[PATCH 0/2] ata: pata_parport: fix UAF on protocol module unload

Pei Xiao posted 2 patches 3 weeks, 2 days ago
There is a newer version of this series
drivers/ata/pata_parport/pata_parport.c | 27 +++++++++++++++++++++----
1 file changed, 23 insertions(+), 4 deletions(-)
[PATCH 0/2] ata: pata_parport: fix UAF on protocol module unload
Posted by Pei Xiao 3 weeks, 2 days ago
This series fixes use-after-free issues in pata_parport when a protocol
module goes away while pi_adapter devices created by it are still
attached.

Patch 1 pins the protocol module before the device becomes visible.
Previously try_module_get() ran after device_register(), so a forced
module unload in between left pi->proto dangling from the moment the
device appeared on the bus.

Patch 2 makes pata_parport_unregister_driver() tear down all adapters
using the protocol. Without this, the rollback path of a multi-protocol
module init (e.g. kbic registering k951 then k971) left the devices of
the already-registered protocol alive while the module loader freed the
module memory; removing such a dangling device later crashed in
pi_disconnect() dereferencing pi->proto->disconnect.

Pei Xiao (2):
  ata: pata_parport: pin the protocol module before device_register()
  ata: pata_parport: unregister devices on protocol unregister

 drivers/ata/pata_parport/pata_parport.c | 27 +++++++++++++++++++++----
 1 file changed, 23 insertions(+), 4 deletions(-)

-- 
2.25.1