[PATCH v6 1/6] phy: fsl-imx8mq-usb: fix typec switch leak on probe error path

Xu Yang xu.yang_2 at oss.nxp.com
Thu Jul 16 03:40:50 PDT 2026


On Wed, Jul 15, 2026 at 11:46:25AM +0000, sashiko-bot at kernel.org wrote:
> Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
> 
> Pre-existing issues:
> - [High] The Type-C switch callback `tca_blk_typec_switch_set` can be invoked after the PHY driver is unbound, leading to a Use-After-Free of the driver context.

It's a common issue and it should be fixed in Typec-C subsystem.

Thanks,
Xu Yang

> --
> 
> --- Patch [1]: [PATCH v6 1/6] phy: fsl-imx8mq-usb: fix typec switch leak on probe error path ---
> commit 5e0093cfdd6e9dd648ed3549eb93bacb54164be2
> Author: Felix Gu <ustc.gu at gmail.com>
> 
> phy: fsl-imx8mq-usb: fix typec switch leak on probe error path
> 
> This commit fixes a typec switch resource leak when probe fails after
> imx95_usb_phy_get_tca() succeeds. It transitions the cleanup of the switch
> to use devm_add_action_or_reset() so that it is properly freed on both
> probe failure and driver removal.
> 
> > diff --git a/drivers/phy/freescale/phy-fsl-imx8mq-usb.c b/drivers/phy/freescale/phy-fsl-imx8mq-usb.c
> > index b05d80e849a14..9a33c06d6fc39 100644
> > --- a/drivers/phy/freescale/phy-fsl-imx8mq-usb.c
> > +++ b/drivers/phy/freescale/phy-fsl-imx8mq-usb.c
> > @@ -173,9 +173,9 @@ static struct typec_switch_dev *tca_blk_get_typec_switch(struct platform_device
> >  	return sw;
> >  }
> >  
> > -static void tca_blk_put_typec_switch(struct typec_switch_dev *sw)
> > +static void tca_blk_put_typec_switch(void *data)
> >  {
> > -	typec_switch_unregister(sw);
> > +	typec_switch_unregister(data);
> 
> [Severity: High]
> This is a pre-existing issue, but does typec_switch_unregister() guarantee
> that no consumers will invoke the .set callback afterwards?
> 
> If a consumer acquires the switch using fwnode_typec_switch_get() and holds
> a reference, it appears typec_switch_unregister() removes the device from
> sysfs but doesn't revoke the consumer's ability to call sw_dev->set().
> 
> Because imx_phy and tca are allocated with devm_kzalloc() during probe, they
> are automatically freed when the provider unbinds. Could this lead to a
> use-after-free if the consumer asynchronously calls typec_switch_set():
> 
> tca_blk_typec_switch_set()
>     struct imx8mq_usb_phy *imx_phy = typec_switch_get_drvdata(sw);
>     struct tca_blk *tca = imx_phy->tca;
> 
> where imx_phy has already been freed by the devm teardown?
> 
> >  }
> >  
> >  static void tca_blk_orientation_set(struct tca_blk *tca,
> 
> [ ... ]
> 
> -- 
> Sashiko AI review · https://sashiko.dev/#/patchset/20260715-imx8mp-usb-phy-improvement-v6-0-00d95e270e4c@nxp.com?part=1



More information about the linux-phy mailing list