Re: [PATCH v2] power: supply: bq24257: fix use-after-free on remove

Sebastian Reichel <[email protected]> Sat, 01 Aug 2026 18:26:44 +0200
Newsgroups org.kernel.vger.linux-pm,org.kernel.vger.linux-kernel,org.kernel.vger.stable
Message-ID <178560160420.8893.15196865802852999836.b4-ty@b4>
On Sat, 01 Aug 2026 05:19:58 +0000, Fan Wu wrote:
> The STAT-pin interrupt is devm-managed, so it stays armed until the devm
> cleanup that runs after remove() returns. remove() cancels
> bq->iilimit_setup_work while the threaded handler can still fire; that
> handler reschedules the work and dereferences bq, so the work runs
> against freed memory once devm frees bq.
> 
> Make the delayed work device-managed with devm_delayed_work_autocancel(),
> registered before the interrupt request. The devm cleanup then releases
> the interrupt first, so the handler can no longer reschedule the work,
> and cancels the work before bq is freed. The explicit
> cancel_delayed_work_sync() in remove() is no longer needed and is dropped.
> 
> [...]

Applied, thanks!

[1/1] power: supply: bq24257: fix use-after-free on remove
      commit: 9d34c9d660c3d0931d2cc749c46c47cf31f96e48

Best regards,
-- 
Sebastian Reichel <[email protected]>