Re: [PATCH] HID: amd_sfh: clear hid_sensor_hubs entry on probe failure

Jiri Kosina <[email protected]> Mon, 3 Aug 2026 19:52:18 +0200 (CEST)
Newsgroups org.kernel.vger.linux-input,org.kernel.vger.linux-kernel
Message-ID <[email protected]>
On Wed, 15 Jul 2026, Chen Changcheng wrote:

> In amdtp_hid_probe(), the newly allocated HID device is stored in
> cli_data->hid_sensor_hubs[cur_hid_dev] before calling hid_add_device().
> If hid_add_device() fails, the error path frees the HID device and its
> driver_data but does not clear the array entry, leaving a dangling
> pointer.
> 
> When the caller (amd_sfh_hid_client_init or
> amd_sfh1_1_hid_client_init) detects the probe failure, it jumps to its
> cleanup label, which unconditionally calls amd_sfh_hid_client_deinit()
> and subsequently amdtp_hid_remove(). The latter iterates over all
> hid_sensor_hubs[] entries and, upon encountering the non-NULL but freed
> pointer, performs a use-after-free read followed by double-free of both
> the HID device and its driver_data.
> 
> Clear the array entry in the error path of amdtp_hid_probe() so that
> amdtp_hid_remove() skips the failed entry.

Applied, thanks.

-- 
Jiri Kosina
SUSE Labs