Re: [PATCH] mmc: via-sdmmc: Fix use-after-free in via_sd_remove due to race condition
From: Pei Xiao
Date: Tue Aug 04 2026 - 21:13:05 EST
在 2026/8/4 21:43, Ulf Hansson 写道:
> On Tue, Aug 4, 2026 at 3:40 AM Pei Xiao <xiaopei01@xxxxxxxxxx> wrote:
>>
>> In via_init_mmc_host, &sdhost->carddet_work is bound with
>> via_sdc_card_detect, and via_sdc_isr can schedule this work on
>> system_wq when it handles a card insertion/removal interrupt.
>>
>> If we remove the device, via_sd_remove makes cleanup and the memory
>> allocated for sdhost with devm_mmc_alloc_host() is released after the
>> remove callback returns, while the work mentioned above may still be
>> pending or running. The sequence of operations that may lead to a UAF
>> bug is as follows:
>>
>> CPU0 CPU1
>>
>> | via_sdc_isr
>> | schedule_work(&sdhost->carddet_work)
>> via_sd_remove |
>> mmc_remove_host(sdhost->mmc) |
>> free_irq(pcidev->irq, sdhost) |
>> timer_delete_sync(&sdhost->timer) |
>> cancel_work_sync(&sdhost->finish_bh_work) |
>> | via_sdc_card_detect
>> | // use sdhost
>> // devm resources released after |
>> // remove returns, sdhost is freed |
>> | // use sdhost (use-after-free)
>>
>> Fix it by canceling the work after the IRQ handler that can schedule
>> it has been stopped, and before proceeding with the remaining cleanup
>> in via_sd_remove.
>>
>> Fixes: f0bf7f61b840 ("mmc: Add new via-sdmmc host controller driver")
>> Assisted-by: Codex:deepseek-v4-flash
>> Signed-off-by: Pei Xiao <xiaopei01@xxxxxxxxxx>
>
> I already have a patch for this in my tree, so this isn't needed. Thanks anyway!
>
> Future wise, please make sure to base your patches again on my next
> branch in my mmc tree.
Maybe I was using the linux-next branch, and I haven't updated it for a
few days. Thank you for pointing that out.
Thanks!
Pei.
>
> Kind regards
> Uffe
>
>
>
>
>> ---
>> drivers/mmc/host/via-sdmmc.c | 2 ++
>> 1 file changed, 2 insertions(+)
>>
>> diff --git a/drivers/mmc/host/via-sdmmc.c b/drivers/mmc/host/via-sdmmc.c
>> index 8c049f8355cd..be90fc767c74 100644
>> --- a/drivers/mmc/host/via-sdmmc.c
>> +++ b/drivers/mmc/host/via-sdmmc.c
>> @@ -1199,6 +1199,8 @@ static void via_sd_remove(struct pci_dev *pcidev)
>>
>> free_irq(pcidev->irq, sdhost);
>>
>> + cancel_work_sync(&sdhost->carddet_work);
>> +
>> timer_delete_sync(&sdhost->timer);
>>
>> cancel_work_sync(&sdhost->finish_bh_work);
>> --
>> 2.25.1
>>