From e873c74132f0c5f1452816cd9bb26208f0bba1e1 Mon Sep 17 00:00:00 2001 From: Shivank Garg Date: Sat, 22 Aug 2026 19:22:05 +0000 Subject: dmaengine: fix use-after-free in dma_chan_put() and dma_release_channel() When dma_device_put() drops the last reference on chan->device->ref, dma_device_release() runs and may free the dma_device along with its channels. dma_chan_put() then still reads chan->device->owner via dma_chan_to_owner() for the trailing module_put(). KASAN catches it: slab-use-after-free in dma_chan_put+0x3e6/0x4c0 Read of size 8 by task insmod/6319 Freed by task 6319: kfree+0x225/0x470 dma_chan_put+0x395/0x4c0 dmaengine_put+0xf8/0x160 Cache the module owner in dma_chan_put() before the put so the trailing module_put() does not need chan->device. Fixes: 8ad342a86359 ("dmaengine: Add reference counting to dma_device struct") Suggested-by: Sashiko Link: https://sashiko.dev/#/patchset/20260518-dmaengine-kref-fix-v1-1-4d6125048fb7@amd.com Reviewed-by: Frank Li Reviewed-by: Logan Gunthorpe Signed-off-by: Shivank Garg Link: https://patch.msgid.link/20260822-dmaengine-kref-fix-v5-3-d4a4ee47d927@amd.com Signed-off-by: Vinod Koul --- scripts/module.lds.S | 63 ++++++++++++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 63 insertions(+) create mode 100644 scripts/module.lds.S (limited to 'scripts/module.lds.S') diff --git a/scripts/module.lds.S b/scripts/module.lds.S new file mode 100644 index 000000000..d0f200428 --- /dev/null +++ b/scripts/module.lds.S @@ -0,0 +1,63 @@ +/* + * Common module linker script, always used when linking a module. + * Archs are free to supply their own linker scripts. ld will + * combine them automatically. + */ + +#include + +SECTIONS { + /DISCARD/ : { + *(.discard) + *(.discard.*) + *(.export_symbol) + *(.no_trim_symbol) + } + + __ksymtab 0 : ALIGN(8) { *(SORT(___ksymtab+*)) } + __kcrctab 0 : ALIGN(4) { *(SORT(___kcrctab+*)) } + __kflagstab 0 : ALIGN(1) { *(SORT(___kflagstab+*)) } + + .ctors 0 : ALIGN(8) { *(SORT(.ctors.*)) *(.ctors) } + .init_array 0 : ALIGN(8) { *(SORT(.init_array.*)) *(.init_array) } + + .altinstructions 0 : ALIGN(8) { KEEP(*(.altinstructions)) } + __bug_table 0 : ALIGN(8) { KEEP(*(__bug_table)) } + __jump_table 0 : ALIGN(8) { KEEP(*(__jump_table)) } + __ex_table 0 : ALIGN(4) { KEEP(*(__ex_table)) } + + __patchable_function_entries 0 : { *(__patchable_function_entries) } + + .init.klp_funcs 0 : ALIGN(8) { KEEP(*(.init.klp_funcs)) } + .init.klp_objects 0 : ALIGN(8) { KEEP(*(.init.klp_objects)) } + +#ifdef CONFIG_ARCH_USES_CFI_TRAPS + __kcfi_traps 0 : { KEEP(*(.kcfi_traps)) } +#endif + +#ifndef CONFIG_ARCH_WANTS_MODULES_TEXT_SECTIONS + .text 0 : { + *(.text .text.[0-9a-zA-Z_]*) + } +#endif + + .bss 0 : { + *(.bss .bss.[0-9a-zA-Z_]*) + *(.bss..L*) + } + + .data 0 : { + *(.data .data.[0-9a-zA-Z_]*) + *(.data..L*) + } + + .rodata 0 : { + *(.rodata .rodata.[0-9a-zA-Z_]*) + *(.rodata..L*) + } + + MOD_SEPARATE_CODETAG_SECTIONS() +} + +/* bring in arch-specific sections */ +#include -- cgit v1.3.1