From nobody Sat Jul 25 21:24:07 2026 Received: from fout-a4-smtp.messagingengine.com (fout-a4-smtp.messagingengine.com [103.168.172.147]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 00972340410; Mon, 13 Jul 2026 15:44:43 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=103.168.172.147 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1783957487; cv=none; b=qce+mDuEzzr98EP9OcQXZ5LQ13ADSqzshs0xr+dy22MXboKBDCi3LoEuSzHBHpSCtAK5fmVettQalsA71dzyZa4Go62pHDWZp+UyVBZsuDY5xu99OCZRc6+jwTdHih95co9Gd8/kZlmwxpDkJapynkNebs6uRf3Ni/7GxY8uM74= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1783957487; c=relaxed/simple; bh=i2CZTUXEQ3hou/RGOkSypfDwEldYfuj/m1E4ty+SM5Q=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=fJgzEq82XZDPGKB6w7QF8+RAGJGAvC2DgMTgcHr4I2wRmC2q/WVRAwM92HQC9AjnGBxw5M5CZIdPmxOWCXQIBb31n8bSEGI41u7EtjkfFMfrAuiXSSt7mjPgHpGFsLAz1cbs/C1RyIZRENIXUwAITJPhbSIlFD/6F/96nlTOtTg= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=kroah.com; spf=pass smtp.mailfrom=kroah.com; dkim=pass (2048-bit key) header.d=kroah.com header.i=@kroah.com header.b=pPUDON79; dkim=pass (2048-bit key) header.d=messagingengine.com header.i=@messagingengine.com header.b=lQzi46iX; arc=none smtp.client-ip=103.168.172.147 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=kroah.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=kroah.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kroah.com header.i=@kroah.com header.b="pPUDON79"; dkim=pass (2048-bit key) header.d=messagingengine.com header.i=@messagingengine.com header.b="lQzi46iX" Received: from phl-compute-05.internal (phl-compute-05.internal [10.202.2.45]) by mailfout.phl.internal (Postfix) with ESMTP id 554D2EC0084; Mon, 13 Jul 2026 11:44:42 -0400 (EDT) Received: from phl-frontend-04 ([10.202.2.163]) by phl-compute-05.internal (MEProxy); Mon, 13 Jul 2026 11:44:42 -0400 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=kroah.com; h=cc :cc:content-transfer-encoding:content-type:content-type:date :date:from:from:in-reply-to:in-reply-to:message-id:mime-version :references:reply-to:subject:subject:to:to; s=fm2; t=1783957482; x=1784043882; bh=kk3oo+cn7S549tlbg/+iWEtaXESiNMv/FlPnN5HZBUI=; b= pPUDON7968WWx8qw8R/ihERPndX/LfOI4lAI2XvoYcwi0qLGZBabTYaiY40kVPJT W7uNVMep+buX2wtMub5c5w3KhIZa0htpE+TKgZ/4eGIw8Ur6bH2e++Hq2XfQurUc ltthzGBMXrP7M3CFDH72rEr4YrLvOMwymrG3B0HaM2i/WTmyaE1o/+ehBg7h+Xds U3MHy878OWRwHiajQRB0c6O5m7Ba4l0A3t7K+GbrVmhWoK5JG0EcuU2QWfVmmP/S G1LUVDLY0NwPxQrrjWyYpipbhP6UZDwylGdEkTuAwfTnh+1QwZA1Uyyj5uhzxJnt A6lp1elKeSXPEDNZliTbLw== DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d= messagingengine.com; h=cc:cc:content-transfer-encoding :content-type:content-type:date:date:feedback-id:feedback-id :from:from:in-reply-to:in-reply-to:message-id:mime-version :references:reply-to:subject:subject:to:to:x-me-proxy :x-me-sender:x-me-sender:x-sasl-enc; s=fm2; t=1783957482; x= 1784043882; bh=kk3oo+cn7S549tlbg/+iWEtaXESiNMv/FlPnN5HZBUI=; b=l Qzi46iXTv5KQ9OEGZDv27II+NmoPFbc1gXwBxhjABwuvoW7QbjePYFKqVaRzgU3k AHRADZw+fcE+bO4Joa9Uz6dYbOr68r3QoX22aphbw4CxneQ1VxSSDszslfMNlin6 XAWuNCqhJbkqid7UyOWDIC301mJT9Xn9FGT5pBL1Ui0IBPjzKREVvSfcI4kyP9do 0Jex7Pg/yNmtcqPnDERG79Ik4ZFPIVFOusjh6Oh+X+O25uOCDN0dCqUe24P4C3Hv AC4YO4NoB4L0FE5MNrU9tFpkeBwgg/rZUQ8i2XTDj7o4tYOkh4d45Di9x5+XYDAD BGtHMnCqzV/rbnpxPNpgw== X-ME-Sender: X-ME-Received: X-ME-Proxy-Cause: dmFkZTFY6lH9UbikzGGF+9sTo8UnYKIW62Rg0AFuhhMRxe07csUQLwTQQfvo4sy375h/2V Zr/B98moAMOnyZQc0VbUs8/0nQgbxv8BFVIvKwhho5KTzQkAcyd0Vd3LLCSLohNBSMvv3f nNZzs+RUmFJ7N3+Jh74cJuWWmgOlbSSRIKuYu4y1cGYLGe8hfMD3YhSXQ9elcHbZpvhVwq CnVsURCx4qbz6b3Fevycl3cZxx/tUTnzwkeDlYUn+08SoZotEhtT3huicw7MBejLP2aKkV +4GdT2B09kBadJKQMqneWwJoWrlcm0YoXzzK/QlifjeAGuPHj1XuxvYzd+OYapojrw3aJJ fbzelQ4YHTAOZuuPQPJXpl4JuHr9O22drgWPOdlsHUBGziw0haqErzX1vcUbnvbuBb49U3 IvT0eUzg2gYtqG+xHZmFsJI0JzucybiJZKNaEyfXmA6G+3U9iyj/ByhVIbi7wM1rpiHeBL a+55DuZM+uItLFBOh5yjhyxKisNn3GROC6wUqg2XkRv6LmJVDVwRXCIy2j3T/sDLPunUv7 +BIeQAnRq5HqDAKXSTxsG6mXNvBkMk8osMLKhhfZlxgYatuFuWT/yt6PesYiHl7FyFAebx 4Wu187Oeu6ed1KMH5dlOXt16KC5Rd2xA7pF/N410TQlnNE2jKAluxlm5HqFA X-ME-Proxy: Feedback-ID: i1d2843be:Fastmail Received: by mail.messagingengine.com (Postfix) with ESMTPA; Mon, 13 Jul 2026 11:44:38 -0400 (EDT) From: Griffin Kroah-Hartman Date: Mon, 13 Jul 2026 17:43:51 +0200 Subject: [PATCH 1/3] usb: core: Add size check to find_next_descriptor() Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260713-usb_core_patches_1-v1-1-7721c2b33f53@kroah.com> References: <20260713-usb_core_patches_1-v1-0-7721c2b33f53@kroah.com> In-Reply-To: <20260713-usb_core_patches_1-v1-0-7721c2b33f53@kroah.com> To: Greg Kroah-Hartman Cc: linux-usb@vger.kernel.org, linux-kernel@vger.kernel.org, Griffin Kroah-Hartman X-Mailer: b4 0.15.2 X-Developer-Signature: v=1; a=ed25519-sha256; t=1783957473; l=899; i=griffin@kroah.com; s=20260706; h=from:subject:message-id; bh=i2CZTUXEQ3hou/RGOkSypfDwEldYfuj/m1E4ty+SM5Q=; b=RUrgy1yMo0i72Ua1qWrrKQOULEuhroZkV0dOBWGqDGyJw7DO3lhTHZtxCGcQh8DqAoHfxGEbu Y4jqFzgRNyKBQwSTrztUwCeTjcgtlQEipkyxffs9SjPvKE8ppwC5C7c X-Developer-Key: i=griffin@kroah.com; a=ed25519; pk=Hy1TuVHERdQhLAWwjmxLFNtGj7eEEjaZWPXehAlic5M= Add a size check for the descriptor header in find_next_descriptor(). This prevents a scenario where h->blength =3D 0, causing the while loop to spin forever. Assisted-by: gkh_clanker_t1000 Signed-off-by: Griffin Kroah-Hartman --- drivers/usb/core/config.c | 2 ++ 1 file changed, 2 insertions(+) diff --git a/drivers/usb/core/config.c b/drivers/usb/core/config.c index 45e20c6d76c0..17c93e95945f 100644 --- a/drivers/usb/core/config.c +++ b/drivers/usb/core/config.c @@ -29,6 +29,8 @@ static int find_next_descriptor(unsigned char *buffer, in= t size, /* Find the next descriptor of type dt1 or dt2 */ while (size > 0) { h =3D (struct usb_descriptor_header *) buffer; + if (h->bLength < sizeof(struct usb_descriptor_header)) + break; if (h->bDescriptorType =3D=3D dt1 || h->bDescriptorType =3D=3D dt2) break; buffer +=3D h->bLength; --=20 2.55.0 From nobody Sat Jul 25 21:24:07 2026 Received: from fout-a4-smtp.messagingengine.com (fout-a4-smtp.messagingengine.com [103.168.172.147]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id EE6CD3DE425; Mon, 13 Jul 2026 15:44:48 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=103.168.172.147 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1783957492; cv=none; b=F5GFeiLiHWdZTIucPHPMdZX0YMSSRxyt1ajqivLVCw7qG5+wrg4WLyr7xgX8se7qWyudPN6XwIe5mML1Ht/jLuqA/xeRK7hB7NncWRx+RCe38nzNL8M/VH3M1OuPEIzO1l7JVRsxSMPvv0sZe65gp3pzo8jOeCT2fz3P1Z1Wdxk= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1783957492; c=relaxed/simple; bh=0VCccmYDWpK/oTYjIIoywXY3zSry1JDAoxEb1Xrp29A=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=mGtTwjhB1HpJnxwSh0Quxn90o+u5+ZggbS0JwkpI4AAhZdVvYooCnKnDo5k/KxrDUYGjLqwLi+ylFz9BgvQiFyGoTEnuWXtV5kpb6VgPJR7GXgaxJcwLk+a3dqjpikOATDGUWp7vWysOg9GQTcaFxWxpuqO7daAvdRwMOB3wNBc= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=kroah.com; spf=pass smtp.mailfrom=kroah.com; dkim=pass (2048-bit key) header.d=kroah.com header.i=@kroah.com header.b=Hq9ht7Zp; dkim=pass (2048-bit key) header.d=messagingengine.com header.i=@messagingengine.com header.b=miJoZoRm; arc=none smtp.client-ip=103.168.172.147 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=kroah.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=kroah.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kroah.com header.i=@kroah.com header.b="Hq9ht7Zp"; dkim=pass (2048-bit key) header.d=messagingengine.com header.i=@messagingengine.com header.b="miJoZoRm" Received: from phl-compute-02.internal (phl-compute-02.internal [10.202.2.42]) by mailfout.phl.internal (Postfix) with ESMTP id A2E31EC0084; Mon, 13 Jul 2026 11:44:47 -0400 (EDT) Received: from phl-frontend-04 ([10.202.2.163]) by phl-compute-02.internal (MEProxy); Mon, 13 Jul 2026 11:44:47 -0400 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=kroah.com; h=cc :cc:content-transfer-encoding:content-type:content-type:date :date:from:from:in-reply-to:in-reply-to:message-id:mime-version :references:reply-to:subject:subject:to:to; s=fm2; t=1783957487; x=1784043887; bh=zM35qb7+kQwuMuWX0N7MHmQezh7Ps2eM5se/5PKIfDM=; b= Hq9ht7ZpAfA3ZCoNjB9QxvRb0TacrvqvrUeM88NLl7toIKZNwJMG35DM+E3geAMA 0vbK0ZrDFN3fja9DqepjrPiwmVcz3GyljfIPrLubTxT0NVIg6AxRcpG29CHFQWSv JULhg3d5dCNlkBuMfDH56LgtcXaH+eC9OnE8CNsQnCI8TBJWv+BRYImXOGCTkT4l uDQbxY23J/QGG/YOzrNSFu/yIQcNKl/bN/428pGksxoabt307r3hCqOMSU7r96HT NZjorp74M4RnOzo1hDZLEOrMOXUNdjcMtsDGLp5u8FCoahGCxO/hviplMTCipD2k e22cb0pciwq4FsF7cdaw/Q== DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d= messagingengine.com; h=cc:cc:content-transfer-encoding :content-type:content-type:date:date:feedback-id:feedback-id :from:from:in-reply-to:in-reply-to:message-id:mime-version :references:reply-to:subject:subject:to:to:x-me-proxy :x-me-sender:x-me-sender:x-sasl-enc; s=fm2; t=1783957487; x= 1784043887; bh=zM35qb7+kQwuMuWX0N7MHmQezh7Ps2eM5se/5PKIfDM=; b=m iJoZoRmYtZHVmqwm/6/lEX99h6hBMGAbxGKaR7/4BgDB7AqrDCZRX6+IbgDZ0ijN 9TztdLVVzf/Q6Z8KRWhqFtOJChCgV1Ig+ZXip0KCmytFHG938JR7Ep2CpHQMTFyS eLDJw4ZEBoYiaYqiZ6YoSjQEGbMC0nCjHoYY0vxInfJkxW2Svmvutfz8VXsfjxFR sVGC+kAaeLCg7DX5eCuzSLanEZTQnHsAvJA3Zc8f+dEjgx3L97OCwpP14kEDALpF x12Bfz44xsJuZqkI1OyiPlTEgq4tlQOjjNtWrzm0YEP3XfU/UbV5s6E9PVQ96Fvu iStvOb4zp/CIrHIVtmv+g== X-ME-Sender: X-ME-Received: X-ME-Proxy-Cause: dmFkZTFY6lH9UbikzGGF+9sTo8UnYKIW62Rg0AFuhhMRxe07csUQLwTQQfvo4sy375h/2V Zr/B98moAMOnyZQc0VbUs8/0nQgbxv8BFVIvKwhho5KTzQkAcyd0Vd3LLCSLohNBSMvv3f nNZzs+RUmFJ7N3+Jh74cJuWWmgOlbSSRIKuYu4y1cGYLGe8hfMD3YhSXQ9elcHbZpvhVwq CnVsURCx4qbz6b3Fevycl3cZxx/tUTnzwkeDlYUn+08SoZotEhtT3huicw7MBejLP2aKkV +4GdT2B09kBadJKQMqneWwJoWrlcm0YoXzzK/QlifjeAGuPHj1XuxvYzd+OYapojrw3aM/ impbtIrOeHO7V9UYoepEwwaCxGV8eOzH6Kr9GScXc/nOrYHbPuGzVablgEvXgENbxf9d10 M8rHu2w5zoCy+RDzSV1UMbCjHORcyQd2JrV6r9IJo9sFbS49mgqaGVatHvh9YHzmWtrz8b nm0Lp6yTFOcrUfPpna9YtGbr6AY3pep6HRNC/A9hTxL0LLVAZZJbrg2Ssu9yBCTyN/TmmR OrcSXvRuvprd2lY5FUdFyQCb8zdfIHCxPSufXA1+p9zU+CkP2l3DlQ/M6guzVIGZmTRRbE AZTbFMIwz36mzjRhtDE5Q0TsST9ntogrqMQBMbWu577QroximuQ9kKQGX+aQ X-ME-Proxy: Feedback-ID: i1d2843be:Fastmail Received: by mail.messagingengine.com (Postfix) with ESMTPA; Mon, 13 Jul 2026 11:44:42 -0400 (EDT) From: Griffin Kroah-Hartman Date: Mon, 13 Jul 2026 17:43:52 +0200 Subject: [PATCH 2/3] usb: core: strengthen size check in usb_parse_interface() Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260713-usb_core_patches_1-v1-2-7721c2b33f53@kroah.com> References: <20260713-usb_core_patches_1-v1-0-7721c2b33f53@kroah.com> In-Reply-To: <20260713-usb_core_patches_1-v1-0-7721c2b33f53@kroah.com> To: Greg Kroah-Hartman Cc: linux-usb@vger.kernel.org, linux-kernel@vger.kernel.org, Griffin Kroah-Hartman X-Mailer: b4 0.15.2 X-Developer-Signature: v=1; a=ed25519-sha256; t=1783957473; l=970; i=griffin@kroah.com; s=20260706; h=from:subject:message-id; bh=0VCccmYDWpK/oTYjIIoywXY3zSry1JDAoxEb1Xrp29A=; b=kPJ2Ng6ZnJQMtJFZ5XZ177tHZSOUlppTH+hFSm5z2vunV6Aim7MsiQSIYk8KR234Q4mSLaw9X BEnrSF5au1wCYGCy14Cqps/mAHsQWJrajxxDOkJPpyldq/f+/dCaOHl X-Developer-Key: i=griffin@kroah.com; a=ed25519; pk=Hy1TuVHERdQhLAWwjmxLFNtGj7eEEjaZWPXehAlic5M= Change the size check from size > 0 to size >=3D sizeof(struct usb_descriptor_header) in usb_parse_interface(). This prevents a malicious device from utilizing trailing bytes to incur an OOB read. This matches the size check in usb_parse_configuration() as well. Assisted-by: gkh_clanker_t1000 Signed-off-by: Griffin Kroah-Hartman --- drivers/usb/core/config.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/drivers/usb/core/config.c b/drivers/usb/core/config.c index 17c93e95945f..91a51cedc1b8 100644 --- a/drivers/usb/core/config.c +++ b/drivers/usb/core/config.c @@ -623,7 +623,7 @@ static int usb_parse_interface(struct device *ddev, int= cfgno, =20 /* Parse all the endpoint descriptors */ n =3D 0; - while (size > 0) { + while (size >=3D sizeof(struct usb_descriptor_header)) { if (((struct usb_descriptor_header *) buffer)->bDescriptorType =3D=3D USB_DT_INTERFACE) break; --=20 2.55.0 From nobody Sat Jul 25 21:24:07 2026 Received: from fout-a4-smtp.messagingengine.com (fout-a4-smtp.messagingengine.com [103.168.172.147]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 68F8F42E8FE; Mon, 13 Jul 2026 15:44:57 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=103.168.172.147 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1783957500; cv=none; b=GEmJBe+haKT4RGbU64tiZEIjfEi/EztMXrI8ODJWlAowAuCOyzVRQUz6ZzXyE/OnPlsqlK/bwuy+VKySu3q/khurhLry9/yrsLgKWVkhxJy+LO3XFMmrqvlwAnmVRHTt6hh5lw30friabAJt8j6Jr8dX9yF0Jc3SUYTbQWwgp2Q= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1783957500; c=relaxed/simple; bh=qiFAsQb8gUaGA1Sdt3fo6PE0mxhDQJ7KW2hdjuBePxw=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:References: In-Reply-To:To:Cc; b=YnNB++FmDH1TiPHHay4x657xnoIReoUSNs3MgnckDesnju1qkItb/VpU4o/PzpJ7G5ul2VxTDpvTMWkbAT3ppDn6tWgxti031KOPlrBq0r31wZ5Pelzik9E4nvEy9KZ1zYoqYQu8SIYmuC3L8fqYe9sdqqFN0LQ2EVMh9Ygfk3g= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=kroah.com; spf=pass smtp.mailfrom=kroah.com; dkim=pass (2048-bit key) header.d=kroah.com header.i=@kroah.com header.b=E7QLxJi5; dkim=pass (2048-bit key) header.d=messagingengine.com header.i=@messagingengine.com header.b=UuyjrOfp; arc=none smtp.client-ip=103.168.172.147 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=kroah.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=kroah.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kroah.com header.i=@kroah.com header.b="E7QLxJi5"; dkim=pass (2048-bit key) header.d=messagingengine.com header.i=@messagingengine.com header.b="UuyjrOfp" Received: from phl-compute-01.internal (phl-compute-01.internal [10.202.2.41]) by mailfout.phl.internal (Postfix) with ESMTP id 1F6F4EC009A; Mon, 13 Jul 2026 11:44:56 -0400 (EDT) Received: from phl-frontend-04 ([10.202.2.163]) by phl-compute-01.internal (MEProxy); Mon, 13 Jul 2026 11:44:56 -0400 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=kroah.com; h=cc :cc:content-transfer-encoding:content-type:content-type:date :date:from:from:in-reply-to:in-reply-to:message-id:mime-version :references:reply-to:subject:subject:to:to; s=fm2; t=1783957496; x=1784043896; bh=G5CDfNhUwyMB821dnYP3ZRG3UTDWP6nc/ymDxsJ0UUg=; b= E7QLxJi51BtGKoLmlbCT2ADd5yOD0bbDF4X2Ukn5lO++0w+/PW+nHSV6BLmQQsxb ieq9NywlQyUe++sp7s5gel4LP6IfGOudIW08y9/IHrTp+WlkHVUFFvpGCZ8HfUg2 Gevu5cJ1slHsYm8GBaJD2vnxMWfCez0VXGHcYaK39b6SE6zdVD6V1Fx6/4+4lgCL ysgswYn2VsRez0CzqtyyhN2ZIqzLHXSosmAbgRzpXrRKgLJAhM3eY1So1EZ6OH2g QYQMV8+7wHyra9Oo0Q0BBRj/T5WoNCwNksH3eTRe+ytMynB8T8TKAFMdZbI6CFWj MpgM+umir6nk8X+V9a71VA== DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d= messagingengine.com; h=cc:cc:content-transfer-encoding :content-type:content-type:date:date:feedback-id:feedback-id :from:from:in-reply-to:in-reply-to:message-id:mime-version :references:reply-to:subject:subject:to:to:x-me-proxy :x-me-sender:x-me-sender:x-sasl-enc; s=fm2; t=1783957496; x= 1784043896; bh=G5CDfNhUwyMB821dnYP3ZRG3UTDWP6nc/ymDxsJ0UUg=; b=U uyjrOfpZgbl6Mi2tn0PNARS+t9435M15lzMx8bObYgKAFeFIrZRh8sTyQyALNkrH 7kJxfzQPaeiQnZrYwZgGfSej0fb4c9v5R59Ewg8kVK99PFq1byEL1MfehwadXp7n du6Qb0LfWVQRNmwfvCB+ngK0uXkVhmmBApiYpuclrSv17yFMAQwfOfUG+b88z+oS puVXDYPblLPbz8sLpBoAT0VF92wfq3Ku4glkB1ibQTBkHmWJIeIr7ehoS1FS33PG lgzl4LsLCe0/BInQf2xyU6+kNCsG531Z3M0465rhB/UTwIi66Q/4BoxpK0H05Byg 0ghloBaynx8N9mqwsZy1A== X-ME-Sender: X-ME-Received: X-ME-Proxy-Cause: dmFkZTFY6lH9UbikzGGF+9sTo8UnYKIW62Rg0AFuhhMRxe07csUQLwTQQfvo4sy375h/2V Zr/B98moAMOnyZQc0VbUs8/0nQgbxv8BFVIvKwhho5KTzQkAcyd0Vd3LLCSLohNBSMvv3f nNZzs+RUmFJ7N3+Jh74cJuWWmgOlbSSRIKuYu4y1cGYLGe8hfMD3YhSXQ9elcHbZpvhVwq CnVsURCx4qbz6b3Fevycl3cZxx/tUTnzwkeDlYUn+08SoZotEhtT3huicw7MBejLP2aKkV +4GdT2B09kBadJKQMqneWwJoWrlcm0YoXzzK/QlifjeAGuPHj1XuxvYzd+OYapojrw3aZE Yk92ExmJdU9TnVX/xU+XqTSPKEZJFCKzvFXmkQ85O1Fu98cHuPizfutmvQ2g8zTQNx+BT9 Tvg6nMFvj5L9SBEFLl1zYDc5Np8iZaS3sjst2TsFVl7NXwXvHAXOVchzwWboXrArQjjcJW PALMjQT4fUeKoFjQ0BcE2pLsrRf2HRZMY3ZAvVy1g/w2d7deYwuJwvTNipOwpcRn0nNUh4 0NHV1fUMWy+F4GuZO5Q1x14jVE0orzadh2jAWbwgP219yEh/qrxGvRhZq4YqaZpGWPfqvy 4/xW/Xy0ZMLLmD9h1SpIBWQsH8kaGKrBzOykXYCnlrpGcBIyBaN26VMcPQmw X-ME-Proxy: Feedback-ID: i1d2843be:Fastmail Received: by mail.messagingengine.com (Postfix) with ESMTPA; Mon, 13 Jul 2026 11:44:48 -0400 (EDT) From: Griffin Kroah-Hartman Date: Mon, 13 Jul 2026 17:43:53 +0200 Subject: [PATCH 3/3] usb: core: Add lock to usb_wakeup_notification() Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260713-usb_core_patches_1-v1-3-7721c2b33f53@kroah.com> References: <20260713-usb_core_patches_1-v1-0-7721c2b33f53@kroah.com> In-Reply-To: <20260713-usb_core_patches_1-v1-0-7721c2b33f53@kroah.com> To: Greg Kroah-Hartman Cc: linux-usb@vger.kernel.org, linux-kernel@vger.kernel.org, Griffin Kroah-Hartman X-Mailer: b4 0.15.2 X-Developer-Signature: v=1; a=ed25519-sha256; t=1783957473; l=1227; i=griffin@kroah.com; s=20260706; h=from:subject:message-id; bh=qiFAsQb8gUaGA1Sdt3fo6PE0mxhDQJ7KW2hdjuBePxw=; b=EUIpRvo6ddcrVFUkKdVT0otwfPKE8FBG8o7WAllEED2DwI7kvHWC4nw0nkdctI8XGrwbNj7v5 e/fmFTP6VWBBG9dmia3DezVmlN0FfeUcC7fV/4Fc8R0gyMWHmAWkFlm X-Developer-Key: i=griffin@kroah.com; a=ed25519; pk=Hy1TuVHERdQhLAWwjmxLFNtGj7eEEjaZWPXehAlic5M= Add a spin lock to usb_wakeup notification to prevent a race condition with dereferencing freed memory. This could be hit by the xHCI driver as it calls this function from an IRQ and could race with the hub_disconnect() function, which properly grabs this lock to protect the state of the device. Assisted-by: gkh_clanker_t1000 Signed-off-by: Griffin Kroah-Hartman --- drivers/usb/core/hub.c | 3 +++ 1 file changed, 3 insertions(+) diff --git a/drivers/usb/core/hub.c b/drivers/usb/core/hub.c index 5262e11c12cd..5798efdd91a9 100644 --- a/drivers/usb/core/hub.c +++ b/drivers/usb/core/hub.c @@ -753,10 +753,12 @@ void usb_wakeup_notification(struct usb_device *hdev, { struct usb_hub *hub; struct usb_port *port_dev; + unsigned long flags; =20 if (!hdev) return; =20 + spin_lock_irqsave(&device_state_lock, flags); hub =3D usb_hub_to_struct_hub(hdev); if (hub) { port_dev =3D hub->ports[portnum - 1]; @@ -766,6 +768,7 @@ void usb_wakeup_notification(struct usb_device *hdev, set_bit(portnum, hub->wakeup_bits); kick_hub_wq(hub); } + spin_unlock_irqrestore(&device_state_lock, flags); } EXPORT_SYMBOL_GPL(usb_wakeup_notification); =20 --=20 2.55.0