[PATCH 0/2] pps: generators: fix use-after-free on unregister with the file open

From: Danish Khateeb

Date: Mon Sep 28 2026 - 22:26:43 EST


Unregistering a PPS generator while /dev/pps-genN is open leads to two
use-after-frees, one per patch:

1/2: closing the file frees pps_gen in ->release(), and __fput() then
calls cdev_put() on the cdev embedded in it. pps.c had the same bug
before commit c79a39dc8d06 ("pps: Fix a use-after-free"). Fixed with
cdev_device_add().

2/2: the ioctls keep using the driver's pps_gen_source_info: TIO's devm
memory after an unbind, and pps_gen-dummy's module data and code after
an rmmod. They now return -ENODEV, as PPS_KC_BIND does for a removed
PPS device since commit 3649f9a6b897.

Yibo Tan's "pps: generators: Pin dummy provider while a file is open"
[1] keeps the dummy module loaded while its file is open. That covers
only the dummy rmmod case; a device such as TIO can still be unbound,
so 2/2 is needed either way.

[1] https://lore.kernel.org/all/20260911134952.648064-1-lhfff@xxxxxxxxxx/

Danish Khateeb (2):
pps: generators: fix use-after-free when closing a removed device
pps: generators: don't use the driver's info after unregister

drivers/pps/generators/pps_gen.c | 94 +++++++++++++++++++-------------
include/linux/pps_gen_kernel.h | 4 +-
2 files changed, 60 insertions(+), 38 deletions(-)


base-commit: 72d3fcf802c45d00b300f25b848a93c3a2bd7c7e
--
2.55.0