[PATCH 0/2] fastrpc: fix probe-time races between rpmsg and userspace

From: Vinayak Katoch

Date: Thu Oct 01 2026 - 07:02:25 EST


This series fixes two races in fastrpc_rpmsg_probe() that can be
triggered when userspace opens a fastrpc device node concurrently with
the rpmsg probe sequence.

fastrpc_device_register() calls misc_register() before the channel
context is fully initialised. A concurrent open() in that window hits
kref_get() on a zero refcount, and because fastrpc_cb_devices_create()
has not yet run sesscount is 0, the error path calls kref_put() on the
saturated refcount, triggering kfree() of the channel context. A
subsequent IRQ-path fastrpc_rpmsg_callback() then dereferences the
freed spinlock, causing a kernel panic. A NULL dereference in the
fastrpc_device_open() error path when cctx->rpdev is concurrently
cleared by fastrpc_rpmsg_remove() is also addressed.

Signed-off-by: Vinayak Katoch <vinayak.katoch@xxxxxxxxxxxxxxxx>
---
Vinayak Katoch (2):
misc: fastrpc: fix NULL rpdev dereference when session alloc fails
misc: fastrpc: fix init ordering race in rpmsg probe

drivers/misc/fastrpc.c | 55 ++++++++++++++++++++++++++------------------------
1 file changed, 29 insertions(+), 26 deletions(-)
---
base-commit: 5c4d4169604b335c38bbc79bc1fc03042981fc6f
change-id: 20260923-fastrpc-probe-fixes-30c1980b50e6
prerequisite-change-id: 20260609-dup-sessions-ea2acaac1994:v5
prerequisite-patch-id: 425dc9414848bbc3f2a053d067195d849898e2ae
prerequisite-patch-id: 4fea14b47d11a5a3e18065d8cf3a461841ee2b86
prerequisite-patch-id: da0a3d55397a522ea4b77769e387df9faea8e024

Best regards,
--
Vinayak Katoch <vinayak.katoch@xxxxxxxxxxxxxxxx>