]> git.ipfire.org Git - thirdparty/linux.git/commit
dmaengine: mmp_pdma: Fix race condition in mmp_pdma_residue()
authorGuodong Xu <guodong@riscstar.com>
Tue, 16 Dec 2025 14:10:06 +0000 (22:10 +0800)
committerVinod Koul <vkoul@kernel.org>
Tue, 16 Dec 2025 14:58:39 +0000 (20:28 +0530)
commita143545855bc2c6e1330f6f57ae375ac44af00a7
tree94f36fc0a06bc6f99e7835acca7a9675a003d79a
parent430f7803b69cd5e5694e5dfc884c6628870af36e
dmaengine: mmp_pdma: Fix race condition in mmp_pdma_residue()

Add proper locking in mmp_pdma_residue() to prevent use-after-free when
accessing descriptor list and descriptor contents.

The race occurs when multiple threads call tx_status() while the tasklet
on another CPU is freeing completed descriptors:

CPU 0                              CPU 1
-----                              -----
mmp_pdma_tx_status()
mmp_pdma_residue()
  -> NO LOCK held
     list_for_each_entry(sw, ..)
                                   DMA interrupt
                                   dma_do_tasklet()
                                     -> spin_lock(&desc_lock)
                                        list_move(sw->node, ...)
                                        spin_unlock(&desc_lock)
  |                                     dma_pool_free(sw) <- FREED!
  -> access sw->desc <- UAF!

This issue can be reproduced when running dmatest on the same channel with
multiple threads (threads_per_chan > 1).

Fix by protecting the chain_running list iteration and descriptor access
with the chan->desc_lock spinlock.

Signed-off-by: Juan Li <lijuan@linux.spacemit.com>
Signed-off-by: Guodong Xu <guodong@riscstar.com>
Link: https://patch.msgid.link/20251216-mmp-pdma-race-v1-1-976a224bb622@riscstar.com
Signed-off-by: Vinod Koul <vkoul@kernel.org>
drivers/dma/mmp_pdma.c