From df717747fdf18d12fa0606b64d77b1d8db9c1d08 Mon Sep 17 00:00:00 2001 From: Harini Manikumar Date: Thu, 4 Sep 2025 17:27:06 +0530 Subject: [PATCH] msm: smmu: Unregister SMMU fault handler before cleanup IOMMU fault handler can be invoked post SMMU destroy which can lead to use-after-free issue. Unregister the SMMU fault handler before freeing SMMU context and unregistering the platform device. Change-Id: I1cddd4a381f16d650258850a3d012d380fbe5ef8 Signed-off-by: Harini Manikumar Signed-off-by: Karthik Veeranki --- msm/msm_smmu.c | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/msm/msm_smmu.c b/msm/msm_smmu.c index 53f5f926560a..af9ba0ba87f5 100644 --- a/msm/msm_smmu.c +++ b/msm/msm_smmu.c @@ -1,4 +1,5 @@ /* + * Copyright (c) Qualcomm Technologies, Inc. and/or its subsidiaries. * Copyright (c) 2015-2020, The Linux Foundation. All rights reserved. * Copyright (C) 2013 Red Hat * Author: Rob Clark @@ -211,6 +212,10 @@ static void msm_smmu_destroy(struct msm_mmu *mmu) { struct msm_smmu *smmu = to_msm_smmu(mmu); struct platform_device *pdev = to_platform_device(smmu->client_dev); + struct iommu_domain *domain = iommu_get_domain_for_dev(smmu->client_dev); + + if (domain) + iommu_set_fault_handler(domain, NULL, NULL); if (smmu->client_dev) platform_device_unregister(pdev);