWugF8iHp/Mi6m Ee60bY9W1HbrO3wFPVxdnicc8QCB9ZKPKXBSDNDAc+G2wbIRi/zt9iRwnCuV4ukzck fF9/mePf8GUG815kQ9Cs8PSutuJPqvgQEWe6owB89RH/h/WNZGfrnkN3FXT3ixJr/a 3swPhzBSpLE/dhDzPu56CDeINjQQPN/V2S47GnCjEOMz87RzV5AqB4Uv1Ohdv7FivS EfyExTT8TnzztP14RJjAklD8RBPxN5GaX++Al3pTyPzbBGbq7NnJrGDzMIqwr4DJx1 Vn8aFNm9rRm7A== Date: Mon, 10 Aug 2026 09:57:59 +0000 To: Felix Fietkau , Lorenzo Bianconi , Ryder Lee , Shayne Chen , Sean Wang , Matthias Brugger , AngeloGioacchino Del Regno From: Ryan Leung Cc: linux-wireless@vger.kernel.org, linux-kernel@vger.kernel.org, linux-arm-kernel@lists.infradead.org, linux-mediatek@lists.infradead.org, Ryan Leung Subject: [PATCH mt76] wifi: mt76: mt7915: fix thermal zone use-after-free on unregister Message-ID: <20260810-mt7915-unregister-thermal-v1-1-c6d57b4cb368@protonmail.com> Feedback-ID: 184418679:user:proton X-Pm-Message-ID: bdfc05f714111930a08a7bf935deca3457c14f2a Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" phy->tzone is registered with devm_thermal_of_zone_register() against the parent device, so its cleanup runs only after .remove() returns. But mt7915_unregister_thermal() never unregisters it, while the phy memory is freed earlier via mt76_free_device()/ieee80211_free_hw() in that same .remove() path, leaving a use-after-free window. Explicitly unregister it with devm_thermal_of_zone_unregister() in mt7915_unregister_thermal() before the phy is freed. While at it, include phy->mt76->band_idx in the dev_warn() message emitted when devm_thermal_of_zone_register() fails, to help identify which band's thermal zone registration failed on multi-band chips. Fixes: 313f1a27ebcb ("wifi: mt76: mt7915: add thermal zone device registrat= ion") Signed-off-by: Ryan Leung --- drivers/net/wireless/mediatek/mt76/mt7915/init.c | 7 +++++-- 1 file changed, 5 insertions(+), 2 deletions(-) diff --git a/drivers/net/wireless/mediatek/mt76/mt7915/init.c b/drivers/net= /wireless/mediatek/mt76/mt7915/init.c index ca46a203aa48..e0376da79dda 100644 --- a/drivers/net/wireless/mediatek/mt76/mt7915/init.c +++ b/drivers/net/wireless/mediatek/mt76/mt7915/init.c @@ -200,6 +200,9 @@ static void mt7915_unregister_thermal(struct mt7915_phy= *phy) { struct wiphy *wiphy =3D phy->mt76->hw->wiphy; =20 + if (phy->tzone) + devm_thermal_of_zone_unregister(phy->dev->mt76.dev, phy->tzone); + if (!phy->cdev) return; =20 @@ -238,8 +241,8 @@ static int mt7915_thermal_init(struct mt7915_phy *phy) if (IS_ERR(phy->tzone)) { if (PTR_ERR(phy->tzone) !=3D -ENODEV) dev_warn(phy->dev->mt76.dev, - "failed to register thermal zone: %ld\n", - PTR_ERR(phy->tzone)); + "failed to register thermal zone %d: %ld\n", + phy->mt76->band_idx, PTR_ERR(phy->tzone)); phy->tzone =3D NULL; } =20 --- base-commit: ca800a9302764c445de0da0e84d2252400a770ee change-id: 20260809-mt7915-unregister-thermal-82e805c618a6 Best regards, -- =20 Ryan Leung