[PATCH net 2/2] net: phy: xilinx-gmii2rgmii: Restore PHY driver on remove

From: Vineeth Karumanchi

Date: Thu Oct 01 2026 - 03:48:13 EST


The GMII-to-RGMII converter replaces phydev->drv with a modified copy
of the attached PHY driver. This copied driver is embedded in the
converter's private data and is released when the converter is
removed.

Without a remove callback, phydev->drv continues to point to the freed
copy after the converter is unbound. A subsequent PHY operation can
dereference this stale pointer and result in a use-after-free.

With Generic KASAN enabled, unbinding only the converter while the
external PHY remains active produces the following report (abridged):

BUG: KASAN: slab-use-after-free in phy_check_link_status+0x2d8/0x338
Read of size 8 at addr ffff000006c359b0 by task kworker/2:0/27
Workqueue: events_power_efficient phy_state_machine
Call trace:
phy_check_link_status+0x2d8/0x338
_phy_state_machine+0xdc/0xa4c
phy_state_machine+0x2c/0x70
process_one_work+0x554/0xe44
worker_thread+0x6d0/0x1180
kthread+0x2e8/0x5d4
ret_from_fork+0x10/0x20

Allocated by task 55:
...
devm_kmalloc+0xac/0x2ac
xgmiitorgmii_probe+0xa0/0x37c
mdio_probe+0x68/0xb4
...

Freed by task 642:
...
kfree+0x14c/0x38c
release_nodes+0xb4/0x1e0
devres_release_all+0x140/0x1f4
device_unbind_cleanup+0x20/0x190
device_release_driver_internal+0x344/0x460
device_driver_detach+0x3c/0x54
unbind_store+0xe0/0xf8
...

Store the converter private data in its own MDIO device and add a
remove callback. Restore the attached PHY's original driver while
holding phydev->lock so that the update cannot race with an active PHY
callback.

Also release the device reference acquired by of_phy_find_device().

Fixes: f411a6160bd4 ("net: phy: Add gmiitorgmii converter support")
Signed-off-by: Vineeth Karumanchi <vineeth.karumanchi@xxxxxxx>
---
drivers/net/phy/xilinx_gmii2rgmii.c | 20 ++++++++++++++++++++
1 file changed, 20 insertions(+)

diff --git a/drivers/net/phy/xilinx_gmii2rgmii.c b/drivers/net/phy/xilinx_gmii2rgmii.c
index 61f71e977a57..b9aa5515577b 100644
--- a/drivers/net/phy/xilinx_gmii2rgmii.c
+++ b/drivers/net/phy/xilinx_gmii2rgmii.c
@@ -128,10 +128,29 @@ static int xgmiitorgmii_probe(struct mdio_device *mdiodev)
priv->conv_phy_drv.read_status = xgmiitorgmii_read_status;
priv->conv_phy_drv.set_loopback = xgmiitorgmii_set_loopback;
priv->phy_dev->drv = &priv->conv_phy_drv;
+ mdiodev_set_drvdata(mdiodev, priv);

return 0;
}

+static void xgmiitorgmii_remove(struct mdio_device *mdiodev)
+{
+ struct gmii2rgmii *priv = mdiodev_get_drvdata(mdiodev);
+
+ /*
+ * The attached PHY is a separate, still-bound device whose state
+ * machine keeps running and dispatches ->read_status / ->set_loopback
+ * under phydev->lock. Restore its original driver under that lock so
+ * the swap cannot race an in-flight dispatch; the restored driver is
+ * the PHY's own static phy_driver, not the devres-freed conv_phy_drv.
+ */
+ mutex_lock(&priv->phy_dev->lock);
+ priv->phy_dev->drv = priv->phy_drv;
+ mutex_unlock(&priv->phy_dev->lock);
+
+ put_device(&priv->phy_dev->mdio.dev);
+}
+
static const struct of_device_id xgmiitorgmii_of_match[] = {
{ .compatible = "xlnx,gmii-to-rgmii-1.0" },
{},
@@ -140,6 +159,7 @@ MODULE_DEVICE_TABLE(of, xgmiitorgmii_of_match);

static struct mdio_driver xgmiitorgmii_driver = {
.probe = xgmiitorgmii_probe,
+ .remove = xgmiitorgmii_remove,
.mdiodrv.driver = {
.name = "xgmiitorgmii",
.of_match_table = xgmiitorgmii_of_match,
--
2.43.0