jerpelea opened a new pull request, #20290: URL: https://github.com/apache/nuttx/pull/20290
## Summary sensor_poll() arms a per-subscriber watchdog for fetch()-only sensors with a requested interval. The watchdog handler sensor_fetch_expired() dereferences the subscriber and re-arms itself unless user->fds is NULL. sensor_poll() teardown clears user->fds and cancels the watchdog, but sensor_close() removed the subscriber from the user list and freed it without doing either. A close() racing an armed timer therefore lets the handler run after the subscriber is freed, causing a timer-context use-after-free and re-arm of a freed watchdog. Mirror the poll teardown in sensor_close(): clear user->fds and cancel user->wdog under upper->lock before notifying other users and freeing the subscriber. Fixes #20145. ## Impact RELEASE ## Testing CI -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
