[PATCH] PCI/P2PDMA: Fix use-after-free in pci_p2pdma_add_resource() error path

From: leixiang

Date: Fri Jul 17 2026 - 05:53:27 EST


In pci_p2pdma_add_resource(), a devm action is registered to call
pci_p2pdma_unmap_mappings() with the 'p2p_pgmap' context. If the subsequent
call to gen_pool_add_owner() fails, the code jumps to the 'pages_free'
error path.

In this error path, 'p2p_pgmap' is explicitly freed via devm_kfree().
However, the previously registered devm action is never removed. This
leaves a dangling pointer in the device's devres list. When the device
is unbound and devres is cleaning up resources, the unmap action will be
called with the already-freed 'p2p_pgmap', resulting in a use-after-free
bug.

Fix this by properly calling devm_remove_action() in the error path before
freeing 'p2p_pgmap'.

Fixes: 7e9c7ef83d78 ("PCI/P2PDMA: Allow userspace VMA allocations through sysfs")
Assisted-by: Antigravity:Gemini [tools]
Signed-off-by: leixiang <leixiang@xxxxxxxxxx>
---
drivers/pci/p2pdma.c | 4 +++-
1 file changed, 3 insertions(+), 1 deletion(-)

diff --git a/drivers/pci/p2pdma.c b/drivers/pci/p2pdma.c
index b2d5266f8653..7f54532932ab 100644
--- a/drivers/pci/p2pdma.c
+++ b/drivers/pci/p2pdma.c
@@ -451,13 +451,15 @@ int pci_p2pdma_add_resource(struct pci_dev *pdev, int bar, size_t size,
range_len(&pgmap->range), dev_to_node(&pdev->dev),
&pgmap->ref);
if (error)
- goto pages_free;
+ goto unmap_mappings;

pci_info(pdev, "added peer-to-peer DMA memory %#llx-%#llx\n",
pgmap->range.start, pgmap->range.end);

return 0;

+unmap_mappings:
+ devm_remove_action(&pdev->dev, pci_p2pdma_unmap_mappings, p2p_pgmap);
pages_free:
devm_memunmap_pages(&pdev->dev, pgmap);
pgmap_free:
--
2.43.0