[PATCH] crypto: ccp: kill v3 IRQ tasklet during teardown

From: Jiale Yao

Date: Sun Sep 20 2026 - 13:35:26 EST


On PCI devices using MSI-X, ccp_irq_handler() schedules irq_tasklet. The
teardown paths release the IRQ but do not drain a tasklet that was
already queued, so it can access ccp after the device-managed allocation
has been released.

Kill the tasklet after releasing the IRQ in both the initialization
error path and ccp_destroy().

Fixes: 7b537b24e76a ("crypto: ccp - Change ISR handler method for a v3 CCP")

Signed-off-by: Jiale Yao <yaojiale02@xxxxxxx>
---
drivers/crypto/ccp/ccp-dev-v3.c | 4 ++++
1 file changed, 4 insertions(+)

diff --git a/drivers/crypto/ccp/ccp-dev-v3.c b/drivers/crypto/ccp/ccp-dev-v3.c
index fe69053b2394..e85b4ded417a 100644
--- a/drivers/crypto/ccp/ccp-dev-v3.c
+++ b/drivers/crypto/ccp/ccp-dev-v3.c
@@ -506,6 +506,8 @@ static int ccp_init(struct ccp_device *ccp)
kthread_stop(ccp->cmd_q[i].kthread);

sp_free_ccp_irq(ccp->sp, ccp);
+ if (ccp->use_tasklet)
+ tasklet_kill(&ccp->irq_tasklet);

e_pool:
for (i = 0; i < ccp->cmd_q_count; i++)
@@ -545,6 +547,8 @@ static void ccp_destroy(struct ccp_device *ccp)
kthread_stop(ccp->cmd_q[i].kthread);

sp_free_ccp_irq(ccp->sp, ccp);
+ if (ccp->use_tasklet)
+ tasklet_kill(&ccp->irq_tasklet);

for (i = 0; i < ccp->cmd_q_count; i++)
dma_pool_destroy(ccp->cmd_q[i].dma_pool);
--
2.34.1