]> git.ipfire.org Git - thirdparty/kernel/linux.git/commitdiff
watchdog: pretimeout: Fix UAF in watchdog_unregister_governor()
authorTzung-Bi Shih <tzungbi@kernel.org>
Tue, 7 Jul 2026 10:18:03 +0000 (10:18 +0000)
committerGuenter Roeck <linux@roeck-us.net>
Wed, 8 Jul 2026 14:06:59 +0000 (07:06 -0700)
When a watchdog governor is unregistered, it updates existing watchdog
devices that were using this governor by falling back to `default_gov`.

If the governor being unregistered is currently set as `default_gov`,
the `default_gov` is never cleared.  This leads to 2 use-after-free
issues:
1. New watchdog devices registered after this point will inherit the
   dangling `default_gov`.
2. Existing watchdog devices using the unregistered governor will have
   their `wdd->gov` reassigned to the dangling `default_gov`.

Fix the UAF by clearing `default_gov` if it matches the governor being
unregistered.

Fixes: da0d12ff2b82 ("watchdog: pretimeout: add panic pretimeout governor")
Signed-off-by: Tzung-Bi Shih <tzungbi@kernel.org>
Link: https://lore.kernel.org/r/20260707101803.3598173-1-tzungbi@kernel.org
Signed-off-by: Guenter Roeck <linux@roeck-us.net>
drivers/watchdog/watchdog_pretimeout.c

index 19eb2ed2c7cb0e4e786bc90ac398466a94a2d3cf..02e09b9e396dab212f702c900bd46c4a1fed008b 100644 (file)
@@ -167,6 +167,8 @@ void watchdog_unregister_governor(struct watchdog_governor *gov)
        }
 
        spin_lock_irq(&pretimeout_lock);
+       if (default_gov == gov)
+               default_gov = NULL;
        list_for_each_entry(p, &pretimeout_list, entry)
                if (p->wdd->gov == gov)
                        p->wdd->gov = default_gov;