Re: [PATCH] serial: core: shut down initialized port on removal
From: Greg Kroah-Hartman
Date: Fri Sep 25 2026 - 01:35:48 EST
On Thu, Sep 24, 2026 at 10:22:24PM +0300, Igor Putko wrote:
> When a serial port configured as a console is opened and subsequently
> closed, tty_port_shutdown() skips invoking port->ops->shutdown() because
> port->console is true. As a result, tty_port_initialized() remains true
> and the port's interrupt handler stays registered in the irq subsystem.
>
> If the underlying device is later unbound or removed (e.g. via sysfs
> unbind), serial_core_remove_one_port() unregisters the console, frees
> uport->name with kfree(), and clears state->uart_port without ever
> shutting down the port or freeing its IRQ. Consequently, the irqaction
> remains linked in the genirq descriptor with action->name pointing to
> freed memory.
>
> When another device later requests the same IRQ line, __setup_irq()
> encounters the stale action, detects a flags mismatch, and attempts to
> print old->name in pr_err(), triggering a KASAN use-after-free read:
How can a different device request the same irq line on a real device?
How was this all tested, with "fake" devices?
thanks,
greg k-h