[PATCH v3 0/2] cc2520: fix FIFOP work and RX tasklet use-after-free

Fan Wu <[email protected]>
Newsgroups org.kernel.vger.linux-wpan,org.kernel.vger.linux-kernel,org.kernel.vger.netdev,org.kernel.vger.stable
Message-ID <[email protected]>
This series incorporates Miquel Raynal's disable_work_sync()
suggestion and separately fixes the registration-failure path.

Patch 1 fixes the removal path: the FIFOP IRQ can re-queue RX work after
cc2520_remove() flushes it, so the work may run after the private data is
freed.  Disable the work with disable_work_sync() and destroy the buffer
mutex last.

Patch 2 fixes a registration failure: with the FIFOP interrupt requested
before cc2520_register(), a failed registration could leave the mac802154
RX tasklet scheduled across ieee802154_free_hw().  Request the FIFOP
interrupt after registration (and the SFD interrupt before it).

Changes in v3:
- Split into two fixes (removal path, registration failure), per Miquel
  Raynal's review of v2.

Changes in v2:
- Use disable_work_sync() for the FIFOP work instead of explicitly
  freeing the interrupts, as suggested by Miquel Raynal.

Fan Wu (2):
  ieee802154: cc2520: fix FIFOP work use-after-free
  ieee802154: cc2520: fix RX tasklet use-after-free

 drivers/net/ieee802154/cc2520.c | 43 +++++++++++++++++----------------
 1 file changed, 22 insertions(+), 21 deletions(-)

-- 
2.34.1
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.