1: 47287726e92e ! 1: dc3b284a099e wifi: carl9170: Revert "carl9170: devres-ing input_allocate_device" @@ Commit message  This reverts commit 87ddb2fc29f10cf689ff0dfb88a19b7d3687006b.  - carl9170_register() is invoked asynchronously from the - request_firmware_nowait() callback after carl9170_usb_probe() has - already returned, and carl9170_usb_disconnect() calls - carl9170_unregister() followed immediately by carl9170_free(), which - frees struct ar9170 (including ar->wps.name and ar->wps.phys). - - Allocating the WPS button input device via - devm_input_allocate_device(&ar->udev->dev) ties its unregistration to - the parent struct usb_device rather than the driver lifecycle. Even if - it were tied to &ar->intf->dev, devres_release_all() runs after - carl9170_usb_disconnect() has already freed struct ar9170 and - unregistered the parent wiphy device. Consequently, the input device - remains registered on input_dev_list with input->name and input->phys - pointing into freed memory, causing a use-after-free when reading - /proc/bus/input/devices or when generating the KOBJ_REMOVE uevent on - unregistration. + In carl9170_usb_disconnect(), the driver calls carl9170_unregister() + followed immediately by carl9170_free(), freeing struct ar9170 inside + .disconnect(), while devres resources are released only after + .disconnect() returns (and devres on &ar->udev->dev is not released at + all on interface unbind or registration failure), leaving the WPS input + device registered with input->name and input->phys pointing into freed + memory.  Fixes: 87ddb2fc29f1 ("carl9170: devres-ing input_allocate_device") Cc: stable@vger.kernel.org 2: f16cfc40e59d ! 2: 1228e89f2c70 wifi: carl9170: Revert "carl9170: devres-ing hwrng_register usage" @@ Commit message  This reverts commit 23de0fa0d2a05ff71c7bc8df9d12c9f23be83f13.  - carl9170_register() is invoked asynchronously from the - request_firmware_nowait() callback after carl9170_usb_probe() has - already returned, and carl9170_usb_disconnect() calls - carl9170_unregister() followed immediately by carl9170_free(), which - frees struct ar9170 (including struct hwrng ar->rng.rng and - ar->rng.name). - - Registering the hardware random number generator via - devm_hwrng_register(&ar->udev->dev, &ar->rng.rng) ties its - unregistration to the parent struct usb_device rather than the driver - lifecycle. Furthermore, if carl9170_rng_get() fails at the end of - carl9170_register_hwrng(), or when the interface is disconnected and - carl9170_free() frees struct ar9170 before devres_release_all() runs, - the embedded struct hwrng remains registered on the global rng_list in - freed memory, causing a use-after-free. + carl9170_usb_disconnect() frees struct ar9170 inside .disconnect() + before devres release (and devres on &ar->udev->dev is not released + on interface unbind), leaving the embedded struct hwrng registered + on rng_list in freed memory. Furthermore, if carl9170_rng_get() fails + in carl9170_register_hwrng(), the HWRNG also remains registered while + ar is freed on the error path. Revert the devres conversion to restore + explicit HWRNG unregistration.  Fixes: 23de0fa0d2a0 ("carl9170: devres-ing hwrng_register usage") Cc: stable@vger.kernel.org