Compare commits

...
Author SHA1 Message Date
Michael Bestas
c8bc4b74db
Merge remote-tracking branch 'sm8350/lineage-20' into lineage-23.2
* sm8350/lineage-20:
  tipc: fix double-free in tipc_buf_append()
  FROMGIT: HID: logitech-hidpp: Prevent use-after-free on force feedback initialisation failure
  UPSTREAM: nfc: llcp: add missing return after LLCP_CLOSED checks

Change-Id: Ibf3e62f1100281728cb118786d1d2c4dcaec595a
2026-09-09 01:16:28 +03:00
Lee Jones
db44a74f9f
tipc: fix double-free in tipc_buf_append()
[ Upstream commit d293ca716e7d5dffdaecaf6b9b2f857a33dc3d3a ]

tipc_msg_validate() can potentially reallocate the skb it is validating,
freeing the old one.  In tipc_buf_append(), it was being called with a
pointer to a local variable which was a copy of the caller's skb
pointer.

If the skb was reallocated and validation subsequently failed, the error
handling path would free the original skb pointer, which had already
been freed, leading to double-free.

Fix this by checking if head now points to a newly allocated reassembled
skb.  If it does, reassign *headbuf for later freeing operations.

Bug: 500022799
Fixes: d618d09a68 ("tipc: enforce valid ratio between skb truesize and contents")
Suggested-by: Tung Nguyen <tung.quang.nguyen@est.tech>
Signed-off-by: Lee Jones <lee@kernel.org>
Reviewed-by: Tung Nguyen <tung.quang.nguyen@est.tech>
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
[uli: backport to 4.19]
Signed-off-by: Ulrich Hecht <uli@kernel.org>
Reviewed-by: Pavel Machek <pavel@nabladev.com>
Reviewed-by: Nobuhiro Iwamatsu <nobuhiro.iwamatsu.x90@mail.toshiba>
Change-Id: I76d957597768652e2f05be3470bf960f6ff29085
2026-09-09 00:48:51 +03:00
Lee Jones
1f9e522f94
FROMGIT: HID: logitech-hidpp: Prevent use-after-free on force feedback initialisation failure
Presently, if the force feedback initialisation fails when probing the
Logitech G920 Driving Force Racing Wheel for Xbox One, an error number
will be returned and propagated before the userspace infrastructure
(sysfs and /dev/input) has been torn down.  If userspace ignores the
errors and continues to use its references to these dangling entities, a
UAF will promptly follow.

We have 2 options; continue to return the error, but ensure that all of
the infrastructure is torn down accordingly or continue to treat this
condition as a warning by emitting the message but returning success.
It is thought that the original author's intention was to emit the
warning but keep the device functional, less the force feedback feature,
so let's go with that.

Bug: 482992246
Signed-off-by: Lee Jones <lee@kernel.org>
Reviewed-by: Günther Noack <gnoack@google.com>
Signed-off-by: Benjamin Tissoires <bentiss@kernel.org>
(cherry picked from commit f7a4c78bfeb320299c1b641500fe7761eadbd101) # HID
Signed-off-by: Lee Jones <joneslee@google.com>
Change-Id: I2d2148fc1fd977b47e07523ee977070dbfa149b5
2026-09-09 00:41:34 +03:00
Junxi Qian
d3d47118ab
UPSTREAM: nfc: llcp: add missing return after LLCP_CLOSED checks
In nfc_llcp_recv_hdlc() and nfc_llcp_recv_disc(), when the socket
state is LLCP_CLOSED, the code correctly calls release_sock() and
nfc_llcp_sock_put() but fails to return. Execution falls through to
the remainder of the function, which calls release_sock() and
nfc_llcp_sock_put() again. This results in a double release_sock()
and a refcount underflow via double nfc_llcp_sock_put(), leading to
a use-after-free.

Add the missing return statements after the LLCP_CLOSED branches
in both functions to prevent the fall-through.

Bug: 499350302
Fixes: d646960f79 ("NFC: Initial LLCP support")
Signed-off-by: Junxi Qian <qjx1298677004@gmail.com>
Reviewed-by: Eric Dumazet <edumazet@google.com>
Link: https://patch.msgid.link/20260408081006.3723-1-qjx1298677004@gmail.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
(cherry picked from commit 2b5dd4632966c39da6ba74dbc8689b309065e82c)
Signed-off-by: Lee Jones <joneslee@google.com>
Change-Id: I041f20fc1fea32f715d2646579fab071e58688d8
2026-09-09 00:38:21 +03:00
LuK1337
aba9e36d0f
input: fingerprint: etxxx: Fix CFI failure on module init
[    2.458802] Unable to handle kernel NULL pointer dereference at virtual address 0000000000000010
[    2.459516] Internal error: Oops: 96000005 [#1] PREEMPT SMP
[    2.459788] Modules linked in: ec617_drv(+) wcd9xxx_dlkm(+) bolero_cdc_dlkm(+) mbhc_dlkm stub_dlkm q6_dlkm adsp_loader_dlkm leds_aw2016 wcd937x_slave_dlkm rdbg focaltech_fts sec_ts_drv(+) p73 btpower apr_dlkm wcd938x_slave_dlkm wsa881x_analog_dlkm bu520x1nvx q6_notifier_dlkm rmnet_shs wcd_core_dlkm rmnet_offload q6_pdr_dlkm haptic snd_event_dlkm rmnet_core swr_dlkm rmnet_ctl snx0
[    2.460075] CPU: 2 PID: 546 Comm: modprobe Tainted: G S                5.4.302-qgki-g3972ebf038eb #3
[    2.460221] Hardware name: Sony Mobile Communications. PDX225(BLAIR v4) (DT)
[    2.460285] pstate: 80400005 (Nzcv daif +PAN -UAO)
[    2.460398] pc : __cfi_check_fail+0x4/0x50 [ec617_drv]
[    2.460457] lr : __cfi_check+0x1ac/0x1e0 [ec617_drv]
[    2.460912] x21: 02b3a43e29242445 x20: 0000000000000010
[    2.462187] Call trace:
[    2.462240]  __cfi_check_fail+0x4/0x50 [ec617_drv]
[    2.462332]  __cfi_slowpath+0x10c/0x168
[    2.462383]  do_one_initcall+0x1dc/0x384
[    2.462435]  do_init_module+0x4c/0x204
[    2.462522]  load_module+0x1734/0x18c0
[    2.462569]  __arm64_sys_finit_module+0xb4/0xf0
[    2.462617]  el0_svc_common+0xc0/0x1a8
[    2.462698]  el0_svc_handler+0x24/0x70
[    2.462745]  el0_svc+0x8/0x100
[    2.462877] ---[ end trace 711a96c503b0de92 ]---
[    2.481911] Kernel panic - not syncing: Fatal exception

module_init()/module_exit() define init_module/cleanup_module as aliases
of the given functions. With clang r584948 and cross-DSO CFI, such an
alias only gets its own jump table entry when the aliasee has internal
linkage. Since egisfp_init()/egisfp_exit() were declared non-static,
modpost ended up pointing __this_module.init at the raw .init.text
address instead of init_module.cfi_jt:

  R_AARCH64_ABS64  init_module + 0
  R_AARCH64_ABS64  cleanup_module + 0

__cfi_check() then compared the initcall pointer (type id
02b3a43e29242445) against egisfp_init.cfi_jt, failed, and jumped to
__cfi_check_fail(), which faulted while dereferencing its bogus diag
argument.

Make both functions static, as they should have been in the first place.
The relocations now resolve to the jump table:

  R_AARCH64_ABS64  init_module.cfi_jt + 0
  R_AARCH64_ABS64  cleanup_module.cfi_jt + 0

Assisted-by: ClaudeCode:claude-opus-5
Change-Id: I3bf5a698bc5103e1fe0ae13e4c9c52cad9b41c7e
2026-08-30 21:48:49 +03:00
Michael Bestas
b44ad6704a
Merge remote-tracking branch 'sm8350/lineage-20' into lineage-23.2
* sm8350/lineage-20:
  techpack: audio: wcd_cpe: Fix -Wimplicit-enum-enum-cast
  qcacld-3.0: Fix implicit enum-enum-cast warnings

Change-Id: Ibce416295c81d6a22dd555343e60a405048c5c8d
2026-08-30 17:25:54 +03:00
Michael Bestas
925d92bed5 techpack: audio: wcd_cpe: Fix -Wimplicit-enum-enum-cast
Change-Id: Ie415813c248c86c162673ea932927ffd1d35755d
2026-08-29 22:52:17 -04:00
angelomds42
b9f3e9838b
qcacld-3.0: Fix implicit enum-enum-cast warnings
This fixes the following warning when building with newer clang:
error: implicit conversion from enumeration type
      'A_STATUS' to different enumeration type 'QDF_STATUS' [-Werror,-Wimplicit-enum-enum-cast]

Change-Id: I84f9f9b0406fad6df74749cbcb2cb176d42525aa
Signed-off-by: angelomds42 <angelomds42@gmail.com>
2026-08-28 11:13:36 +02:00
8 changed files with 29 additions and 13 deletions

View file

@ -3743,10 +3743,12 @@ static int hidpp_probe(struct hid_device *hdev, const struct hid_device_id *id)
if (hidpp->quirks & HIDPP_QUIRK_CLASS_G920) {
ret = hidpp_ff_init(hidpp, &data);
if (ret)
if (ret) {
hid_warn(hidpp->hid_dev,
"Unable to initialize force feedback support, errno %d\n",
ret);
ret = 0;
}
}
return ret;

View file

@ -1543,7 +1543,7 @@ egistec_probe_failed:
return status;
}
int __init egisfp_init(void)
static int __init egisfp_init(void)
{
int status;
INFO_PRINT(" %s : module init \n", __func__);
@ -1556,7 +1556,7 @@ int __init egisfp_init(void)
INFO_PRINT(" %s : module init OK ! \n", __func__);
return status;
}
void __exit egisfp_exit(void)
static void __exit egisfp_exit(void)
{
INFO_PRINT("module exit \n");
platform_driver_unregister(&egisfp_driver);

View file

@ -1473,7 +1473,7 @@ egistec_probe_failed:
return status;
}
int __init egisfp_init(void)
static int __init egisfp_init(void)
{
int status;
INFO_PRINT(" %s : module init \n", __func__);
@ -1486,7 +1486,7 @@ int __init egisfp_init(void)
INFO_PRINT(" %s : module init OK ! \n", __func__);
return status;
}
void __exit egisfp_exit(void)
static void __exit egisfp_exit(void)
{
INFO_PRINT("module exit \n");
platform_driver_unregister(&egisfp_driver);

View file

@ -1389,7 +1389,7 @@ egistec_probe_failed:
return status;
}
int __init egisfp_init(void)
static int __init egisfp_init(void)
{
int status;
INFO_PRINT(" %s : module init \n", __func__);
@ -1402,7 +1402,7 @@ int __init egisfp_init(void)
INFO_PRINT(" %s : module init OK ! \n", __func__);
return status;
}
void __exit egisfp_exit(void)
static void __exit egisfp_exit(void)
{
INFO_PRINT("module exit \n");
platform_driver_unregister(&egisfp_driver);

View file

@ -629,7 +629,7 @@ htt_h2t_rx_ring_cfg_msg_hl(struct htt_pdev_t *pdev)
pkt = htt_htc_pkt_alloc(pdev);
if (!pkt)
return A_ERROR; /* failure */
return QDF_STATUS_E_FAILURE; /* failure */
/*
* show that this is not a tx frame download
@ -645,7 +645,7 @@ htt_h2t_rx_ring_cfg_msg_hl(struct htt_pdev_t *pdev)
HTC_HEADER_LEN + HTC_HDR_ALIGNMENT_PADDING, 4, true);
if (!msg) {
htt_htc_pkt_free(pdev, pkt);
return A_ERROR; /* failure */
return QDF_STATUS_E_FAILURE; /* failure */
}
/*
* Set the length of the message.

View file

@ -1096,6 +1096,7 @@ static void nfc_llcp_recv_hdlc(struct nfc_llcp_local *local,
if (sk->sk_state == LLCP_CLOSED) {
release_sock(sk);
nfc_llcp_sock_put(llcp_sock);
return;
}
/* Pass the payload upstream */
@ -1187,6 +1188,7 @@ static void nfc_llcp_recv_disc(struct nfc_llcp_local *local,
if (sk->sk_state == LLCP_CLOSED) {
release_sock(sk);
nfc_llcp_sock_put(llcp_sock);
return;
}
if (sk->sk_state == LLCP_CONNECTED) {

View file

@ -175,8 +175,20 @@ int tipc_buf_append(struct sk_buff **headbuf, struct sk_buff **buf)
if (fragid == LAST_FRAGMENT) {
TIPC_SKB_CB(head)->validated = false;
if (unlikely(!tipc_msg_validate(&head)))
/* If the reassembled skb has been freed in
* tipc_msg_validate() because of an invalid truesize,
* then head will point to a newly allocated reassembled
* skb, while *headbuf points to freed reassembled skb.
* In such cases, correct *headbuf for freeing the newly
* allocated reassembled skb later.
*/
if (unlikely(!tipc_msg_validate(&head))) {
if (head != *headbuf)
*headbuf = head;
goto err;
}
*buf = head;
TIPC_SKB_CB(head)->tail = NULL;
*headbuf = NULL;

View file

@ -987,7 +987,7 @@ static enum cpe_svc_result broadcast_boot_event(
static enum cpe_process_result cpe_boot_initialize(struct cpe_info *t_info,
enum cpe_svc_result *cpe_rc)
{
enum cpe_process_result rc = CPE_SVC_FAILED;
enum cpe_process_result rc = CPE_PROC_FAILED;
struct cpe_svc_notification payload;
struct cmi_core_svc_event_system_boot *p = NULL;
@ -1991,7 +1991,7 @@ enum cmi_api_result cmi_send_msg(void *message)
GFP_ATOMIC);
if (!msg) {
CPE_SVC_REL_LOCK(&cpe_d.cpe_api_mutex, "cpe_api");
return CPE_SVC_NO_MEMORY;
return CMI_API_NO_MEMORY;
}
if (CMI_HDR_GET_OBM_FLAG(hdr) == CMI_OBM_FLAG_OUT_BAND)
@ -2006,7 +2006,7 @@ enum cmi_api_result cmi_send_msg(void *message)
if (!msg->payload) {
kfree(msg);
CPE_SVC_REL_LOCK(&cpe_d.cpe_api_mutex, "cpe_api");
return CPE_SVC_NO_MEMORY;
return CMI_API_NO_MEMORY;
}
msg->address = 0;