Re: [PATCH v2 3/3] soundwire: intel_auxdevice: Don't disable IRQs before removing children
From: Charles Keepax
Date: Thu Oct 08 2026 - 08:43:42 EST
On Mon, Oct 05, 2026 at 02:11:47PM +0100, Charles Keepax wrote:
> On Mon, Oct 05, 2026 at 11:32:05AM +0100, Charles Keepax wrote:
> > On Sun, Oct 04, 2026 at 12:29:58PM +0000, Richard Patel wrote:
> > > On Fri, Sep 25, 2026 at 04:42:16PM +0100, Charles Keepax wrote:
> > > I don't understand the code very well, but isn't there a second UAF
> > > with the ctx object getting freed? kfree(ctx) in sdw_intel_exit()
> > > runs well before the IRQ is unregistered.
> >
> > This situation is unfortunately fairly complex, the IRQ is shared
> > between many different functions and only the SoundWire function
> > relies on ctx. I will do some more poking, but I believe the
> > free order is such that the soundwire stuff is shutdown before
> > ctx is freed. I am not 100% certain if that will prevent the
> > SoundWire IRQ path from getting called, although I would like
> > to believe it does :-)
>
> Hmm... ok so poking this a little more looks like I do see just
> see these freed in hard the wrong order so we should probably
> fix that up too. Thanks for spotting that I will have a bit of
> a think.
Ok found some time to look at this properly I think this is all
fine. sdw_intel_exit() first calls sdw_intel_cleanup() which will
eventually call sdw_cdns_enable_interrupt(..., false), which
should disable the SoundWire IRQs. Then sdw_intel_exit() frees
the ctx, whilst at that point whilst the IRQ is still registered
one should no longer be able to see soundwire IRQs, so you shouldn't
get a dereferencing of ctx.
Thanks,
Charles