Re: [PATCH] watchdog: pretimeout: Fix UAF in watchdog_unregister_governor()

From: Guenter Roeck

Date: Wed Jul 08 2026 - 10:19:48 EST


On Tue, Jul 07, 2026 at 10:18:03AM +0000, Tzung-Bi Shih wrote:
> When a watchdog governor is unregistered, it updates existing watchdog
> devices that were using this governor by falling back to `default_gov`.
>
> If the governor being unregistered is currently set as `default_gov`,
> the `default_gov` is never cleared. This leads to 2 use-after-free
> issues:
> 1. New watchdog devices registered after this point will inherit the
> dangling `default_gov`.
> 2. Existing watchdog devices using the unregistered governor will have
> their `wdd->gov` reassigned to the dangling `default_gov`.
>
> Fix the UAF by clearing `default_gov` if it matches the governor being
> unregistered.
>
> Fixes: da0d12ff2b82 ("watchdog: pretimeout: add panic pretimeout governor")
> Signed-off-by: Tzung-Bi Shih <tzungbi@xxxxxxxxxx>

Applied.

Thanks,
Guenter

> ---
> drivers/watchdog/watchdog_pretimeout.c | 2 ++
> 1 file changed, 2 insertions(+)
>
> diff --git a/drivers/watchdog/watchdog_pretimeout.c b/drivers/watchdog/watchdog_pretimeout.c
> index 19eb2ed2c7cb..02e09b9e396d 100644
> --- a/drivers/watchdog/watchdog_pretimeout.c
> +++ b/drivers/watchdog/watchdog_pretimeout.c
> @@ -167,6 +167,8 @@ void watchdog_unregister_governor(struct watchdog_governor *gov)
> }
>
> spin_lock_irq(&pretimeout_lock);
> + if (default_gov == gov)
> + default_gov = NULL;
> list_for_each_entry(p, &pretimeout_list, entry)
> if (p->wdd->gov == gov)
> p->wdd->gov = default_gov;