]> git.ipfire.org Git - thirdparty/kernel/stable.git/commitdiff
spi: tegra210-quad: Protect curr_xfer in tegra_qspi_combined_seq_xfer
authorBreno Leitao <leitao@debian.org>
Mon, 26 Jan 2026 17:50:29 +0000 (09:50 -0800)
committerGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Wed, 11 Feb 2026 12:42:00 +0000 (13:42 +0100)
[ Upstream commit bf4528ab28e2bf112c3a2cdef44fd13f007781cd ]

The curr_xfer field is read by the IRQ handler without holding the lock
to check if a transfer is in progress. When clearing curr_xfer in the
combined sequence transfer loop, protect it with the spinlock to prevent
a race with the interrupt handler.

Protect the curr_xfer clearing at the exit path of
tegra_qspi_combined_seq_xfer() with the spinlock to prevent a race
with the interrupt handler that reads this field.

Without this protection, the IRQ handler could read a partially updated
curr_xfer value, leading to NULL pointer dereference or use-after-free.

Fixes: b4e002d8a7ce ("spi: tegra210-quad: Fix timeout handling")
Signed-off-by: Breno Leitao <leitao@debian.org>
Tested-by: Jon Hunter <jonathanh@nvidia.com>
Acked-by: Jon Hunter <jonathanh@nvidia.com>
Acked-by: Thierry Reding <treding@nvidia.com>
Link: https://patch.msgid.link/20260126-tegra_xfer-v2-4-6d2115e4f387@debian.org
Signed-off-by: Mark Brown <broonie@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
drivers/spi/spi-tegra210-quad.c

index 6d89a9309d85e86a5fc9399b578047e495641752..78e26c25a7b3554301d69e73b542c893b0e2ac6a 100644 (file)
@@ -1089,6 +1089,7 @@ static int tegra_qspi_combined_seq_xfer(struct tegra_qspi *tqspi,
        u32 address_value = 0;
        u32 cmd_config = 0, addr_config = 0;
        u8 cmd_value = 0, val = 0;
+       unsigned long flags;
 
        /* Enable Combined sequence mode */
        val = tegra_qspi_readl(tqspi, QSPI_GLOBAL_CONFIG);
@@ -1207,13 +1208,17 @@ static int tegra_qspi_combined_seq_xfer(struct tegra_qspi *tqspi,
                        tegra_qspi_transfer_end(spi);
                        spi_transfer_delay_exec(xfer);
                }
+               spin_lock_irqsave(&tqspi->lock, flags);
                tqspi->curr_xfer = NULL;
+               spin_unlock_irqrestore(&tqspi->lock, flags);
                transfer_phase++;
        }
        ret = 0;
 
 exit:
+       spin_lock_irqsave(&tqspi->lock, flags);
        tqspi->curr_xfer = NULL;
+       spin_unlock_irqrestore(&tqspi->lock, flags);
        msg->status = ret;
 
        return ret;