[PATCH v2 0/3] iio: hid-sensors: fix shared callbacks in temperature and humidity

From: Christopher Hoover

Date: Wed Oct 07 2026 - 14:56:25 EST


hid-sensor-temperature and hid-sensor-humidity share one static
struct hid_sensor_hub_callbacks across instances and overwrite its pdev
on every probe. With two temperature sensors, reports for one go to
the other's pdev; once that device is removed,
temperature_capture_sample() dereferences NULL. I hit this on 7.0
with two uhid-created sensors.

Patches 2-3 make the callbacks per instance, as the other HID sensor
drivers do. Patch 1 makes sensor_hub_remove_callback() take
pdata->lock, as sensor_hub_raw_event() does, so a report racing an
unbind cannot call through the freed callbacks.

Changes in v2:
- New patch 1, for the use-after-free on unbind found by the Sashiko
review of v1.

Christopher Hoover (3):
HID: hid-sensor-hub: Synchronize callback removal with raw events
iio: temperature: hid-sensor-temperature: Use per-instance callbacks
iio: humidity: hid-sensor-humidity: Use per-instance callbacks

drivers/hid/hid-sensor-hub.c | 12 ++++++++++--
drivers/iio/humidity/hid-sensor-humidity.c | 12 +++++-------
drivers/iio/temperature/hid-sensor-temperature.c | 12 +++++-------
3 files changed, 20 insertions(+), 16 deletions(-)


base-commit: 9ee8306121495d2a25aa5d1bfd519f2748786b83
--
2.43.0