From nobody Fri Oct 2 11:42:16 2026 Received: from mail-wm1-f48.google.com (mail-wm1-f48.google.com [209.85.128.48]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 156483A641F for ; Sat, 1 Aug 2026 16:37:57 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.128.48 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785602279; cv=none; b=kDUbrS6dZnPvdQAgGlPFcByCrOQ+3codbsoKWlbQWu4Cet8IoQUgO60YTXzjmpJ+AcujRXFJKOITY7c71e4d2oKuRgnNU2pUKJFl7Fblynoorp2Pxsyl1XgYIhH1clTmOAxBlfGsxTWHm9pRKy7JkUOaE3phOdgEIBw8cDUCaRo= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785602279; c=relaxed/simple; bh=jBFcsgxdsHHBtuj6y0A4tNj7euZVpJzFOiPD+w8Y0Es=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=BO9i/YamNOq60K4TFXgbu83wp8cBVEjJYNlPz+ROItRd4eqAF7Z2h7mvSSSgsOXzXFxibEEa2gGtG0vDcONYHY33p00zlRy/76Lqq9iMbpVqFEy2WRPkYeeNooi/G0OgarLM/rk96zy1lWbcvwIy/j0ZYo8ARHi5oZ7uES+j+9A= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=rR1+xJJL; arc=none smtp.client-ip=209.85.128.48 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="rR1+xJJL" Received: by mail-wm1-f48.google.com with SMTP id 5b1f17b1804b1-490cf322ed0so4262195e9.1 for ; Sat, 01 Aug 2026 09:37:57 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1785602276; x=1786207076; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to:content-type; bh=/aOkOfzHfwCb8la8nV7ofbFSb+oxHno2SRX3scABeu0=; b=rR1+xJJLR9kcRNtuEL7URIj0cfazNz1hwGwr6Hy0WERF/7UmTJza1gj3nHgbBDylPh Jl7roZM7wD6wgltIrkL2tumn8z1AectR9HlJrj8MDPoA+Hwswn5tg+cT9HKrHAOTxhoK b49/upzwYduxnX8ysY7kQNGquwJhEHWlo+NDA2R7xhmNNG1JP5BteW5I1EagY1fwbIF3 qWhWeYo69gP8TtyBnF8fWer4xB4xqo5eD6IkPkcau20awx/qVtqZI2g96mvM0zgsFf4L T+NbA5SnrEuqIm4Hu9qEIEm4arC5qjgyy2PVlnt4pst3GO51cWOUnH1u63AD4LThCOwm YjEA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785602276; x=1786207076; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=/aOkOfzHfwCb8la8nV7ofbFSb+oxHno2SRX3scABeu0=; b=AukGbyuMj5/ZA9krvqIDd7dvhM6kbrwoJ6G9NFxK3MY9v6xCdZPl5FtuWui/9AFAbF JJVjV0/zbXzXiswprkR03pmpCFUEZxbrdAU+lTKsQAC2Xu4JIXJY56j8KQGXUzsjRR4Y uSkyXKduSJepS0kyFgAc6ExN+sxS/beNK8FQO6nFF/h6bPcxD+reGVVmZhPrrBQdEPNp P8W0nWaExys8MRgRrYqLORt9F86pQXcDBKRMmNmE0lgst6IVlPDL+A4LpopDwqU5x0B5 tIhSSDeBDkjcJo/7inRJI+Os9RUPPtJnSPnnJhvwiEbAhtuRXdWsb0nop7TErNwlesDO Gtew== X-Forwarded-Encrypted: i=1; AHgh+RrlQdWppLRAO1AuvsJJMLlaowRa7um06o7trG/aNbtbmWBAebUiJDcuEtbytWsZK541M9n1LBSS9sH7op0=@vger.kernel.org X-Gm-Message-State: AOJu0YxoGX7TdEHTPeFhBrpWLk5kdY8GNdpREP9Ciw1/aMStAZzXPpBG GxzAATSyL7cAaydsEZvUzZNCQe81fvVZhMG9AX7anLcXtvHc79hJ+CC2 X-Gm-Gg: AR+sD10bHASN8aah2LgBAbrXCRisU46VkIMegZ3P89i9nuNZsHim19SGUPNq7Iglp53 a61JHMxLcdmyyTfrvIlxkFpsCtR+RR4Nz1a/gi0RoHRCK1nZJ5SivO0eOkyvL7lRKdLqmoPmVfN uwI1+SFwo6zk+8VQWeNVJ3SFFEomuWviIOcgYHtL8VF59ZIvNHLomitxuI7uY0a175sBsjRB9GE qzuDsTR2+OVBxQabq9COEo/Ksg1+ksAeiCWldfwymDc8UBXdln3WhispH2PhzuO/whuq6sYs/zQ yyTxVHWrO8h/LnBNH+kMC6Hk0N0jpskNqTeHVmVJlamL5+O1vfY4jiAMYLHpIu3mBkBN65wE5Ob Mdsv86OP1rJIZnsDRMtjoqZPg1kqkJuhuPU2TZ0/OMy+XShNvidAEI8wni5MLGKhwuY/9ii7Ytb zMRyxdLG07PplkYPFxEWsSLwYoro489GDWoSx/Y0H0VLJkJx90EhjIyRUAezf2+nulil+M3E3HQ wXNzsRm28r9X+xzxBgZVeJrpiI1Z6cZUOc9zB1AzPph7C3gjiqrcRunL4J9aGhXM+tdhOiDkdi6 oQas/cwp12JE6H/HneceYasrLfVnoMyrLnCilCYReNin X-Received: by 2002:a05:600c:4e90:b0:495:7426:c392 with SMTP id 5b1f17b1804b1-4980eb4d5f9mr50698045e9.1.1785602276233; Sat, 01 Aug 2026 09:37:56 -0700 (PDT) Received: from riacini.speedport.ip (p200300fcd73d5b958d916a1d293e566c.dip0.t-ipconnect.de. [2003:fc:d73d:5b95:8d91:6a1d:293e:566c]) by smtp.gmail.com with ESMTPSA id 5b1f17b1804b1-49807b5f0adsm66461855e9.4.2026.08.01.09.37.55 (version=TLS1_3 cipher=TLS_CHACHA20_POLY1305_SHA256 bits=256/256); Sat, 01 Aug 2026 09:37:55 -0700 (PDT) From: Rituparna Warwatkar To: Greg Kroah-Hartman Cc: linux-usb@vger.kernel.org, linux-kernel@vger.kernel.org, Michael Grzeschik , Laurent Pinchart , Daniel Scally , Rituparna Warwatkar , syzbot+54927260acba030187a6@syzkaller.appspotmail.com Subject: [PATCH] usb: gadget: uvc: don't pack struct uvcg_extension_unit_descriptor Date: Sat, 1 Aug 2026 18:37:47 +0200 Message-ID: <20260801163747.82910-1-rwarwatkar@gmail.com> X-Mailer: git-send-email 2.50.1 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" kmemleak reports the baSourceID and bmControls arrays allocated by the UVC extension-unit configfs attributes as leaked, e.g.: BUG: memory leak unreferenced object 0xffff888114fee2c0 (size 8): __kmalloc_noprof uvcg_extension_ba_source_id_store configfs_write_iter vfs_write ksys_write The arrays are not actually leaked: they are reachable through xu->desc.baSourceID / xu->desc.bmControls and are freed when the extension unit is removed. The problem is that struct uvcg_extension_unit_descriptor is marked __packed, so these two heap pointers are stored at unaligned offsets (22 and 31). kmemleak only scans memory on pointer-aligned boundaries, so it never sees the pointers and reports the arrays as unreferenced. Unlike the UAPI struct uvc_extension_unit_descriptor, this is a purely in-memory staging structure: baSourceID and bmControls are pointers, not inline arrays, and the wire descriptor is assembled field by field in UVC_COPY_XU_DESCRIPTOR(). Nothing relies on the packed layout, so the __packed attribute is unnecessary and only serves to misalign the pointers. Drop __packed so the pointers are naturally aligned and visible to kmemleak, silencing the false positive. Fixes: 0525210c9840 ("usb: gadget: uvc: Allow definition of XUs in configfs= ") Reported-by: syzbot+54927260acba030187a6@syzkaller.appspotmail.com Closes: https://syzkaller.appspot.com/bug?extid=3D54927260acba030187a6 Signed-off-by: Rituparna Warwatkar --- drivers/usb/gadget/function/uvc_configfs.h | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/drivers/usb/gadget/function/uvc_configfs.h b/drivers/usb/gadge= t/function/uvc_configfs.h index 9391614135e..5a882afbce4 100644 --- a/drivers/usb/gadget/function/uvc_configfs.h +++ b/drivers/usb/gadget/function/uvc_configfs.h @@ -176,7 +176,7 @@ struct uvcg_extension_unit_descriptor { u8 bControlSize; u8 *bmControls; u8 iExtension; -} __packed; +}; struct uvcg_extension { struct config_item item; -- 2.47.3