Re: [PATCH v4 1/4] dmaengine: Fix possible use after free

From: Frank Li

Date: Thu May 07 2026 - 14:33:47 EST


On Fri, Apr 24, 2026 at 06:40:14PM +0100, Nuno Sá wrote:
> In dma_release_channel(), check chan->device->privatecnt after call
> dma_chan_put(). However, dma_chan_put() call dma_device_put() which could
> release the last reference of the device if the DMA provider is already
> gone and hence free it.
>
> Fixes it by moving dma_chan_put() after the check.
>
> Fixes: 0f571515c332 ("dmaengine: Add privatecnt to revert DMA_PRIVATE property")
> Signed-off-by: Nuno Sá <nuno.sa@xxxxxxxxxx>

Reviewed-by: Frank Li <Frank.Li@xxxxxxx>
> ---
> drivers/dma/dmaengine.c | 3 ++-
> 1 file changed, 2 insertions(+), 1 deletion(-)
>
> diff --git a/drivers/dma/dmaengine.c b/drivers/dma/dmaengine.c
> index 405bd2fbb4a3..9049171df857 100644
> --- a/drivers/dma/dmaengine.c
> +++ b/drivers/dma/dmaengine.c
> @@ -905,11 +905,12 @@ void dma_release_channel(struct dma_chan *chan)
> mutex_lock(&dma_list_mutex);
> WARN_ONCE(chan->client_count != 1,
> "chan reference count %d != 1\n", chan->client_count);
> - dma_chan_put(chan);
> /* drop PRIVATE cap enabled by __dma_request_channel() */
> if (--chan->device->privatecnt == 0)
> dma_cap_clear(DMA_PRIVATE, chan->device->cap_mask);
>
> + dma_chan_put(chan);
> +
> if (chan->slave) {
> sysfs_remove_link(&chan->dev->device.kobj, DMA_SLAVE_NAME);
> sysfs_remove_link(&chan->slave->kobj, chan->name);
>
> --
> 2.54.0
>