* [PATCH 1/2] mtd: virt-concat: unlink concat node before freeing it
@ 2026-09-25 12:55 Harshit Mogalapalli
2026-09-25 12:55 ` [PATCH 2/2] mtd: virt-concat: unlink discarded items before freeing Harshit Mogalapalli
2026-09-25 14:29 ` [PATCH 1/2] mtd: virt-concat: unlink concat node before freeing it Miquel Raynal
0 siblings, 2 replies; 3+ messages in thread
From: Harshit Mogalapalli @ 2026-09-25 12:55 UTC (permalink / raw)
To: Miquel Raynal, Richard Weinberger, Vignesh Raghavendra,
Luca Ceresoli, Amit Kumar Mahapatra, linux-mtd, linux-kernel
Cc: kernel-janitors, error27, harshit.m.mogalapalli, stable
mtd_virt_concat_create_item() links each new mtd_virt_concat_node to
concat_node_list. mtd_virt_concat_destroy() later frees the node after
destroying its concatenated MTD device, but fails to unlink it. A later
list traversal dereferences the freed node, causing a use-after-free.
Remove the node from concat_node_list before freeing it.
Fixes: 43db6366fc2d ("mtd: Add driver for concatenating devices")
Cc: stable@vger.kernel.org
Assisted-by: Codex:gpt-5.6, smatch
Signed-off-by: Harshit Mogalapalli <harshit.m.mogalapalli@oracle.com>
---
Was performing static analysis with smatch and found this.
---
drivers/mtd/mtd_virt_concat.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/drivers/mtd/mtd_virt_concat.c b/drivers/mtd/mtd_virt_concat.c
index 25cf33fe1ec1..1443f0e4c7cb 100644
--- a/drivers/mtd/mtd_virt_concat.c
+++ b/drivers/mtd/mtd_virt_concat.c
@@ -130,6 +130,7 @@ int mtd_virt_concat_destroy(struct mtd_info *mtd)
mtd_concat_destroy(&concat->mtd);
}
+ list_del(&item->head);
for (idx = 0; idx < item->count; idx++)
of_node_put(item->nodes[idx]);
--
2.52.0
^ permalink raw reply [flat|nested] 3+ messages in thread
* [PATCH 2/2] mtd: virt-concat: unlink discarded items before freeing
2026-09-25 12:55 [PATCH 1/2] mtd: virt-concat: unlink concat node before freeing it Harshit Mogalapalli
@ 2026-09-25 12:55 ` Harshit Mogalapalli
2026-09-25 14:29 ` [PATCH 1/2] mtd: virt-concat: unlink concat node before freeing it Miquel Raynal
1 sibling, 0 replies; 3+ messages in thread
From: Harshit Mogalapalli @ 2026-09-25 12:55 UTC (permalink / raw)
To: Miquel Raynal, Richard Weinberger, Vignesh Raghavendra,
Amit Kumar Mahapatra, Luca Ceresoli, linux-mtd, linux-kernel
Cc: kernel-janitors, error27, harshit.m.mogalapalli, stable
mtd_virt_concat_destroy_items() frees each item without removing it
from concat_node_list. list_for_each_entry_safe() protects the
current traversal, but concat_node_list still points to the freed
items afterward.
The function also unwinds errors from mtd_virt_concat_node_create().
A later initialization can traverse a freed item in
mtd_is_part_concat(), causing a use-after-free.
Unlink each item before freeing it.
Fixes: 43db6366fc2d ("mtd: Add driver for concatenating devices")
Cc: stable@vger.kernel.org
Assisted-by: Codex:gpt-5.6, smatch
Signed-off-by: Harshit Mogalapalli <harshit.m.mogalapalli@oracle.com>
---
Was writing a Smatch check for list APIs and found this. Only compile
tested.
---
drivers/mtd/mtd_virt_concat.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/drivers/mtd/mtd_virt_concat.c b/drivers/mtd/mtd_virt_concat.c
index 1443f0e4c7cb..40b300021dda 100644
--- a/drivers/mtd/mtd_virt_concat.c
+++ b/drivers/mtd/mtd_virt_concat.c
@@ -202,6 +202,7 @@ void mtd_virt_concat_destroy_items(void)
int i;
list_for_each_entry_safe(item, temp, &concat_node_list, head) {
+ list_del(&item->head);
for (i = 0; i < item->count; i++)
of_node_put(item->nodes[i]);
--
2.52.0
^ permalink raw reply [flat|nested] 3+ messages in thread
* Re: [PATCH 1/2] mtd: virt-concat: unlink concat node before freeing it
2026-09-25 12:55 [PATCH 1/2] mtd: virt-concat: unlink concat node before freeing it Harshit Mogalapalli
2026-09-25 12:55 ` [PATCH 2/2] mtd: virt-concat: unlink discarded items before freeing Harshit Mogalapalli
@ 2026-09-25 14:29 ` Miquel Raynal
1 sibling, 0 replies; 3+ messages in thread
From: Miquel Raynal @ 2026-09-25 14:29 UTC (permalink / raw)
To: Richard Weinberger, Vignesh Raghavendra, Luca Ceresoli,
Amit Kumar Mahapatra, linux-mtd, linux-kernel,
Harshit Mogalapalli
Cc: kernel-janitors, error27, stable
On Fri, 25 Sep 2026 05:55:44 -0700, Harshit Mogalapalli wrote:
> mtd_virt_concat_create_item() links each new mtd_virt_concat_node to
> concat_node_list. mtd_virt_concat_destroy() later frees the node after
> destroying its concatenated MTD device, but fails to unlink it. A later
> list traversal dereferences the freed node, causing a use-after-free.
>
> Remove the node from concat_node_list before freeing it.
>
> [...]
Applied to mtd/next, thanks!
[1/2] mtd: virt-concat: unlink concat node before freeing it
commit: 532caaa2f445b22b74b88b4023a810426772db54
[2/2] mtd: virt-concat: unlink discarded items before freeing
commit: 112a666bd82e96e4a01e0cd8a0fb9c88dd0bce38
Patche(s) should be available on mtd/linux.git and will be
part of the next PR (provided that no robot complains by then).
Kind regards,
Miquèl
^ permalink raw reply [flat|nested] 3+ messages in thread
end of thread, other threads:[~2026-09-25 14:29 UTC | newest]
Thread overview: 3+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-09-25 12:55 [PATCH 1/2] mtd: virt-concat: unlink concat node before freeing it Harshit Mogalapalli
2026-09-25 12:55 ` [PATCH 2/2] mtd: virt-concat: unlink discarded items before freeing Harshit Mogalapalli
2026-09-25 14:29 ` [PATCH 1/2] mtd: virt-concat: unlink concat node before freeing it Miquel Raynal
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®