]> git.ipfire.org Git - thirdparty/kernel/stable.git/commitdiff
pmdomain: mediatek: fix use-after-free in scpsys_get_bus_protection_legacy()
authorWentao Liang <vulab@iscas.ac.cn>
Wed, 8 Apr 2026 14:11:21 +0000 (14:11 +0000)
committerUlf Hansson <ulf.hansson@linaro.org>
Mon, 27 Apr 2026 12:53:30 +0000 (14:53 +0200)
In scpsys_get_bus_protection_legacy(), of_find_node_with_property()
returns a device node with its reference count incremented. The function
then calls of_node_put(node) before checking whether
syscon_regmap_lookup_by_phandle() returns an error. If an error occurs,
dev_err_probe() dereferences the node pointer to print diagnostic
information, but the node memory may have already been freed due to the
earlier of_node_put(), leading to a use-after-free vulnerability.

Fix this by moving the of_node_put() call after the error check, ensuring
the node is still valid when accessed in the error path.

Fixes: c29345fa5f66 ("pmdomain: mediatek: Refactor bus protection regmaps retrieval")
Cc: stable@vger.kernel.org
Signed-off-by: Wentao Liang <vulab@iscas.ac.cn>
Signed-off-by: Ulf Hansson <ulf.hansson@linaro.org>
drivers/pmdomain/mediatek/mtk-pm-domains.c

index d2b8d0332951537c190d1138edeeb10801473c30..e1cfd42234734f3c13872e79001840743b1b8bd4 100644 (file)
@@ -1015,6 +1015,7 @@ static int scpsys_get_bus_protection_legacy(struct device *dev, struct scpsys *s
        struct device_node *node, *smi_np;
        int num_regmaps = 0, i, j;
        struct regmap *regmap[3];
+       int ret = 0;
 
        /*
         * Legacy code retrieves a maximum of three bus protection handles:
@@ -1065,11 +1066,14 @@ static int scpsys_get_bus_protection_legacy(struct device *dev, struct scpsys *s
        if (node) {
                regmap[2] = syscon_regmap_lookup_by_phandle(node, "mediatek,infracfg-nao");
                num_regmaps++;
-               of_node_put(node);
-               if (IS_ERR(regmap[2]))
-                       return dev_err_probe(dev, PTR_ERR(regmap[2]),
+               if (IS_ERR(regmap[2])) {
+                       ret = dev_err_probe(dev, PTR_ERR(regmap[2]),
                                             "%pOF: failed to get infracfg regmap\n",
                                             node);
+                       of_node_put(node);
+                       return ret;
+               }
+               of_node_put(node);
        } else {
                regmap[2] = NULL;
        }