Re: [PATCH v5 0/4] dmaengine: fix kref underflow and UAF in dma_chan_put()

From: Garg, Shivank

Date: Mon Aug 31 2026 - 04:44:34 EST


On Sat, 2026-08-22 at 19:22 +0000, Shivank Garg wrote:
> Fix bugs related to dma_chan_put(), found while testing with SDXI[1].
>
> [1]: https://lore.kernel.org/dmaengine/20260605-sdxi-base-v3-0-4d38ca2bdffe@xxxxxxx
>
> Signed-off-by: Shivank Garg <shivankg@xxxxxxx>
> ---
> Changes in v5:
> - Use int return type and add __must_check for dma_device_get() (Frank)
> - Drop the comment above synchronize_rcu() and note in the commit message
> that this will delay for grace period dma_list_mutex held (Logan)
> - Link to v4: https://lore.kernel.org/r/20260818-dmaengine-kref-fix-v4-0-c6ef991462a0@xxxxxxx
>
> Changes in v4:
> - Add dma_device_get() helper (Frank)
> - Drop dma_chan_put() move change (Frank)
> - Link to v3: https://lore.kernel.org/r/20260816-dmaengine-kref-fix-v3-0-7e76187145df@xxxxxxx
>
> Changes in v3:
> - Add patch 3: add synchronize_rcu() to wait for RCU readers to prevent
> use-after-free. (Sashiko)
> - Link to v2: https://lore.kernel.org/r/20260526-dmaengine-kref-fix-v2-0-3df60afac01d@xxxxxxx
>
> Changes in v2:
> - Add patch 2 fixing the dma_chan_put()/dma_release_channel() use-after-free (sashiko)
> - Link to v1: https://lore.kernel.org/r/20260518-dmaengine-kref-fix-v1-1-4d6125048fb7@xxxxxxx
>
> ---
> Shivank Garg (4):
> dmaengine: add dma_device_get() helper
> dmaengine: Fix device kref underflow in dma_chan_put()
> dmaengine: fix use-after-free in dma_chan_put() and dma_release_channel()
> dmaengine: wait for RCU readers before releasing dma_device
>
> drivers/dma/dmaengine.c | 19 +++++++++++++++----
> 1 file changed, 15 insertions(+), 4 deletions(-)
> ---
> base-commit: a4ff2be345d0abc943da8dd8da98151843b750dc
> change-id: 20260518-dmaengine-kref-fix-7b21acb09455
>
> Best regards,


Hi Vinod,

Would you consider this series for next?
It applies cleanly on v7.3-rc1.

Thanks,
Shivank