[PATCH v2] Input: byd - synchronize timer deletion before freeing private data

From: Linmao Li

Date: Mon Jul 20 2026 - 02:21:32 EST


byd_disconnect() uses timer_delete() before freeing the driver's private
data. This does not wait for a running byd_clear_touch() callback, which
dereferences the private data and its psmouse pointer. A callback racing
with disconnect can therefore access the private data after it has been
freed. The timer can also still be re-armed by byd_process_byte() while
the disconnect is in progress.

Use timer_shutdown_sync() before freeing the private data: it waits for
a running callback and turns any later re-arm attempt into a no-op.

Fixes: 2d5f5611dd0d ("Input: byd - enable absolute mode")
Cc: stable@xxxxxxxxxxxxxxx
Signed-off-by: Linmao Li <lilinmao@xxxxxxxxxx>
---
v2:
- use timer_shutdown_sync() instead of timer_delete_sync() so the
timer cannot be re-armed by byd_process_byte() while disconnect is
in progress (Sashiko review, Dmitry)

drivers/input/mouse/byd.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/drivers/input/mouse/byd.c b/drivers/input/mouse/byd.c
index f5770a3af2f1..5fc3c629590a 100644
--- a/drivers/input/mouse/byd.c
+++ b/drivers/input/mouse/byd.c
@@ -423,7 +423,7 @@ static void byd_disconnect(struct psmouse *psmouse)
struct byd_data *priv = psmouse->private;

if (priv) {
- timer_delete(&priv->timer);
+ timer_shutdown_sync(&priv->timer);
kfree(psmouse->private);
psmouse->private = NULL;
}
--
2.25.1