Re: [PATCH v3 4/4] HID: wiimote: fix uaf when hid events are handled during destroy
"David Rheinsberg" <[email protected]> Fri, 31 Jul 2026 13:17:41 +0200
| Newsgroups | org.kernel.vger.linux-input |
|---|---|
| Message-ID | <[email protected]> |
Hi On Wed, Jul 29, 2026, at 6:49 PM, Rafael Passos wrote: > In wiimote_destroy, in the time between setting WIIPROTO_FLAG_EXITING > and hid_hw_stop, new events could be handled. > The new behaviour mirrors hid-playstation's output_worker_initialized > flag-gate (source of inspiration). > > This issue was reported as a pre-existign race condition by sashiko. > I confirmed it is possible, but very unlikely. It could only happen if > shutdown is initiated by Linux, and the controller is being used. `hdev->driver_input_lock` serializes all probe/remove/event callbacks. Can you elaborate how this is triggered? I can see that external APIs like debugfs and other sysfs registrations can trigger this, but they are deinitialized before cancelling the work, aren't they? Thanks David > Signed-off-by: Rafael Passos <[email protected]> > --- > drivers/hid/hid-wiimote-core.c | 3 +++ > 1 file changed, 3 insertions(+) > > diff --git a/drivers/hid/hid-wiimote-core.c > b/drivers/hid/hid-wiimote-core.c > index 31ee86affc553..067db8b8a56d1 100644 > --- a/drivers/hid/hid-wiimote-core.c > +++ b/drivers/hid/hid-wiimote-core.c > @@ -92,6 +92,9 @@ static void wiimote_queue(struct wiimote_data *wdata, > const __u8 *buffer, > */ > > spin_lock_irqsave(&wdata->queue.lock, flags); > + /* Do not schedule work if controller is exiting */ > + if ((wdata->state.flags & WIIPROTO_FLAG_EXITING)) > + goto out_unlock; > > memcpy(wdata->queue.outq[wdata->queue.head].data, buffer, count); > wdata->queue.outq[wdata->queue.head].size = count; > -- > 2.53.0