[PATCH net v3 1/7] net: macb: manage the netdev lifetime with devres

From: Jiale Yao

Date: Sat Oct 03 2026 - 05:03:24 EST


macb_remove() frees the netdev while its managed IRQs are only
released after the remove callback returns. An interrupt in that window
can dereference the freed netdev or queue data.

Allocate the netdev with devres as well. Since the IRQs are registered
later, devres releases them before freeing the netdev and closes the
lifetime gap.

This issue was found by a static analysis method used in our research.

Fixes: 0a4acf08ea62 ("net: macb: Use devm_request_irq()")
Cc: stable@xxxxxxxxxxxxxxx
Signed-off-by: Jiale Yao <yaojiale02@xxxxxxx>
---
drivers/net/ethernet/cadence/macb_main.c | 17 +++++++----------
1 file changed, 7 insertions(+), 10 deletions(-)

diff --git a/drivers/net/ethernet/cadence/macb_main.c b/drivers/net/ethernet/cadence/macb_main.c
index b8234ac4b602..ebf6ffb1cc4f 100644
--- a/drivers/net/ethernet/cadence/macb_main.c
+++ b/drivers/net/ethernet/cadence/macb_main.c
@@ -5812,7 +5812,8 @@ static int macb_probe(struct platform_device *pdev)
goto err_disable_clocks;
}

- netdev = alloc_etherdev_mq(sizeof(*bp), num_queues);
+ netdev = devm_alloc_etherdev_mqs(&pdev->dev, sizeof(*bp),
+ num_queues, num_queues);
if (!netdev) {
err = -ENOMEM;
goto err_disable_clocks;
@@ -5859,7 +5860,7 @@ static int macb_probe(struct platform_device *pdev)
IS_ENABLED(CONFIG_MACB_USE_HWSTAMP)) {
dev_err(&pdev->dev, "Timer adjust mode is not supported\n");
err = -EINVAL;
- goto err_out_free_netdev;
+ goto err_disable_clocks;
}

/* By default we set to partial store and forward mode for zynqmp.
@@ -5893,7 +5894,7 @@ static int macb_probe(struct platform_device *pdev)
err = dma_set_mask_and_coherent(&pdev->dev, DMA_BIT_MASK(44));
if (err) {
dev_err(&pdev->dev, "failed to set DMA mask\n");
- goto err_out_free_netdev;
+ goto err_disable_clocks;
}
bp->caps |= MACB_CAPS_DMA_64B;
}
@@ -5903,7 +5904,7 @@ static int macb_probe(struct platform_device *pdev)
netdev->irq = platform_get_irq(pdev, 0);
if (netdev->irq < 0) {
err = netdev->irq;
- goto err_out_free_netdev;
+ goto err_disable_clocks;
}

/* MTU range: 68 - 1518 or 10240 */
@@ -5932,7 +5933,7 @@ static int macb_probe(struct platform_device *pdev)

err = of_get_ethdev_address(np, bp->netdev);
if (err == -EPROBE_DEFER)
- goto err_out_free_netdev;
+ goto err_disable_clocks;
else if (err)
macb_get_hwaddr(bp);

@@ -5946,7 +5947,7 @@ static int macb_probe(struct platform_device *pdev)
/* IP specific init */
err = macb_init(pdev, macb_config);
if (err)
- goto err_out_free_netdev;
+ goto err_disable_clocks;

err = macb_mii_init(bp);
if (err)
@@ -5988,9 +5989,6 @@ static int macb_probe(struct platform_device *pdev)
err_out_phy_exit:
phy_exit(bp->phy);

-err_out_free_netdev:
- free_netdev(netdev);
-
err_disable_clocks:
macb_clks_disable(pclk, hclk, tx_clk, rx_clk, tsu_clk);
pm_runtime_disable(&pdev->dev);
@@ -6024,7 +6022,6 @@ static void macb_remove(struct platform_device *pdev)
pm_runtime_dont_use_autosuspend(&pdev->dev);
pm_runtime_set_suspended(&pdev->dev);
phylink_destroy(bp->phylink);
- free_netdev(netdev);
}
}

--
2.34.1