Re: [PATCH] crypto: caam/jr: fix use-after-free in interrupt handler teardown
From: Herbert Xu
Date: Mon Aug 10 2026 - 04:13:27 EST
On Thu, Jul 30, 2026 at 04:16:03PM -0700, Rosen Penev wrote:
> caam_jr_shutdown() currently calls tasklet_kill() without freeing the
> IRQ first, creating a window where the interrupt handler can fire and
> schedule the tasklet after it has been killed. Move from
> devm_request_irq() to request_irq()/free_irq() so that the IRQ is
> explicitly freed in caam_jr_shutdown() before the tasklet is killed.
>
> As part of this change, pass jrp directly as the dev_id cookie to
> request_irq() instead of the device pointer. This lets the interrupt
> handler obtain jrp directly from the cookie, eliminating the
> dev_get_drvdata() call in the hot path.
>
> Two related fixes:
> - Use jrp->dev instead of the now-undefined dev local in the handler's
> error path.
> - Set jrpriv->dev before calling caam_jr_init() so that jrp->dev is
> valid before the IRQ is registered and the handler can run.
>
> Assisted-by: opencode:big-pickle
> Signed-off-by: Rosen Penev <rosenp@xxxxxxxxx>
> ---
> drivers/crypto/caam/jr.c | 14 +++++++-------
> 1 file changed, 7 insertions(+), 7 deletions(-)
I think we should fix the general problem of hardware removal
in the middle of a crypto operation first before attempting these
fixes.
The driver needs to be modified so that it can fail gracefully
if the hardware is forcefully unbound while a crypto op is ongoing.
Thanks,
--
Email: Herbert Xu <herbert@xxxxxxxxxxxxxxxxxxx>
Home Page: http://gondor.apana.org.au/~herbert/
PGP Key: http://gondor.apana.org.au/~herbert/pubkey.txt