From nobody Fri Oct 2 10:08:41 2026 Received: from mail-pl1-f181.google.com (mail-pl1-f181.google.com [209.85.214.181]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 049F43B8BDA for ; Sun, 2 Aug 2026 16:28:40 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.214.181 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785688122; cv=none; b=rwwrQp7zs4AxeWx18C71RaTQtimmUnCXlAPuk6LWbbQruvEx4TXh8HbHDtUce2g+VxVjXFbNDnbkilTtPoPa3anxWgzlVS/CzJwv9Hgn/shEdHsmiG946gMJHG1mIswExGAlrQeKyQE5hmcBr2vdvjHW9RmM8vX38mLl8H38/3o= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785688122; c=relaxed/simple; bh=Aa1C7XVP5D0lXpdtOpM1N5UmX0/npqGqHnpvdbQLwLs=; h=From:Date:Subject:MIME-Version:Content-Type:Message-Id:To:Cc; b=MJqmIANlmyzP62ol+fJbdBv4BiT6h24xS2HdwhHR7G/bbEYI5C5Wj6Dam1HSoysKB0FIpx3vzmDX9n4K/tBmwTFdmNq/8Bu6Obd5bvKuGjztRRwkqXGoV7ErF/c7BChaVL0/FM8QVUiNcpFFYTog3RleULwuM3VbUECsTqjKZkI= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=XoWIqNWW; arc=none smtp.client-ip=209.85.214.181 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="XoWIqNWW" Received: by mail-pl1-f181.google.com with SMTP id d9443c01a7336-2cfbbdfa60bso20186175ad.3 for ; Sun, 02 Aug 2026 09:28:40 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1785688120; x=1786292920; darn=vger.kernel.org; h=cc:to:message-id:content-transfer-encoding:content-type :mime-version:subject:date:from:from:to:cc:subject:date:message-id :reply-to:content-type; bh=7scSJm40+Y+XIQ6APOkt7PEg3eFGXlNbl1wv/V9PRHk=; b=XoWIqNWWAa6IF5Do72OjtzMHcsAJf9+qGaMAOLt/L11F6L/BLox5vXKRvksbkIm0de fSuV3LfRZKs7eXi4aUTFJiRRCoV49X+X6t8yPk7QmHODbfyLGETjGNSjztEkTLnMfhiH qYtY050ae/hKO6/KWkT39fpFadXgP7QeTZ4aT08KLevhSjUBcPza04Lf2qCuggumafOc 5RCkjVXXnlr9pjlTa0cYIHADarKnXSwHxI/xszr1xHFWsjYOzMWQMJSN10ALHuBJGtno xCsXn+D26gqUuIgatm1eSBl9G4swm5Cdcu0DIOssKhyx36pImCFLrKpVpn1ZzycQwceQ 5yBQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785688120; x=1786292920; h=cc:to:message-id:content-transfer-encoding:content-type :mime-version:subject:date:from:x-gm-gg:x-gm-message-state:from:to :cc:subject:date:message-id:reply-to:content-type; bh=7scSJm40+Y+XIQ6APOkt7PEg3eFGXlNbl1wv/V9PRHk=; b=T3IiDR7GRPs8ZbxftXTiP9GLZ7jkik4RfpplW7/5ibxTszLVoUHYwN9OxKdYqxZ1v6 srghJDGfSU2v2eyAOkk+Jz3/IdgZp6gG11wCRc7YuilaCEck3PbNyl2rbCwAps2EXg0e ibkWsq6Za0y5iTPJTuOBlupj0sRHT3Eee6i7MuGmY9SMQOllyb8LIQjSTS3OaNuG9DGb Lt5OZAgPYlpWu8QcSiofi4kEe5fkxZvWX3w9Td4SkI24owKecyeUw2Vs+Aveyvitu4sV NnoIlvFNir+8HfBFoz8iNE7H70waDYStG4wxev269OB/gkw9rfweZFvqYszsHmfiJwjb GKoQ== X-Forwarded-Encrypted: i=1; AHgh+RqmsVjIqr0aNkXSSa/k4bJLWovz6JdyiZ8gucTTOKzGYeTXLWaU6J63i9s1BetQAaySdKDZpQIvwA4K/J4=@vger.kernel.org X-Gm-Message-State: AOJu0YyKNi9XxECJyXwFLTwhMTiXJQWJXdBdd0jRUckitqotT0nLK52y U1ITheKBc8K1mgjG7YijYwY1q4704eZUNEb9Olst1pvSndAFZSlLC0UW X-Gm-Gg: AR+sD11Js4m+ZuS5txlde2ekIzrElBBqpuwjFlXqSz4zcBUc+sNCaP/qUjISFnIudRR mFNT9fO4epy4OV/+/X60HTCAmKwunyQmhCGCzNAmgLH+kicH3ogfJ85qc/p1EPVNRBTE3YrD4ZM Cw23lQvt9r2z7qD6iyE5J+w9Rxod5iwoKXX9L0jCXL1I0xgl+fE8wcXFCtqDAIXAD6mdHef92JJ EdO5j0w5Xt/jwIhkxOCr6urN1nieJzrCmbNQhLwiY8w2N4TLWIpxJr7ptms5EygTA1zGjpgcclQ FZb6MYu895ND5hnaLaG0QHWzez2fgVxN252r/gEyVvUUV1oBVog8CjKL9QIHeg2QR+/JgSIzAMC C/5Tb7ZODVoSHIsfjBGPFmc4P4KuMJRjIuum4eN6yVBm9Y5en8J0SLEDQh77It6o/j7OElTafzE ibewzUav6szzkF+VdQ2dAubBwK6RiIJHfZ0XAybVIDIiW4AazpxhTMJi4umZ6JiTw= X-Received: by 2002:a17:903:390c:b0:2ca:ce92:6e44 with SMTP id d9443c01a7336-2d05218984fmr68365745ad.8.1785688120180; Sun, 02 Aug 2026 09:28:40 -0700 (PDT) Received: from [127.0.1.1] ([2404:f801:8028:3:b43c:4b21:e8d4:b1b4]) by smtp.gmail.com with ESMTPSA id 5a478bee46e88-3153ddda5d9sm34668604eec.13.2026.08.02.09.28.37 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 02 Aug 2026 09:28:39 -0700 (PDT) From: Subasri S Date: Sun, 02 Aug 2026 21:58:34 +0530 Subject: [PATCH] usb: gadget: f_uac1/f_uac2: fix invalid-free and memory leak in sampling rate store Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Message-Id: <20260802-usb-f_uac1-v1-1-2c85fb0597e0@gmail.com> X-B4-Tracking: v=1; b=H4sIADFwb2oC/6tWKk4tykwtVrJSqFYqSi3LLM7MzwNyDHUUlJIzE vPSU3UzU4B8JSMDIzMDCwMj3dLiJN20+NLEZEPdtMSklBTjVDMLi6QUJaCGgqLUtMwKsGHRsbW 1AEfZ8DpcAAAA To: Greg Kroah-Hartman , Julian Scheel , Pavel Hofman Cc: linux-usb@vger.kernel.org, linux-kernel@vger.kernel.org, syzbot+2532c7901f590afd0c3a@syzkaller.appspotmail.com, Subasri S X-Mailer: b4 0.13.0 X-Developer-Signature: v=1; a=ed25519-sha256; t=1785688117; l=3948; i=subasris1210@gmail.com; s=20260709; h=from:subject:message-id; bh=Aa1C7XVP5D0lXpdtOpM1N5UmX0/npqGqHnpvdbQLwLs=; b=YWc4X9Zgd+NxD4giR1uKSIm9+wnIctaLp6/lMeu2Zndny/1Q+LdLXx/ro42OF2XpPmA+N2V9G 4Jct0vG/VzTDIcv6ktIRGg/30koJhCeKGmX/6bne+TN3hE66EU7f7BR X-Developer-Key: i=subasris1210@gmail.com; a=ed25519; pk=6C4wavGFy/OsR8yQQKNWuDXoYPHp2L3sfgNfyzTruTk= strsep() modifies the pointer passed to it, advancing it past each delimiter. In f_uac1.c, in the UAC1_RATE_ATTRIBUTE macro, it advances the 'split_page' pointer past the "," between the sampling rates. This causes two bugs: On the error path: if kstrtou32() fails while parsing (possibly due to a garbage value passed to it), the goto jumps to 'end' where kfree() is called on 'split_page', which now points into the middle of the 'split_page' pointer instead of its start, causing an invalid-free. On the success path: when strsep() exhausts the string it sets 'split_page' to NULL, so the kfree() at 'end' becomes a no-op, silently leaking the kstrdup allocation on every successful write. Save the return value of kstrdup into 'dup_page' before the strsep loop and always free that instead. This fixes both the invalid-free on the error path and the memory leak on the success path. Apply the same fix to the identical UAC2_RATE_ATTRIBUTE macro in f_uac2.c. Reported-by: syzbot+2532c7901f590afd0c3a@syzkaller.appspotmail.com Closes: https://syzkaller.appspot.com/bug?extid=3D2532c7901f590afd0c3a Tested-by: syzbot+2532c7901f590afd0c3a@syzkaller.appspotmail.com Fixes: 695d39ffc2b5 ("usb: gadget: f_uac1: Support multiple sampling rates") Signed-off-by: Subasri S --- drivers/usb/gadget/function/f_uac1.c | 4 +++- drivers/usb/gadget/function/f_uac2.c | 4 +++- 2 files changed, 6 insertions(+), 2 deletions(-) diff --git a/drivers/usb/gadget/function/f_uac1.c b/drivers/usb/gadget/func= tion/f_uac1.c index 85c502e98f57..07c33dbce3be 100644 --- a/drivers/usb/gadget/function/f_uac1.c +++ b/drivers/usb/gadget/function/f_uac1.c @@ -1595,6 +1595,7 @@ static ssize_t f_uac1_opts_##name##_store(struct conf= ig_item *item, \ { \ struct f_uac1_opts *opts =3D to_f_uac1_opts(item); \ char *split_page =3D NULL; \ + char *dup_page =3D NULL; \ int ret =3D -EINVAL; \ char *token; \ u32 num; \ @@ -1609,6 +1610,7 @@ static ssize_t f_uac1_opts_##name##_store(struct conf= ig_item *item, \ i =3D 0; \ memset(opts->name##s, 0x00, sizeof(opts->name##s)); \ split_page =3D kstrdup(page, GFP_KERNEL); \ + dup_page =3D split_page; \ while ((token =3D strsep(&split_page, ",")) !=3D NULL) { \ ret =3D kstrtou32(token, 0, &num); \ if (ret) \ @@ -1619,7 +1621,7 @@ static ssize_t f_uac1_opts_##name##_store(struct conf= ig_item *item, \ }; \ \ end: \ - kfree(split_page); \ + kfree(dup_page); \ mutex_unlock(&opts->lock); \ return ret; \ } \ diff --git a/drivers/usb/gadget/function/f_uac2.c b/drivers/usb/gadget/func= tion/f_uac2.c index 897787d0803c..2292c72f3843 100644 --- a/drivers/usb/gadget/function/f_uac2.c +++ b/drivers/usb/gadget/function/f_uac2.c @@ -2013,6 +2013,7 @@ static ssize_t f_uac2_opts_##name##_store(struct conf= ig_item *item, \ { \ struct f_uac2_opts *opts =3D to_f_uac2_opts(item); \ char *split_page =3D NULL; \ + char *dup_page =3D NULL; \ int ret =3D -EINVAL; \ char *token; \ u32 num; \ @@ -2027,6 +2028,7 @@ static ssize_t f_uac2_opts_##name##_store(struct conf= ig_item *item, \ i =3D 0; \ memset(opts->name##s, 0x00, sizeof(opts->name##s)); \ split_page =3D kstrdup(page, GFP_KERNEL); \ + dup_page =3D split_page; \ while ((token =3D strsep(&split_page, ",")) !=3D NULL) { \ ret =3D kstrtou32(token, 0, &num); \ if (ret) \ @@ -2037,7 +2039,7 @@ static ssize_t f_uac2_opts_##name##_store(struct conf= ig_item *item, \ }; \ \ end: \ - kfree(split_page); \ + kfree(dup_page); \ mutex_unlock(&opts->lock); \ return ret; \ } \ --- base-commit: f5098b6bae761e346ebcd9da7f95622c04733cff change-id: 20260802-usb-f_uac1-fabdd3e688bd Best regards, --=20 Subasri S