Re: [PATCH 1/2] serial: tegra: fix RX DMA descriptor use-after-free
From: Austin Schlegel
Date: Fri Oct 02 2026 - 00:36:40 EST
> tegra_uart_terminate_rx_dma() calls dmaengine_terminate_all() and then
> tegra_uart_rx_buffer_push(), which calls async_tx_ack(tup->rx_dma_desc)
> ...
> The same freed-descriptor access happens via tegra_uart_rx_dma_complete(),
> which also reaches tegra_uart_rx_buffer_push() after RX has stopped.
This second paragraph is wrong - the descriptor is still valid inside
tegra_uart_rx_dma_complete(); the ack only moves there because it's
removed from tegra_uart_rx_buffer_push(). I'll fix this in v2.
> Soak tested on Tegra234 (Jetson AGX Orin) for 13+ hours with
> kfence.sample_interval=1 and continuous UART loopback traffic...
This should state 24+ hours, I'll update the number in v2.
This e-mail and any files transmitted with it are the property of Arthrex, Inc. and/or its affiliates, are confidential, and are intended solely for the use of the individual or entity to whom this e-mail is addressed. If you are not one of the named recipient(s) or otherwise have reason to believe that you have received this message in error, please notify the sender at 239-598-4302 and delete this message immediately from your computer. Any other use, retention, dissemination forwarding, printing or copying of this e-mail is strictly prohibited. Please note that any views or opinions presented in this email are solely those of the author and do not necessarily represent those of the company. Finally, while Arthrex uses virus protection, the recipient should check this email and any attachments for the presence of viruses. The company accepts no liability for any damage caused by any virus transmitted by this email.