Re: [PATCH v2] crypto: ccp - Fix use-after-free in backlog cmd advancement

From: Fan Wu

Date: Wed Sep 30 2026 - 03:56:06 EST


On Tue, 29 Sep 2026 17:18:29 +0200, Markus Elfring wrote:
> May lock guards be applied in affected function implementations?
> https://elixir.bootlin.com/linux/v7.3-rc5/source/include/linux/spinlock.h#L642-L645

I considered using lock guards, but kept the manual locking here.

ccp_dequeue_cmd() deliberately has two separate cmd_lock sections, with
the -EINPROGRESS callback between them. The callback must run outside
cmd_lock, so the explicit unlock makes that boundary clear.

This is also a stable fix for code dating back to 2013. Stable branches
such as v6.1 do not have the cleanup/guard helpers, while the manual
form backports unchanged.

I can use a guard for the one-statement ccp_halt_cmds() helper if you
prefer, but would keep the two promotion sections explicit.

Thanks,
Fan Wu