[PATCH v2 0/2] gpio: sloppy-logic-analyzer: fix debugfs UAF on unbind

Cengiz Can <[email protected]> Fri, 31 Jul 2026 01:02:56 +0300
Newsgroups org.kernel.vger.linux-gpio,org.kernel.vger.linux-kernel
Message-ID <[email protected]>
Patch 1 fixes a use-after-free. The "trigger" debugfs file uses
debugfs_create_file_unsafe() with a hand-rolled ->write that dereferences
the devres-freed gpio_la_poll_priv without holding a debugfs reference, so
an unbind racing a write frees the object under the handler. Switching to
debugfs_create_file() makes debugfs_remove_recursive() drain the handler
first.

Patch 2 converts the sibling "buf_size" and "capture" files to
debugfs_create_file() as well, for consistency. They were already safe via
DEFINE_DEBUGFS_ATTRIBUTE(); this is the cleanup requested on v1.

v1 was a single patch that fixed only "trigger". v2 splits it so the fix
carries the stable tag on its own, and adds the consistency conversion as a
separate cleanup.

Note: while testing this I found a pre-existing deadlock in the driver
(gpio_la_poll_remove() holds blob_lock across debugfs_remove_recursive(),
which drains the buf_size/capture handlers that also take blob_lock). It is
unrelated to this series; I will send it separately.

Cengiz Can (2):
  gpio: sloppy-logic-analyzer: fix use-after-free via debugfs trigger on
    unbind
  gpio: sloppy-logic-analyzer: use debugfs_create_file() for buf_size
    and capture

 drivers/gpio/gpio-sloppy-logic-analyzer.c | 6 +++---
 1 file changed, 3 insertions(+), 3 deletions(-)

-- 
2.43.0