Re: [PATCH v4 3/4] dmaengine: fix use-after-free in dma_chan_put() and dma_release_channel()
From: Logan Gunthorpe
Date: Tue Aug 18 2026 - 11:56:34 EST
On 2026-08-17 21:43, Shivank Garg wrote:
> When dma_device_put() drops the last reference on chan->device->ref,
> dma_device_release() runs and may free the dma_device along with its
> channels.
>
> dma_chan_put() then still reads chan->device->owner via
> dma_chan_to_owner() for the trailing module_put(). KASAN catches it:
>
> slab-use-after-free in dma_chan_put+0x3e6/0x4c0
> Read of size 8 by task insmod/6319
> Freed by task 6319:
> kfree+0x225/0x470
> dma_chan_put+0x395/0x4c0
> dmaengine_put+0xf8/0x160
>
> Cache the module owner in dma_chan_put() before the put so the trailing
> module_put() does not need chan->device.
>
> Fixes: 8ad342a86359 ("dmaengine: Add reference counting to dma_device struct")
> Suggested-by: Sashiko <sashiko-bot@xxxxxxxxxx>
> Link: https://sashiko.dev/#/patchset/20260518-dmaengine-kref-fix-v1-1-4d6125048fb7@xxxxxxx
> Reviewed-by: Frank Li <Frank.Li@xxxxxxx>
> Signed-off-by: Shivank Garg <shivankg@xxxxxxx>
Nice catch, looks right to me and the patch is really easy to
understand. Thanks!
Reviewed-by: Logan Gunthorpe <logang@xxxxxxxxxxxx>