Re: [PATCH v2] power: supply: bq24257: fix use-after-free on remove

Sebastian Reichel <[email protected]>
Newsgroups org.kernel.vger.stable,org.kernel.vger.linux-kernel,org.kernel.vger.linux-pm
Message-ID <178560160420.8893.15196865802852999836.b4-ty@b4>
On Sat, 01 Aug 2026 05:19:58 +0000, Fan Wu wrote:
> The STAT-pin interrupt is devm-managed, so it stays armed until the devm
> cleanup that runs after remove() returns. remove() cancels
> bq->iilimit_setup_work while the threaded handler can still fire; that
> handler reschedules the work and dereferences bq, so the work runs
> against freed memory once devm frees bq.
> 
> Make the delayed work device-managed with devm_delayed_work_autocancel(),
> registered before the interrupt request. The devm cleanup then releases
> the interrupt first, so the handler can no longer reschedule the work,
> and cancels the work before bq is freed. The explicit
> cancel_delayed_work_sync() in remove() is no longer needed and is dropped.
> 
> [...]

Applied, thanks!

[1/1] power: supply: bq24257: fix use-after-free on remove
      commit: 9d34c9d660c3d0931d2cc749c46c47cf31f96e48

Best regards,
-- 
Sebastian Reichel <[email protected]>
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.