[PATCH v4 0/2] platform/x86: asus-armoury: fix init errors and modernize resource management
From: Marco Scardovi
Date: Tue Jul 07 2026 - 17:38:49 EST
This patch series addresses a Use-After-Free vulnerability and a memory
leak during driver initialization in the asus-armoury driver, and
modernizes its memory management.
Patch 1 fixes the UAF and memory leak by propagating the error code
from init_rog_tunables(), deferring the global pointer updates, and
adding a rollback path.
Patch 2 refactors init_rog_tunables() to use the cleanup infrastructure
via __free(kfree) and no_free_ptr() to automate memory management and
prevent future leaks.
Changes in v4:
- Rebased on top of next-20260707 to resolve conflicts cleanly.
No functional changes applied.
Changes in v3:
- Added a second patch to convert init_rog_tunables() to use the
__free(kfree) and no_free_ptr() cleanup helper macros.
- Added #include <linux/cleanup.h>.
Thread for v3:
https://lore.kernel.org/platform-driver-x86/20260703103212.7406-1-scardracs@xxxxxxxxxxx/
Changes in v2:
- Restructured init_rog_tunables() to use local pointers
(ac_rog_tunables, dc_rog_tunables) and only update the global
static asus_armoury.rog_tunables structure once all allocations
have successfully succeeded. This removes the risk of exposing
freed or partially allocated pointers to the global struct.
- Removed redundant assignments to NULL in the error paths. Since
initialization fails and the driver is not loaded, cleaning the
global static pointers to NULL is not necessary.
- In init_rog_tunables(), replaced 'goto err_nomem' with direct
'return -ENOMEM'. The 'err_nomem' label in the original code
printed a generic OOM error message, which is discouraged in the
kernel as the allocator already issues OOM details. Because that
label did not perform rollback cleanup, a direct return is cleaner
and simpler.
- Replaced inline cleanup in asus_fw_init() with a standard goto
rollback block at the end of the function for cleaner error path
styling.
Thread for v2:
https://lore.kernel.org/platform-driver-x86/20260701164333.5219-1-scardracs@xxxxxxxxxxx/
Marco Scardovi (2):
platform/x86: asus-armoury: fix Use-After-Free and memory leak in
driver init
platform/x86: asus-armoury: use cleanup.h to manage tunables
drivers/platform/x86/asus-armoury.c | 46 ++++++++++++++++++-----------
1 file changed, 28 insertions(+), 18 deletions(-)
--
2.55.0