[PATCH v2 2/2] tty: vcc: hold port lock when clearing tty pointer in vcc_cleanup
From: Greg Kroah-Hartman
Date: Mon Aug 03 2026 - 10:58:47 EST
From: Joshua Rogers <linux@xxxxxxxxx>
vcc_cleanup() sets port->tty to NULL without holding port->lock, racing
with vcc_event() LDC callbacks that read port->tty under port->lock and
then use tty->port. This can cause a use-after-free when the callback
dereferences tty->port after cleanup has already destroyed and freed it.
Assisted-by: AISLE:Snapshot
Cc: stable <stable@xxxxxxxxxx>
Signed-off-by: Joshua Rogers <linux@xxxxxxxxx>
Signed-off-by: Greg Kroah-Hartman <gregkh@xxxxxxxxxxxxxxxxxxx>
---
drivers/tty/vcc.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/drivers/tty/vcc.c b/drivers/tty/vcc.c
index 3947bd2b75ac..9adb533f7034 100644
--- a/drivers/tty/vcc.c
+++ b/drivers/tty/vcc.c
@@ -986,7 +986,8 @@ static void vcc_cleanup(struct tty_struct *tty)
port = vcc_get(tty->index, true);
if (port) {
- port->tty = NULL;
+ scoped_guard(spinlock_irqsave, &port->lock)
+ port->tty = NULL;
if (port->removed) {
vcc_table_remove(tty->index);
--
2.55.0