CVE-2026-72486: mailbox: mtk-adsp: fix UAF during device teardown
In the Linux kernel, the following vulnerability has been resolved:
mailbox: mtk-adsp: fix UAF during device teardown
When the SOF audio driver fails to initialize (e.g. firmware boot timeout), its devres unwind frees the sndsofdev object that the mailbox client (mtk-adsp-ipc) reaches via chan->cl->rxcallback. The mtk-adsp-mailbox shutdown clears the mailbox command registers but leaves the IRQ line unmasked, so a late interrupt can still queue a threaded handler after mboxfreechannel() had cleared chan->cl, and mboxchanreceiveddata() would then trigger UAF:
BUG: KASAN: slab-use-after-free in sofipc3validatefwversion sofipc3validatefwversion sofipc3dorxwork sofipc3rxmsg mt8196dsphandlerequest mtkadspipcrecv mboxchanreceiveddata mtkadspmboxisr irqthreadfn Freed by task ...: kfree devresreleaseall reallyprobe ... (sof-audio-of-mt8196 probe failure)
The crash was observed roughly three seconds after the failed probe.
disableirq() in shutdown and enableirq() in startup. disableirq() also waits for any in-flight interrupts, so by the time mboxfreechannel() proceeds to clear chan->cl no rxcallback can run.
In addition, request the IRQ with IRQFNOAUTOEN so it stays masked between probe and the first client bind — otherwise an early interrupt can crash on chan->cl == NULL in mboxchanreceiveddata().