Re: [PATCH] i2c: core: fix debugfs UAF on adapter removal
Andi Shyti <[email protected]> Fri, 31 Jul 2026 23:35:54 +0200
| Newsgroups | org.kernel.vger.linux-i2c,org.kernel.vger.linux-kernel |
|---|---|
| Message-ID | <[email protected]> |
Hi Vasileios, ... > diff --git a/drivers/i2c/i2c-core-base.c b/drivers/i2c/i2c-core-base.c > index 3ec04787a737..b894563f5a75 100644 > --- a/drivers/i2c/i2c-core-base.c > +++ b/drivers/i2c/i2c-core-base.c > @@ -1826,8 +1826,6 @@ void i2c_del_adapter(struct i2c_adapter *adap) > > i2c_host_notify_irq_teardown(adap); > > - debugfs_remove_recursive(adap->debugfs); > - > /* wait until all references to the device are gone > * > * FIXME: This is old code and should ideally be replaced by an > @@ -1839,6 +1837,9 @@ void i2c_del_adapter(struct i2c_adapter *adap) > device_unregister(&adap->dev); > wait_for_completion(&adap->dev_released); > > + /* clients use this directory as their debugfs parent */ > + debugfs_remove_recursive(adap->debugfs); > + Speaking of sysfs, this can't work if a new device is created through the new_device interface. Perhaps you can remove the attribute first with device_remove_file(), but we need to check whether that could lead to a double removal when the device attributes are cleaned up during device removal. Thanks, Andi > /* free bus id */ > mutex_lock(&core_lock); > idr_remove(&i2c_adapter_idr, adap->nr); > -- > 2.47.3 >