Re: [PATCH v2] power: supply: bq24257: fix use-after-free on remove

From: Sebastian Reichel

Date: Sat Aug 01 2026 - 12:27:25 EST



On Sat, 01 Aug 2026 05:19:58 +0000, Fan Wu wrote:
> The STAT-pin interrupt is devm-managed, so it stays armed until the devm
> cleanup that runs after remove() returns. remove() cancels
> bq->iilimit_setup_work while the threaded handler can still fire; that
> handler reschedules the work and dereferences bq, so the work runs
> against freed memory once devm frees bq.
>
> Make the delayed work device-managed with devm_delayed_work_autocancel(),
> registered before the interrupt request. The devm cleanup then releases
> the interrupt first, so the handler can no longer reschedule the work,
> and cancels the work before bq is freed. The explicit
> cancel_delayed_work_sync() in remove() is no longer needed and is dropped.
>
> [...]

Applied, thanks!

[1/1] power: supply: bq24257: fix use-after-free on remove
commit: 9d34c9d660c3d0931d2cc749c46c47cf31f96e48

Best regards,
--
Sebastian Reichel <sebastian.reichel@xxxxxxxxxxxxx>