From 5bc4b708d1b0ae19cf66e33373ac768709e45b7a Mon Sep 17 00:00:00 2001 From: Sriharsha Allenki Date: Tue, 5 Mar 2019 16:29:53 +0530 Subject: [PATCH] xhci: Fix NULL pointer dereference with xhci_irq() for shared_hcd Commit ("f068090426ea xhci: Fix leaking USB3 shared_hcd at xhci removal") sets xhci_shared_hcd to NULL without stopping xhci host. This results into a race condition where shared_hcd (super speed roothub) related interrupts are being handled with xhci_irq happens when the xhci_plat_remove is called and shared_hcd is set to NULL. Fix this by setting the shared_hcd to NULL only after the controller is halted and no interrupts are generated. Change-Id: I2c7e460c171eacbf26d0bf7185d563ddb9efb504 Signed-off-by: Sriharsha Allenki --- drivers/usb/host/xhci-plat.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/drivers/usb/host/xhci-plat.c b/drivers/usb/host/xhci-plat.c index 4608dccbbf77..997bc1e57ff3 100644 --- a/drivers/usb/host/xhci-plat.c +++ b/drivers/usb/host/xhci-plat.c @@ -374,10 +374,10 @@ static int xhci_plat_remove(struct platform_device *dev) xhci->xhc_state |= XHCI_STATE_REMOVING; usb_remove_hcd(shared_hcd); - xhci->shared_hcd = NULL; usb_phy_shutdown(hcd->usb_phy); usb_remove_hcd(hcd); + xhci->shared_hcd = NULL; usb_put_hcd(shared_hcd); clk_disable_unprepare(clk);