[PATCH 0/2] ata: pata_parport: fix UAF on protocol module unload

From: Pei Xiao

Date: Wed Sep 02 2026 - 08:07:25 EST


This series fixes use-after-free issues in pata_parport when a protocol
module goes away while pi_adapter devices created by it are still
attached.

Patch 1 pins the protocol module before the device becomes visible.
Previously try_module_get() ran after device_register(), so a forced
module unload in between left pi->proto dangling from the moment the
device appeared on the bus.

Patch 2 makes pata_parport_unregister_driver() tear down all adapters
using the protocol. Without this, the rollback path of a multi-protocol
module init (e.g. kbic registering k951 then k971) left the devices of
the already-registered protocol alive while the module loader freed the
module memory; removing such a dangling device later crashed in
pi_disconnect() dereferencing pi->proto->disconnect.

Pei Xiao (2):
ata: pata_parport: pin the protocol module before device_register()
ata: pata_parport: unregister devices on protocol unregister

drivers/ata/pata_parport/pata_parport.c | 27 +++++++++++++++++++++----
1 file changed, 23 insertions(+), 4 deletions(-)

--
2.25.1