[PATCH] misc: nsm: pin the module while the device is open

raoxu posted 1 patch 1 week, 5 days ago
drivers/misc/nsm.c | 1 +
1 file changed, 1 insertion(+)
[PATCH] misc: nsm: pin the module while the device is open
Posted by raoxu 1 week, 5 days ago
From: Xu Rao <raoxu@uniontech.com>

misc_open() installs a misc driver's file operations with fops_get(),
which pins file_operations::owner before replacing the file's f_op.  The
NSM misc device leaves nsm_dev_fops.owner unset, so opening /dev/nsm does
not take a module reference on the nsm driver.

If the driver is built as a module, an open file descriptor can therefore
survive rmmod of the module that provides its ioctl callbacks.  A later
ioctl through that descriptor can call into unloaded module text.

Set nsm_dev_fops.owner to THIS_MODULE so the misc core holds the module
while any /dev/nsm file descriptor is open, matching the lifetime
expectation for the installed file operations.

Fixes: b9873755a6c8 ("misc: Add Nitro Secure Module driver")
Cc: stable@vger.kernel.org
Signed-off-by: Xu Rao <raoxu@uniontech.com>
---
 drivers/misc/nsm.c | 1 +
 1 file changed, 1 insertion(+)

diff --git a/drivers/misc/nsm.c b/drivers/misc/nsm.c
index ef7b32742340..e7b63a358df5 100644
--- a/drivers/misc/nsm.c
+++ b/drivers/misc/nsm.c
@@ -413,6 +413,7 @@ static int nsm_device_init_vq(struct virtio_device *vdev)
 }

 static const struct file_operations nsm_dev_fops = {
+	.owner = THIS_MODULE,
 	.unlocked_ioctl = nsm_dev_ioctl,
 	.compat_ioctl = compat_ptr_ioctl,
 };
--
2.50.1