Re: [PATCH] nvdimm/bus: Fix dev double put in nd_async_device_register()

From: Alison Schofield

Date: Fri Oct 09 2026 - 22:25:01 EST


On Thu, Sep 17, 2026 at 12:28:16PM +0000, Wentao Liang wrote:
> device_add() takes and drops its own reference on every return path, so
> the async worker only owns the reference that __nd_device_register()
> took with get_device(). The failure branch drops that same reference once
> more before the unconditional put_device(), which underflows the refcount
> and frees the device while it is still referenced by its creator, as
> reported by KASAN for the parent pointer access in this function.
>
> Drop the spurious put_device() from the failure branch.

Hi Wentao,

Thanks for following up a KASAN report. I do agree with the Sashiko raised
concern. I'm not seeing an extra put_device().

The device has its initial reference from device_initialize(), and
__nd_device_register() takes an additional reference for the async work.
If device_add() fails, it doesn't consume either of those references.

The failure-path put_device() releases the initial reference, while
the unconditional put_device() releases the async reference. Removing
the first one would leave the initial reference outstanding, potentially
leaking the device.

Could you also share the KASAN report that prompted this change?
The parent pointer is saved before either reference is dropped and
the async registration path holds a separate reference to the parent.
I'd like to better understand where the reported use-after-free occurs.

Thanks!

-- Alison

>
> Fixes: 4d88a97aa9e8c ("libnvdimm, nvdimm: dimm driver and base libnvdimm device-driver infrastructure")
> Cc: stable@xxxxxxxxxxxxxxx
> Signed-off-by: Wentao Liang <vulab@xxxxxxxxxxx>
> ---
> drivers/nvdimm/bus.c | 4 +---
> 1 file changed, 1 insertion(+), 3 deletions(-)
>
> diff --git a/drivers/nvdimm/bus.c b/drivers/nvdimm/bus.c
> index 45b7d756e39a..a1f33a03aba8 100644
> --- a/drivers/nvdimm/bus.c
> +++ b/drivers/nvdimm/bus.c
> @@ -488,10 +488,8 @@ static void nd_async_device_register(void *d, async_cookie_t cookie)
> struct device *dev = d;
> struct device *parent = dev->parent;
>
> - if (device_add(dev) != 0) {
> + if (device_add(dev) != 0)
> dev_err(dev, "%s: failed\n", __func__);
> - put_device(dev);
> - }
> put_device(dev);
> if (parent)
> put_device(parent);
> --
> 2.34.1
>
>