[PATCH v2 0/2] gpio: sloppy-logic-analyzer: fix debugfs UAF on unbind
From: Cengiz Can
Date: Thu Jul 30 2026 - 18:08:33 EST
Patch 1 fixes a use-after-free. The "trigger" debugfs file uses
debugfs_create_file_unsafe() with a hand-rolled ->write that dereferences
the devres-freed gpio_la_poll_priv without holding a debugfs reference, so
an unbind racing a write frees the object under the handler. Switching to
debugfs_create_file() makes debugfs_remove_recursive() drain the handler
first.
Patch 2 converts the sibling "buf_size" and "capture" files to
debugfs_create_file() as well, for consistency. They were already safe via
DEFINE_DEBUGFS_ATTRIBUTE(); this is the cleanup requested on v1.
v1 was a single patch that fixed only "trigger". v2 splits it so the fix
carries the stable tag on its own, and adds the consistency conversion as a
separate cleanup.
Note: while testing this I found a pre-existing deadlock in the driver
(gpio_la_poll_remove() holds blob_lock across debugfs_remove_recursive(),
which drains the buf_size/capture handlers that also take blob_lock). It is
unrelated to this series; I will send it separately.
Cengiz Can (2):
gpio: sloppy-logic-analyzer: fix use-after-free via debugfs trigger on
unbind
gpio: sloppy-logic-analyzer: use debugfs_create_file() for buf_size
and capture
drivers/gpio/gpio-sloppy-logic-analyzer.c | 6 +++---
1 file changed, 3 insertions(+), 3 deletions(-)
--
2.43.0