Re: [PATCH v2 1/4] pps: generators: fix use-after-free when closing a removed device
From: Rodolfo Giometti
Date: Wed Sep 30 2026 - 08:32:12 EST
On Tue, 29 Sep 2026 07:49:34 -0500, Danish Khateeb wrote:
The cdev of a PPS generator is embedded in struct pps_gen_device, but
nothing ties the lifetime of that structure to the cdev: pps_gen is
freed by the release function of its device, and an open file holds a
device reference only until pps_gen_cdev_release() drops it.
When the generator is unregistered while /dev/pps-genN is open, that
put_device() drops the last reference and frees pps_gen, and __fput()
then calls cdev_put() on the freed cdev:
BUG: KASAN: slab-use-after-free in cdev_put+0x53/0x60
Read of size 8 at addr ffff88801383e138 by task ppsgen64/149
Call Trace:
cdev_put+0x53/0x60
__fput+0x745/0xad0
fput_close_sync+0xd9/0x1b0
__x64_sys_close+0x86/0xf0
...
Freed by task 149:
kfree+0x25a/0x6d0
device_release+0xca/0x3c0
kobject_put+0x169/0x320
pps_gen_cdev_release+0x51/0x80
__fput+0x36a/0xad0
pps.c had the same bug, fixed in commit c79a39dc8d06 ("pps: Fix a
use-after-free").
Fix it the usual way: embed the struct device in pps_gen_device and
register both with cdev_device_add(). This makes the device the parent
of the cdev, so the cdev holds a device reference until the last file
is closed.
Fixes: 86b525bed275 ("drivers pps: add PPS generators support")
Cc: stable@xxxxxxxxxxxxxxx
Assisted-by: LLM
Signed-off-by: Danish Khateeb <danishkhateeb03@xxxxxxxxx>
Acked-by: Rodolfo Giometti <giometti@xxxxxxxxxxxx>