Re: [PATCH 2/2] serial: tegra: fix TX DMA descriptor use-after-free
From: Austin Schlegel
Date: Fri Oct 02 2026 - 00:07:58 EST
> Found by code inspection while fixing the analogous RX bug; not
> reproduced on hardware, since triggering it requires stopping an
> in-flight TX DMA transfer (e.g. via a modem control line or flush)
> at the right moment...
tegra_uart_stop_tx() is reached when TX is stopped by flow control
(e.g. CTS deasserting), not by a flush - flush_buffer() does not go
through this path. I'll remove that example in v2.
This e-mail and any files transmitted with it are the property of Arthrex, Inc. and/or its affiliates, are confidential, and are intended solely for the use of the individual or entity to whom this e-mail is addressed. If you are not one of the named recipient(s) or otherwise have reason to believe that you have received this message in error, please notify the sender at 239-598-4302 and delete this message immediately from your computer. Any other use, retention, dissemination forwarding, printing or copying of this e-mail is strictly prohibited. Please note that any views or opinions presented in this email are solely those of the author and do not necessarily represent those of the company. Finally, while Arthrex uses virus protection, the recipient should check this email and any attachments for the presence of viruses. The company accepts no liability for any damage caused by any virus transmitted by this email.