From: Greg Kroah-Hartman Date: Tue, 24 Nov 2020 18:09:49 +0000 (+0100) Subject: 5.4-stable patches X-Git-Tag: v4.4.247~53 X-Git-Url: http://git.ipfire.org/gitweb.cgi?a=commitdiff_plain;h=e5d207545739b387de9a617dbe164544c30a4209;p=thirdparty%2Fkernel%2Fstable-queue.git 5.4-stable patches added patches: spi-bcm2835-fix-use-after-free-on-unbind.patch --- diff --git a/queue-5.4/series b/queue-5.4/series index d4bd8a2c5f1..b633d70ae66 100644 --- a/queue-5.4/series +++ b/queue-5.4/series @@ -1 +1,2 @@ spi-bcm-qspi-fix-use-after-free-on-unbind.patch +spi-bcm2835-fix-use-after-free-on-unbind.patch diff --git a/queue-5.4/spi-bcm2835-fix-use-after-free-on-unbind.patch b/queue-5.4/spi-bcm2835-fix-use-after-free-on-unbind.patch new file mode 100644 index 00000000000..252f0feb53e --- /dev/null +++ b/queue-5.4/spi-bcm2835-fix-use-after-free-on-unbind.patch @@ -0,0 +1,83 @@ +From foo@baz Tue Nov 24 07:07:33 PM CET 2020 +From: Lukas Wunner +Date: Wed, 11 Nov 2020 20:07:20 +0100 +Subject: spi: bcm2835: Fix use-after-free on unbind + +From: Lukas Wunner + +commit e1483ac030fb4c57734289742f1c1d38dca61e22 upstream + +bcm2835_spi_remove() accesses the driver's private data after calling +spi_unregister_controller() even though that function releases the last +reference on the spi_controller and thereby frees the private data. + +Fix by switching over to the new devm_spi_alloc_master() helper which +keeps the private data accessible until the driver has unbound. + +Fixes: f8043872e796 ("spi: add driver for BCM2835") +Reported-by: Sascha Hauer +Reported-by: Florian Fainelli +Signed-off-by: Lukas Wunner +Cc: # v3.10+: 123456789abc: spi: Introduce device-managed SPI controller allocation +Cc: # v3.10+ +Cc: Vladimir Oltean +Tested-by: Florian Fainelli +Acked-by: Florian Fainelli +Link: https://lore.kernel.org/r/ad66e0a0ad96feb848814842ecf5b6a4539ef35c.1605121038.git.lukas@wunner.de +Signed-off-by: Mark Brown +[sudip: dev_err_probe() not yet available] +Signed-off-by: Sudip Mukherjee +Signed-off-by: Greg Kroah-Hartman +--- + drivers/spi/spi-bcm2835.c | 18 ++++++------------ + 1 file changed, 6 insertions(+), 12 deletions(-) + +--- a/drivers/spi/spi-bcm2835.c ++++ b/drivers/spi/spi-bcm2835.c +@@ -1264,7 +1264,7 @@ static int bcm2835_spi_probe(struct plat + struct bcm2835_spi *bs; + int err; + +- ctlr = spi_alloc_master(&pdev->dev, ALIGN(sizeof(*bs), ++ ctlr = devm_spi_alloc_master(&pdev->dev, ALIGN(sizeof(*bs), + dma_get_cache_alignment())); + if (!ctlr) + return -ENOMEM; +@@ -1284,23 +1284,19 @@ static int bcm2835_spi_probe(struct plat + bs = spi_controller_get_devdata(ctlr); + + bs->regs = devm_platform_ioremap_resource(pdev, 0); +- if (IS_ERR(bs->regs)) { +- err = PTR_ERR(bs->regs); +- goto out_controller_put; +- } ++ if (IS_ERR(bs->regs)) ++ return PTR_ERR(bs->regs); + + bs->clk = devm_clk_get(&pdev->dev, NULL); + if (IS_ERR(bs->clk)) { + err = PTR_ERR(bs->clk); + dev_err(&pdev->dev, "could not get clk: %d\n", err); +- goto out_controller_put; ++ return err; + } + + bs->irq = platform_get_irq(pdev, 0); +- if (bs->irq <= 0) { +- err = bs->irq ? bs->irq : -ENODEV; +- goto out_controller_put; +- } ++ if (bs->irq <= 0) ++ return bs->irq ? bs->irq : -ENODEV; + + clk_prepare_enable(bs->clk); + +@@ -1330,8 +1326,6 @@ static int bcm2835_spi_probe(struct plat + + out_clk_disable: + clk_disable_unprepare(bs->clk); +-out_controller_put: +- spi_controller_put(ctlr); + return err; + } +