[PATCH v2] driver core: avoid klist_remove() on unattached knode_driver
Nguyen Quang Le Kien <[email protected]>
| Newsgroups | dev.linux.lists.driver-core,org.kernel.vger.linux-kernel,org.kernel.vger.linux-usb |
|---|---|
| Message-ID | <[email protected]> |
usb_driver_claim_interface() sets dev->driver directly and skips device_bind_driver() when the interface is not yet registered, so the device can reach teardown with dev->driver set but knode_driver never added to the driver's klist_devices. __device_release_driver() then unconditionally calls klist_remove() on the unattached node, which dereferences a NULL klist pointer in klist_put() and crashes. Only remove the node if the device is actually bound, mirroring the check device_is_bound() already provides for the driver core. This matches the existing guard on knode_bus in bus_remove_device(). Reported-by: [email protected] Closes: https://syzkaller.appspot.com/bug?extid=87188222c77c0dbbdb4d Signed-off-by: Nguyen Quang Le Kien <[email protected]> --- drivers/base/dd.c | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/drivers/base/dd.c b/drivers/base/dd.c index 60c005223..4154b4499 100644 --- a/drivers/base/dd.c +++ b/drivers/base/dd.c @@ -1354,7 +1354,8 @@ static void __device_release_driver(struct device *dev, struct device *parent) device_unbind_cleanup(dev); device_links_driver_cleanup(dev); - klist_remove(&dev->p->knode_driver); + if (device_is_bound(dev)) + klist_remove(&dev->p->knode_driver); device_pm_check_callbacks(dev); bus_notify(dev, BUS_NOTIFY_UNBOUND_DRIVER); -- 2.34.1