On 14.10.2021 06:28:33, Zheyu Ma wrote: > When remove the module peek_pci, referencing 'chan' again after > releasing 'dev' will cause UAF. > > Fix this by releasing 'dev' later. > > The following log reveals it: > > [ 35.961814 ] BUG: KASAN: use-after-free in peak_pci_remove+0x16f/0x270 [peak_pci] > [ 35.963414 ] Read of size 8 at addr ffff888136998ee8 by task modprobe/5537 > [ 35.965513 ] Call Trace: > [ 35.965718 ] dump_stack_lvl+0xa8/0xd1 > [ 35.966028 ] print_address_description+0x87/0x3b0 > [ 35.966420 ] kasan_report+0x172/0x1c0 > [ 35.966725 ] ? peak_pci_remove+0x16f/0x270 [peak_pci] > [ 35.967137 ] ? trace_irq_enable_rcuidle+0x10/0x170 > [ 35.967529 ] ? peak_pci_remove+0x16f/0x270 [peak_pci] > [ 35.967945 ] __asan_report_load8_noabort+0x14/0x20 > [ 35.968346 ] peak_pci_remove+0x16f/0x270 [peak_pci] > [ 35.968752 ] pci_device_remove+0xa9/0x250 > > Signed-off-by: Zheyu Ma Applied to linux-can/testing. Thanks, Marc -- Pengutronix e.K. | Marc Kleine-Budde | Embedded Linux | https://www.pengutronix.de | Vertretung West/Dortmund | Phone: +49-231-2826-924 | Amtsgericht Hildesheim, HRA 2686 | Fax: +49-5121-206917-5555 |