[PATCH v1] mmc: mtk-sd: Cancel request timeout work on remove
Ulf Hansson
ulf.hansson at oss.qualcomm.com
Mon Sep 28 09:13:15 PDT 2026
On Tue, Sep 15, 2026 at 4:45 PM Yibo Tan <lhfff at tju.edu.cn> wrote:
>
> The driver queues req_timeout while a request is active.
> msdc_request_done() uses cancel_delayed_work(), which does not wait for
> a timeout callback that has already started.
>
> The timeout callback calls mmc_request_done(), which wakes the request
> waiter, and then continues to use host->dev_comp and check the SDIO IRQ.
> During unbind, msdc_drv_remove() can return and the managed mmc_host can
> be freed before the callback finishes.
>
> KASAN reported use-after-free accesses in msdc_request_done() and
> msdc_recheck_sdio_irq() in each of three unbind tests. The same tests
> completed without a kernel diagnostic after this change.
>
> Call cancel_delayed_work_sync() after mmc_remove_host() has stopped new
> requests and before the driver releases the host resources.
>
> Fixes: 208489032bdd ("mmc: mediatek: Add Mediatek MMC driver")
> Cc: stable at vger.kernel.org
> Assisted-by: Codex:GPT-5
> Signed-off-by: Yibo Tan <lhfff at tju.edu.cn>
Applied for fixes, thanks!
Kind regards
Uffe
> ---
> drivers/mmc/host/mtk-sd.c | 1 +
> 1 file changed, 1 insertion(+)
>
> diff --git a/drivers/mmc/host/mtk-sd.c b/drivers/mmc/host/mtk-sd.c
> index 01ea3adbdf3b..5b160fdad3f0 100644
> --- a/drivers/mmc/host/mtk-sd.c
> +++ b/drivers/mmc/host/mtk-sd.c
> @@ -3216,6 +3216,7 @@ static void msdc_drv_remove(struct platform_device *pdev)
>
> platform_set_drvdata(pdev, NULL);
> mmc_remove_host(mmc);
> + cancel_delayed_work_sync(&host->req_timeout);
> msdc_deinit_hw(host);
> msdc_gate_clock(host);
>
> --
> 2.39.5
>
More information about the Linux-mediatek
mailing list