[PATCH] memstick: core: don't clear dev->driver in memstick_device_remove()
From: Joshua Mulloy
Date: Sun Oct 04 2026 - 06:29:56 EST
memstick_device_remove() sets card->dev.driver to NULL after calling the
driver's remove() callback. Since commit a995fe1a3aa7 ("rust: driver:
drop device private data post unbind"), device_unbind_cleanup()
dereferences dev->driver after the bus remove() callback has returned,
so this should result in a NULL pointer dereference whenever a
MemoryStick card is removed or its driver is unbound.
The driver core clears dev->driver itself in device_unbind_cleanup(), so
there is no need for the bus code to do it. Remove the assignment.
This was found by code inspection, with the help of an AI coding
assistant, after hitting the same bug in the TI FlashMedia bus code
(drivers/misc/tifm_core.c), which oopsed on SD card removal. It has
only been compile-tested: no MemoryStick hardware was available.
Fixes: a995fe1a3aa7 ("rust: driver: drop device private data post unbind")
Cc: stable@xxxxxxxxxxxxxxx
Assisted-by: LLM
Signed-off-by: Joshua Mulloy <joshuamulloy@xxxxxxxxx>
---
Compile-tested only (W=1, no warnings, current mainline); not runtime-
tested. The same fix for drivers/misc/tifm_core.c, which was tested on
hardware, has been sent separately.
drivers/memstick/core/memstick.c | 1 -
1 file changed, 1 deletion(-)
diff --git a/drivers/memstick/core/memstick.c b/drivers/memstick/core/memstick.c
index e03989c4e..06ee6faed 100644
--- a/drivers/memstick/core/memstick.c
+++ b/drivers/memstick/core/memstick.c
@@ -100,7 +100,6 @@ static void memstick_device_remove(struct device *dev)
if (dev->driver && drv->remove) {
drv->remove(card);
- card->dev.driver = NULL;
}
put_device(dev);
base-commit: 6addb4f385570ebc11c4eb499a4f1c149f313e84
prerequisite-patch-id: d9a5a385ce2ccea3eec18ee2168d603e951c6374
--
2.53.0