From: Xion Wang Date: Thu, 4 Sep 2025 06:37:04 +0000 (+0800) Subject: char: Use list_del_init() in misc_deregister() to reinitialize list pointer X-Git-Tag: v6.18-rc1~74^2~31 X-Git-Url: http://git.ipfire.org/cgi-bin/gitweb.cgi?a=commitdiff_plain;h=e28022873c0d051e980c4145f1965cab5504b498;p=thirdparty%2Fkernel%2Flinux.git char: Use list_del_init() in misc_deregister() to reinitialize list pointer Currently, misc_deregister() uses list_del() to remove the device from the list. After list_del(), the list pointers are set to LIST_POISON1 and LIST_POISON2, which may help catch use-after-free bugs, but does not reset the list head. If misc_deregister() is called more than once on the same device, list_empty() will not return true, and list_del() may be called again, leading to undefined behavior. Replace list_del() with list_del_init() to reinitialize the list head after deletion. This makes the code more robust against double deregistration and allows safe usage of list_empty() on the miscdevice after deregistration. [ Note, this seems to keep broken out-of-tree drivers from doing foolish things. While this does not matter for any in-kernel drivers, external drivers could use a bit of help to show them they shouldn't be doing stuff like re-registering misc devices - gregkh ] Signed-off-by: Xion Wang Link: https://lore.kernel.org/r/20250904063714.28925-2-xion.wang@mediatek.com Signed-off-by: Greg Kroah-Hartman --- diff --git a/drivers/char/misc.c b/drivers/char/misc.c index 69e8ce02e099f..726516fb0a3ba 100644 --- a/drivers/char/misc.c +++ b/drivers/char/misc.c @@ -284,7 +284,7 @@ EXPORT_SYMBOL(misc_register); void misc_deregister(struct miscdevice *misc) { mutex_lock(&misc_mtx); - list_del(&misc->list); + list_del_init(&misc->list); device_destroy(&misc_class, MKDEV(MISC_MAJOR, misc->minor)); misc_minor_free(misc->minor); if (misc->minor > MISC_DYNAMIC_MINOR)