[PATCH 1/1] char: Use list_del_init() in misc_deregister() to reinitialize list pointer
xion.wang at mediatek.com
xion.wang at mediatek.com
Wed Sep 3 23:37:04 PDT 2025
From: Xion Wang <xion.wang at mediatek.com>
Currently, misc_deregister() uses list_del() to remove the device
from the list. After list_del(), the list pointers are set to
LIST_POISON1 and LIST_POISON2, which may help catch use-after-free bugs,
but does not reset the list head.
If misc_deregister() is called more than once on the same device,
list_empty() will not return true, and list_del() may be called again,
leading to undefined behavior.
Replace list_del() with list_del_init() to reinitialize the list head
after deletion. This makes the code more robust against double
deregistration and allows safe usage of list_empty() on the miscdevice
after deregistration.
Fixes: b329becfc78b1 ("char: add WARN_ON() in misc_deregister()")
Signed-off-by: Xion Wang <xion.wang at mediatek.com>
---
drivers/char/misc.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/char/misc.c b/drivers/char/misc.c
index 558302a64dd9..b5d44b08ad7b 100644
--- a/drivers/char/misc.c
+++ b/drivers/char/misc.c
@@ -279,7 +279,7 @@ void misc_deregister(struct miscdevice *misc)
return;
mutex_lock(&misc_mtx);
- list_del(&misc->list);
+ list_del_init(&misc->list);
device_destroy(&misc_class, MKDEV(MISC_MAJOR, misc->minor));
misc_minor_free(misc->minor);
mutex_unlock(&misc_mtx);
--
2.45.2
More information about the linux-arm-kernel
mailing list