Re: [PATCH] watchdog: pretimeout: Fix UAF in watchdog_unregister_governor()

Guenter Roeck <[email protected]> Wed, 8 Jul 2026 07:06:39 -0700
Newsgroups org.kernel.vger.linux-watchdog,org.kernel.vger.linux-kernel
Message-ID <[email protected]>
On Tue, Jul 07, 2026 at 10:18:03AM +0000, Tzung-Bi Shih wrote:
> When a watchdog governor is unregistered, it updates existing watchdog
> devices that were using this governor by falling back to `default_gov`.
> 
> If the governor being unregistered is currently set as `default_gov`,
> the `default_gov` is never cleared.  This leads to 2 use-after-free
> issues:
> 1. New watchdog devices registered after this point will inherit the
>    dangling `default_gov`.
> 2. Existing watchdog devices using the unregistered governor will have
>    their `wdd->gov` reassigned to the dangling `default_gov`.
> 
> Fix the UAF by clearing `default_gov` if it matches the governor being
> unregistered.
> 
> Fixes: da0d12ff2b82 ("watchdog: pretimeout: add panic pretimeout governor")
> Signed-off-by: Tzung-Bi Shih <[email protected]>

Applied.

Thanks,
Guenter

> ---
>  drivers/watchdog/watchdog_pretimeout.c | 2 ++
>  1 file changed, 2 insertions(+)
> 
> diff --git a/drivers/watchdog/watchdog_pretimeout.c b/drivers/watchdog/watchdog_pretimeout.c
> index 19eb2ed2c7cb..02e09b9e396d 100644
> --- a/drivers/watchdog/watchdog_pretimeout.c
> +++ b/drivers/watchdog/watchdog_pretimeout.c
> @@ -167,6 +167,8 @@ void watchdog_unregister_governor(struct watchdog_governor *gov)
>  	}
>  
>  	spin_lock_irq(&pretimeout_lock);
> +	if (default_gov == gov)
> +		default_gov = NULL;
>  	list_for_each_entry(p, &pretimeout_list, entry)
>  		if (p->wdd->gov == gov)
>  			p->wdd->gov = default_gov;