[PATCH] usb: core: sysfs: add lock to bos_descriptors_read()

Griffin Kroah-Hartman posted 1 patch 1 week, 3 days ago
drivers/usb/core/sysfs.c | 8 +++++++-
1 file changed, 7 insertions(+), 1 deletion(-)
[PATCH] usb: core: sysfs: add lock to bos_descriptors_read()
Posted by Griffin Kroah-Hartman 1 week, 3 days ago
Add a lock to the function bos_descriptors_read().

This function accesses udev->bos, which could be simultaneously freed in
usb_reset_and_verify_device(), a function that is commonly called in
drivers all over the kernel.

Assisted-by: gkh_clanker_t1000
Signed-off-by: Griffin Kroah-Hartman <griffin@kroah.com>
---
 drivers/usb/core/sysfs.c | 8 +++++++-
 1 file changed, 7 insertions(+), 1 deletion(-)

diff --git a/drivers/usb/core/sysfs.c b/drivers/usb/core/sysfs.c
index a07866f1060c..d22dc78457d7 100644
--- a/drivers/usb/core/sysfs.c
+++ b/drivers/usb/core/sysfs.c
@@ -899,10 +899,15 @@ bos_descriptors_read(struct file *filp, struct kobject *kobj,
 {
 	struct device *dev = kobj_to_dev(kobj);
 	struct usb_device *udev = to_usb_device(dev);
-	struct usb_host_bos *bos = udev->bos;
+	struct usb_host_bos *bos;
 	struct usb_bos_descriptor *desc;
 	size_t desclen, n = 0;
+	int rc;
 
+	rc = usb_lock_device_interruptible(udev);
+	if (rc < 0)
+		return -EINTR;
+	bos = udev->bos;
 	if (bos) {
 		desc = bos->desc;
 		desclen = le16_to_cpu(desc->wTotalLength);
@@ -911,6 +916,7 @@ bos_descriptors_read(struct file *filp, struct kobject *kobj,
 			memcpy(buf, (void *) desc + off, n);
 		}
 	}
+	usb_unlock_device(udev);
 	return n;
 }
 static const BIN_ATTR_RO(bos_descriptors, 65535); /* max-size BOS */

---
base-commit: a13c140cc289c0b7b3770bce5b3ad42ab35074aa
change-id: 20260715-usb_core_patches_3-a4ce9f00d92b

Best regards,
--  
Griffin Kroah-Hartman <griffin@kroah.com>
Re: [PATCH] usb: core: sysfs: add lock to bos_descriptors_read()
Posted by Alan Stern 1 week, 3 days ago
On Wed, Jul 15, 2026 at 04:59:05PM +0200, Griffin Kroah-Hartman wrote:
> Add a lock to the function bos_descriptors_read().
> 
> This function accesses udev->bos, which could be simultaneously freed in
> usb_reset_and_verify_device(), a function that is commonly called in
> drivers all over the kernel.
> 
> Assisted-by: gkh_clanker_t1000
> Signed-off-by: Griffin Kroah-Hartman <griffin@kroah.com>
> ---

Acked-by: Alan Stern <stern@rowland.harvard.edu>

>  drivers/usb/core/sysfs.c | 8 +++++++-
>  1 file changed, 7 insertions(+), 1 deletion(-)
> 
> diff --git a/drivers/usb/core/sysfs.c b/drivers/usb/core/sysfs.c
> index a07866f1060c..d22dc78457d7 100644
> --- a/drivers/usb/core/sysfs.c
> +++ b/drivers/usb/core/sysfs.c
> @@ -899,10 +899,15 @@ bos_descriptors_read(struct file *filp, struct kobject *kobj,
>  {
>  	struct device *dev = kobj_to_dev(kobj);
>  	struct usb_device *udev = to_usb_device(dev);
> -	struct usb_host_bos *bos = udev->bos;
> +	struct usb_host_bos *bos;
>  	struct usb_bos_descriptor *desc;
>  	size_t desclen, n = 0;
> +	int rc;
>  
> +	rc = usb_lock_device_interruptible(udev);
> +	if (rc < 0)
> +		return -EINTR;
> +	bos = udev->bos;
>  	if (bos) {
>  		desc = bos->desc;
>  		desclen = le16_to_cpu(desc->wTotalLength);
> @@ -911,6 +916,7 @@ bos_descriptors_read(struct file *filp, struct kobject *kobj,
>  			memcpy(buf, (void *) desc + off, n);
>  		}
>  	}
> +	usb_unlock_device(udev);
>  	return n;
>  }
>  static const BIN_ATTR_RO(bos_descriptors, 65535); /* max-size BOS */
> 
> ---
> base-commit: a13c140cc289c0b7b3770bce5b3ad42ab35074aa
> change-id: 20260715-usb_core_patches_3-a4ce9f00d92b
> 
> Best regards,
> --  
> Griffin Kroah-Hartman <griffin@kroah.com>
> 
>