Commit 0fb6aa88 authored by Lance Richardson's avatar Lance Richardson Committed by Kaixiong Yu
Browse files

dma: fix call order in dmam_free_coherent

stable inclusion
from stable-v6.6.44
commit 1fe97f68fce1ba24bf823bfb0eb0956003473130
category: bugfix
bugzilla: https://gitee.com/src-openeuler/kernel/issues/IAKQ2W
CVE: CVE-2024-43856

Reference: https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?id=1fe97f68fce1ba24bf823bfb0eb0956003473130

--------------------------------

[ Upstream commit 28e8b7406d3a1f5329a03aa25a43aa28e087cb20 ]

dmam_free_coherent() frees a DMA allocation, which makes the
freed vaddr available for reuse, then calls devres_destroy()
to remove and free the data structure used to track the DMA
allocation. Between the two calls, it is possible for a
concurrent task to make an allocation with the same vaddr
and add it to the devres list.

If this happens, there will be two entries in the devres list
with the same vaddr and devres_destroy() can free the wrong
entry, triggering the WARN_ON() in dmam_match.

Fix by destroying the devres entry before freeing the DMA
allocation.

Tested:
  kokonut //net/encryption
    http://sponge2/b9145fe6-0f72-4325-ac2f-a84d81075b03



Fixes: 9ac7849e ("devres: device resource management")
Signed-off-by: default avatarLance Richardson <rlance@google.com>
Signed-off-by: default avatarChristoph Hellwig <hch@lst.de>
Signed-off-by: default avatarSasha Levin <sashal@kernel.org>
Signed-off-by: default avatarKaixiong Yu <yukaixiong@huawei.com>
parent 683fc19e
Loading
Loading
Loading
Loading
+1 −1
Original line number Diff line number Diff line
@@ -60,8 +60,8 @@ void dmam_free_coherent(struct device *dev, size_t size, void *vaddr,
{
	struct dma_devres match_data = { size, vaddr, dma_handle };

	dma_free_coherent(dev, size, vaddr, dma_handle);
	WARN_ON(devres_destroy(dev, dmam_release, dmam_match, &match_data));
	dma_free_coherent(dev, size, vaddr, dma_handle);
}
EXPORT_SYMBOL(dmam_free_coherent);