Re: [PATCH 1/8] watchdog: core: Clear wd_data pointer on errors
From: Tzung-Bi Shih
Date: Wed Sep 30 2026 - 07:57:31 EST
On Tue, Sep 29, 2026 at 06:46:28AM -0700, Guenter Roeck wrote:
> In watchdog_cdev_register(), if device registration fails after the core
> watchdog_core_data structure is allocated and assigned to the persistent
> watchdog_device structure, the function frees the data but leaves a
> dangling pointer.
>
> During device registration, watchdog_cdev_register() links the newly
> allocated wd_data to wdd->wd_data. If a subsequent initialization step
> fails, such as the watchdog_kworker validation, dev_set_name(),
> misc_register(), or cdev_device_add(), the function cleans up by freeing
> wd_data via kfree() or put_device(). However, it fails to clear the
> wdd->wd_data pointer before returning. Furthermore, if cdev_device_add()
> fails after misc_register() exposed /dev/watchdog to userspace, a
> concurrent open may hold a reference to wd_data while the caller frees wdd,
> leaving wd_data->wdd dangling.
>
> Fix the problem by clearing wdd->wd_data on all error paths during
> watchdog registration, and clearing wd_data->wdd under wd_data->lock if
> cdev_device_add() fails.
>
> Fixes: b4ffb1909843 ("watchdog: Separate and maintain variables based on variable lifetime")
> Assisted-by: LLM
> Signed-off-by: Guenter Roeck <linux@xxxxxxxxxxxx>
Reviewed-by: Tzung-Bi Shih <tzungbi@xxxxxxxxxx>