Re: [PATCH] pinctrl: devicetree: don't free uninitialized dev_name on error path
From: Linus Walleij
Date: Sat Jul 25 2026 - 05:19:57 EST
On Sun, Jul 19, 2026 at 2:11 PM Karl Mehltretter <kmehltretter@xxxxxxxxx> wrote:
> dt_remember_or_free_map() duplicates dev_name for each map entry. If
> kstrdup_const() fails, dt_free_map() frees dev_name in all num_maps
> entries, including entries that have not been initialized.
>
> Some pinctrl drivers, including pinctrl-imx, allocate the map with
> kmalloc() and leave dev_name for the core to initialize. The untouched
> entries therefore contain uninitialized data which is passed to
> kfree_const().
>
> Reproduced on qemu's mcimx6ul-evk (pinctrl-imx) with failslab injection
> while binding the pinctrl-consuming device, under KASAN:
>
> BUG: KASAN: double-free in dt_free_map+0x34/0xa4
> Free of addr c425a900 by task init/1
> kfree from dt_free_map+0x34/0xa4
> dt_free_map from dt_remember_or_free_map+0x184/0x198
> dt_remember_or_free_map from pinctrl_dt_to_map+0x33c/0x4c8
> pinctrl_dt_to_map from create_pinctrl+0x9c/0x5c0
>
> Initialize all dev_name fields to NULL before duplicating the device
> name, making the full-map cleanup safe after a partial failure.
>
> Fixes: be4c60b563ed ("pinctrl: devicetree: Avoid taking direct reference to device name string")
> Cc: stable@xxxxxxxxxxxxxxx
> Assisted-by: Claude:claude-fable-5
> Signed-off-by: Karl Mehltretter <kmehltretter@xxxxxxxxx>
What a good find, patch applied!
Yours,
Linus Walleij