]> git.ipfire.org Git - thirdparty/kernel/linux.git/commitdiff
auxdisplay: line-display: fix NULL dereference in linedisp_release
authorGuangshuo Li <lgs201920130244@gmail.com>
Thu, 26 Mar 2026 17:14:12 +0000 (01:14 +0800)
committerAndy Shevchenko <andriy.shevchenko@linux.intel.com>
Fri, 27 Mar 2026 08:54:31 +0000 (09:54 +0100)
linedisp_release() currently retrieves the enclosing struct linedisp via
to_linedisp(). That lookup depends on the attachment list, but the
attachment may already have been removed before put_device() invokes the
release callback. This can happen in linedisp_unregister(), and can also
be reached from some linedisp_register() error paths.

In that case, to_linedisp() returns NULL and linedisp_release()
dereferences it while freeing the display resources.

The struct device released here is the embedded linedisp->dev used by
linedisp_register(), so retrieve the enclosing object directly with
container_of() instead.

Fixes: 66c93809487e ("auxdisplay: linedisp: encapsulate container_of usage within to_linedisp")
Cc: stable@vger.kernel.org
Signed-off-by: Guangshuo Li <lgs201920130244@gmail.com>
Reviewed-by: Geert Uytterhoeven <geert@linux-m68k.org>
Signed-off-by: Andy Shevchenko <andriy.shevchenko@linux.intel.com>
drivers/auxdisplay/line-display.c

index 81b4aac65807db783b00e656e8a45bb65bc8afbc..fb6d9294140d997c19097758ad0d094a0bc52f87 100644 (file)
@@ -365,7 +365,7 @@ static DEFINE_IDA(linedisp_id);
 
 static void linedisp_release(struct device *dev)
 {
-       struct linedisp *linedisp = to_linedisp(dev);
+       struct linedisp *linedisp = container_of(dev, struct linedisp, dev);
 
        kfree(linedisp->map);
        kfree(linedisp->message);