Re: [PATCH v5 04/15] crypto: ti - Fix use-after-free of dev_data on DTHEv2 driver removal
From: T Pratham
Date: Thu Sep 24 2026 - 11:53:51 EST
On 9/23/26 11:21, Herbert Xu wrote:
> On Fri, Sep 18, 2026 at 03:52:34PM +0530, T Pratham wrote:
>> Each *_init_tfm() caches a pointer to the per-instance struct dthe_data
>> in its transform context (ctx->dev_data), but never takes a reference on
>> it. If there are tfms in progress when dthe_remove() is called, the devm
>> allocated dev_data gets freed. Then ctx->dev_data will point to a memory
>> that has been freed.
>>
>> Move dthe_data to req_ctx structs of algorithms, and store the device
>> pointer in tfm_ctx. Add a refcnt to struct dthe_data, which atomically
>> counts the number of requests enqueued in the crypto engine queue which
>> reference the dthe_data object.
>>
>> A waitqueue waits on this atomic counter to get back to zero in
>> dthe_remove() before doing the driver teardown.
>>
>> Fixes: 52f641bc63a46 ("crypto: ti - Add driver for DTHE V2 AES Engine (ECB, CBC)")
>> Signed-off-by: T Pratham <t-pratham@xxxxxx>
>> ---
>> drivers/crypto/ti/dthev2-aes.c | 74 +++++++++++++++++++++----------
>> drivers/crypto/ti/dthev2-common.c | 40 ++++++++++++++---
>> drivers/crypto/ti/dthev2-common.h | 52 ++++++++++++++++++++--
>> 3 files changed, 134 insertions(+), 32 deletions(-)
>
> Please check the Sashiko comments:
>
> https://sashiko.dev/#/patchset/20260918102245.2784000-1-t-pratham%40ti.com
>
> Thanks,
Hi Herbert,
For the patch 06/15's Sashiko review, it suggests to use
crypto_skcipher_set_reqsize_dma() in init. But this being similar to
crypto_skcipher_set_reqsize() which you have said will be deprecated and
set .cra_reqsize directly instead, this shouldn't be used as the correct
fix, right?
As an aside, my LLM suggests me to instead do:
- .cra_reqsize = sizeof(struct dthe_aes_req_ctx),
+ .cra_reqsize = sizeof(struct dthe_aes_req_ctx) + CRYPTO_DMA_PADDING,
Doesn't look to me that it is doing same thing as
crypto_skcipher_set_reqsize_dma(). Your thoughts?
--
Regards
T Pratham <t-pratham@xxxxxx>