]> git.ipfire.org Git - thirdparty/kernel/linux.git/commitdiff
hwmon: (gigabyte_waterforce) Stop device IO before calling hid_hw_stop
authorGuenter Roeck <linux@roeck-us.net>
Wed, 8 Jul 2026 00:59:10 +0000 (17:59 -0700)
committerGuenter Roeck <linux@roeck-us.net>
Wed, 8 Jul 2026 03:03:00 +0000 (20:03 -0700)
Calling hid_hw_stop() does not stop the device IO.
This results in a race condition between hid_input_report() and the point
immediately following the execution of hid_device_io_start() within
the driver probe function. If the probe operation fails after "io start"
has been initiated, this race condition will result in a UAF vulnerability.

Fix the problem by calling hid_device_io_stop() before calling
hid_hw_stop().

Reported-by: Sashiko <sashiko-bot@kernel.org>
Fixes: 42ac68e3d4ba0 ("hwmon: Add driver for Gigabyte AORUS Waterforce AIO coolers")
Signed-off-by: Guenter Roeck <linux@roeck-us.net>
drivers/hwmon/gigabyte_waterforce.c

index 27487e215bddff5a4110464868346910a7768b55..4eea05f8b569c2344804bd9d542550169ad86726 100644 (file)
@@ -371,13 +371,15 @@ static int waterforce_probe(struct hid_device *hdev, const struct hid_device_id
        if (IS_ERR(priv->hwmon_dev)) {
                ret = PTR_ERR(priv->hwmon_dev);
                hid_err(hdev, "hwmon registration failed with %d\n", ret);
-               goto fail_and_close;
+               goto fail_and_io_stop;
        }
 
        waterforce_debugfs_init(priv);
 
        return 0;
 
+fail_and_io_stop:
+       hid_device_io_stop(hdev);
 fail_and_close:
        hid_hw_close(hdev);
 fail_and_stop: