Re: [PATCH] crypto: caam/jr: fix use-after-free in interrupt handler teardown

From: Rosen Penev

Date: Wed Aug 12 2026 - 14:58:40 EST


On Mon, Aug 10, 2026 at 1:10 AM Herbert Xu <herbert@xxxxxxxxxxxxxxxxxxx> wrote:
>
> On Thu, Jul 30, 2026 at 04:16:03PM -0700, Rosen Penev wrote:
> > caam_jr_shutdown() currently calls tasklet_kill() without freeing the
> > IRQ first, creating a window where the interrupt handler can fire and
> > schedule the tasklet after it has been killed. Move from
> > devm_request_irq() to request_irq()/free_irq() so that the IRQ is
> > explicitly freed in caam_jr_shutdown() before the tasklet is killed.
> >
> > As part of this change, pass jrp directly as the dev_id cookie to
> > request_irq() instead of the device pointer. This lets the interrupt
> > handler obtain jrp directly from the cookie, eliminating the
> > dev_get_drvdata() call in the hot path.
> >
> > Two related fixes:
> > - Use jrp->dev instead of the now-undefined dev local in the handler's
> > error path.
> > - Set jrpriv->dev before calling caam_jr_init() so that jrp->dev is
> > valid before the IRQ is registered and the handler can run.
> >
> > Assisted-by: opencode:big-pickle
> > Signed-off-by: Rosen Penev <rosenp@xxxxxxxxx>
> > ---
> > drivers/crypto/caam/jr.c | 14 +++++++-------
> > 1 file changed, 7 insertions(+), 7 deletions(-)
>
> I think we should fix the general problem of hardware removal
> in the middle of a crypto operation first before attempting these
> fixes.
>
> The driver needs to be modified so that it can fail gracefully
> if the hardware is forcefully unbound while a crypto op is ongoing.
That's a much bigger change than this one, which I cannot test.
>
> Thanks,
> --
> Email: Herbert Xu <herbert@xxxxxxxxxxxxxxxxxxx>
> Home Page: http://gondor.apana.org.au/~herbert/
> PGP Key: http://gondor.apana.org.au/~herbert/pubkey.txt