]> git.ipfire.org Git - thirdparty/linux.git/commitdiff
misc: nsm: pin the module while the device is open
authorXu Rao <raoxu@uniontech.com>
Mon, 13 Jul 2026 05:55:23 +0000 (13:55 +0800)
committerGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Fri, 17 Jul 2026 12:51:57 +0000 (14:51 +0200)
misc_open() installs a misc driver's file operations with fops_get(),
which pins file_operations::owner before replacing the file's f_op.  The
NSM misc device leaves nsm_dev_fops.owner unset, so opening /dev/nsm does
not take a module reference on the nsm driver.

If the driver is built as a module, an open file descriptor can therefore
survive rmmod of the module that provides its ioctl callbacks.  A later
ioctl through that descriptor can call into unloaded module text.

Set nsm_dev_fops.owner to THIS_MODULE so the misc core holds the module
while any /dev/nsm file descriptor is open, matching the lifetime
expectation for the installed file operations.

Fixes: b9873755a6c8 ("misc: Add Nitro Secure Module driver")
Cc: stable <stable@kernel.org>
Signed-off-by: Xu Rao <raoxu@uniontech.com>
Link: https://patch.msgid.link/BE6951D13B5E5513+20260713055523.3193089-1-raoxu@uniontech.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
drivers/misc/nsm.c

index 185900cdad4a77defcecd215a8e179c513a47858..3960506eb7ab3d3045b4c96c1246d874158ca513 100644 (file)
@@ -413,6 +413,7 @@ static int nsm_device_init_vq(struct virtio_device *vdev)
 }
 
 static const struct file_operations nsm_dev_fops = {
+       .owner = THIS_MODULE,
        .unlocked_ioctl = nsm_dev_ioctl,
        .compat_ioctl = compat_ptr_ioctl,
 };