Re: [PATCH v2 3/3] soundwire: intel_auxdevice: Don't disable IRQs before removing children

From: Charles Keepax

Date: Mon Oct 05 2026 - 06:32:28 EST


On Sun, Oct 04, 2026 at 12:29:58PM +0000, Richard Patel wrote:
> On Fri, Sep 25, 2026 at 04:42:16PM +0100, Charles Keepax wrote:
> I ran into a use-after-free on Samsung Galaxy Book6 (Panther Lake)
> the other day. I was going to send a patch adding RCU, then I saw
> your patch already added a mutex:
>
> sof-audio-pci-intel-ptl 0000:00:1f.3: SOF firmware and/or topology file not found.
> Oops: general protection fault, kernel NULL pointer dereference 0x3c0: 0000 [#1] SMP NOPTI
> RIP: 0010:sdw_cdns_irq+0x9/0x1f0 [soundwire_cadence]
> Call Trace:
> sdw_intel_thread+0x2d/0x50 [soundwire_intel]
> hda_dsp_interrupt_thread+0x97/0x320 [snd_sof_intel_hda_generic]
> irq_thread_fn+0x23/0x60
> irq_thread+0xc7/0x190
>
> I would add 'Fixes: 4a98a6b2fa75 ("soundwire: intel/cadence: merge Soundwire interrupt handlers/threads")' maybe

I can probably add a fixes here, will have a look.

>
> > @@ -145,8 +155,10 @@ irqreturn_t sdw_intel_thread(int irq, void *dev_id)
> > struct sdw_intel_ctx *ctx = dev_id;
> > struct sdw_intel_link_res *link;
> >
> > + mutex_lock(&ctx->link_lock);
> > list_for_each_entry(link, &ctx->link_list, list)
> > sdw_cdns_irq(irq, link->cdns);
> > + mutex_unlock(&ctx->link_lock);
> >
> > return IRQ_HANDLED;
> > }
>
> I don't understand the code very well, but isn't there a second UAF
> with the ctx object getting freed? kfree(ctx) in sdw_intel_exit()
> runs well before the IRQ is unregistered.

This situation is unfortunately fairly complex, the IRQ is shared
between many different functions and only the SoundWire function
relies on ctx. I will do some more poking, but I believe the
free order is such that the soundwire stuff is shutdown before
ctx is freed. I am not 100% certain if that will prevent the
SoundWire IRQ path from getting called, although I would like
to believe it does :-)

Thanks,
Charles