Re: [PATCH V3 06/14] i3c: master: Fix potential UAF in i3c_device_uevent()

From: Mukesh Savaliya

Date: Tue Aug 04 2026 - 14:15:43 EST




On 8/4/2026 7:08 PM, Adrian Hunter wrote:
i3c_device_uevent() dereferences i3cdev->desc without holding the bus
normal-use lock. Since the descriptor pointer can be replaced
concurrently, including when a uevent is generated from sysfs, this can
result in dereferencing a stale descriptor and lead to a use-after-free.

Use i3c_device_get_info() instead, which protects access to the
descriptor with the normal-use lock.

Commit 6cf7b65f7029 ("i3c: Use i3cdev->desc->info instead of calling
i3c_device_get_info() to avoid deadlock") replaced the accessor with a
direct descriptor dereference because i3c_device_get_info() would
recursively acquire bus->lock during device registration.

This change depends on "i3c: master: Fix recursive locking during device
registration", which moves device registration out from under bus->lock
and removes the possibility of that deadlock. Without that change,
restoring the i3c_device_get_info() call would reintroduce the deadlock.

Fixes: 6cf7b65f7029 ("i3c: Use i3cdev->desc->info instead of calling i3c_device_get_info() to avoid deadlock")
Cc: stable@xxxxxxxxxxxxxxx # requires "i3c: master: Fix recursive locking during device registration"
Signed-off-by: Adrian Hunter <adrian.hunter@xxxxxxxxx>
---


Changes in V3:

New patch


drivers/i3c/master.c | 3 +--
1 file changed, 1 insertion(+), 2 deletions(-)

diff --git a/drivers/i3c/master.c b/drivers/i3c/master.c

Acked-by: Mukesh Savaliya <mukesh.savaliya@xxxxxxxxxxxxxxxx>