Re: [PATCH v2 3/3] soundwire: intel_auxdevice: Don't disable IRQs before removing children
From: Charles Keepax
Date: Mon Oct 05 2026 - 09:12:11 EST
On Mon, Oct 05, 2026 at 11:32:05AM +0100, Charles Keepax wrote:
> On Sun, Oct 04, 2026 at 12:29:58PM +0000, Richard Patel wrote:
> > On Fri, Sep 25, 2026 at 04:42:16PM +0100, Charles Keepax wrote:
> > I don't understand the code very well, but isn't there a second UAF
> > with the ctx object getting freed? kfree(ctx) in sdw_intel_exit()
> > runs well before the IRQ is unregistered.
>
> This situation is unfortunately fairly complex, the IRQ is shared
> between many different functions and only the SoundWire function
> relies on ctx. I will do some more poking, but I believe the
> free order is such that the soundwire stuff is shutdown before
> ctx is freed. I am not 100% certain if that will prevent the
> SoundWire IRQ path from getting called, although I would like
> to believe it does :-)
Hmm... ok so poking this a little more looks like I do see just
see these freed in hard the wrong order so we should probably
fix that up too. Thanks for spotting that I will have a bit of
a think.
Thanks,
Charles