Re: [PATCH] pinctrl: devicetree: don't free uninitialized dev_name on error path
Linus Walleij <[email protected]>
| Newsgroups | org.kernel.vger.linux-gpio,org.kernel.vger.linux-kernel,org.kernel.vger.stable |
|---|---|
| Message-ID | <CAD++jLnCSVfJy7hgPr2qAwYeJy2wVNMfHoi7aCdJsupEBXaxDQ@mail.gmail.com> |
On Sun, Jul 19, 2026 at 2:11 PM Karl Mehltretter <[email protected]> wrote: > dt_remember_or_free_map() duplicates dev_name for each map entry. If > kstrdup_const() fails, dt_free_map() frees dev_name in all num_maps > entries, including entries that have not been initialized. > > Some pinctrl drivers, including pinctrl-imx, allocate the map with > kmalloc() and leave dev_name for the core to initialize. The untouched > entries therefore contain uninitialized data which is passed to > kfree_const(). > > Reproduced on qemu's mcimx6ul-evk (pinctrl-imx) with failslab injection > while binding the pinctrl-consuming device, under KASAN: > > BUG: KASAN: double-free in dt_free_map+0x34/0xa4 > Free of addr c425a900 by task init/1 > kfree from dt_free_map+0x34/0xa4 > dt_free_map from dt_remember_or_free_map+0x184/0x198 > dt_remember_or_free_map from pinctrl_dt_to_map+0x33c/0x4c8 > pinctrl_dt_to_map from create_pinctrl+0x9c/0x5c0 > > Initialize all dev_name fields to NULL before duplicating the device > name, making the full-map cleanup safe after a partial failure. > > Fixes: be4c60b563ed ("pinctrl: devicetree: Avoid taking direct reference to device name string") > Cc: [email protected] > Assisted-by: Claude:claude-fable-5 > Signed-off-by: Karl Mehltretter <[email protected]> What a good find, patch applied! Yours, Linus Walleij