From nobody Fri Oct 2 11:42:16 2026 Received: from mail-wr1-f42.google.com (mail-wr1-f42.google.com [209.85.221.42]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 93BAD2192F4 for ; Sun, 2 Aug 2026 00:58:19 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.221.42 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785632301; cv=none; b=PfexMFXJygtzR5aaAPibIGixdvs/MhICr0TBsqbb8xuHKCn+akR7t+LKwM3hE4pJ8ZTFrfqeQSFWbCd0vu++XFiykIazZx8G4kHqS3frKgaLMnibIVLn8iNiQb94mbn0KevFQfS0vry0vrIqOtGyG4OZHJhedf7G4/LQFwmWGeA= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785632301; c=relaxed/simple; bh=QZaiviFXIpFOU6xrt4pohFGuFmFnFNWk4lMFpZyHZPg=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=jyTnrwFJIo8/LCWOCBwLy2lrlpOzspcgz6jbWFWyOO2rSvARhWbrq44HRxjKgpsRiE7T6YEdVJY0jkTVRBz4ic7G858f6URV/DygZT/Ay8fLH/9g9fQcUNkT3OeoIXt5NscMPlgRJoocq1Glp2r2mOKI5S1vSpPYwIvyoDnMN8Y= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=FziIgDtu; arc=none smtp.client-ip=209.85.221.42 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="FziIgDtu" Received: by mail-wr1-f42.google.com with SMTP id ffacd0b85a97d-47fdcdfceb6so231297f8f.3 for ; Sat, 01 Aug 2026 17:58:19 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1785632298; x=1786237098; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to:content-type; bh=5getTzD0IVo0TFYhF1w5tTOZvncb1cQf4iioeWqGs5Y=; b=FziIgDtuq3XFdWR18OLLqec+JY0ah6ECy77AXLIDAXXnB/KDFkr0MwQjPcWTZ7rf7S 4N50adPc4zdXtqvUMIPr599z4bE4kSGZBF2TJ1tFtJYUJF6IH4f1+iH7ZTNJjXu9uZAP 5HAu6opkxrVHtIXSTHaOUzX0/NtsWdYtazkKsjzed/hAO+IF3SL2sG1ySjeqUkp22yrh 0b9ENbgdvoOsGIzlH3EpHZ+JCMEVKud7P3+3r3qN6rlhWOYXzh/eJ26HMvEGIAJs/Zs8 +PKAKHI0NfqwnXUg4PxxJX4f2/2QsPLvIfkf5dyu7AafPlp6uZILwXk2KbIcKPlSPG3n T0qw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785632298; x=1786237098; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=5getTzD0IVo0TFYhF1w5tTOZvncb1cQf4iioeWqGs5Y=; b=Oe0mqIMiPFNdZF/tPatj7mDPSY3Nd4VjOewTtMVu6wKT1aznXFt0rJaDjasjTw2fpG 6BjdV44q6DJb+7GFH9I1vQqcRruOozhqaa1s2seoetQikjk1z5ZTRinB0Xm/PVVAObB7 h8cJHC9Gow+uodn57nZwoKvgm70Qcjq4I3BSCNCOINdKr85BmEYaSBAySPG86YG76LQj hCLyoMsuFbR2OK008l7V6PNIqAfTVhhmsVvC/7tGf3mB6siqSS1BnOjB2qegU3vUnntS 3NkfvFMdMPhQwVy87pz6Je3wHnQiSVwA9s3s6zihHx5LvKZ5v0n17KTab3PiKOzzo5oQ FvNg== X-Forwarded-Encrypted: i=1; AHgh+Rom2SRtPXUIgVIjCxeySKTzB6BLH7pmDI1BK7PNLWwe0xOgXxrE4y2XsskdWAMmHFdgz4poYIDkxGCC3QM=@vger.kernel.org X-Gm-Message-State: AOJu0Yz50BLTIPjzKVawaLsca4Dt3xRk2U3a15PHasbU+9n+cQkpQmRK +XNH1ldF8qqE/ohrCJnNiCE+cxh2Yi6Wj+bMlHEOF2P3xVaiqTamPvCu X-Gm-Gg: AR+sD11BzZX31I3Ckj5BN04li1DAisD2de4L53yfz9lQFcJOOCma8yvyRqZi4HRnnDn MmY8VXLYuP6KQKJfMB++3SblUHr6j+VfaTUYNW3y1mQFtWnUKjuFodLTyh28L7sae++YJ7uvrxk XWAmweepH4ehrEL6xtj34661tbWa0bm2YDMEYNLhBB1Bsgo34Ghp3VGkkMfbEvJpwQ/tx/syhA5 x8Qk2+UNh+DLbi9jMBrmDT8eFRhABYo7YtoOooKJ6D90cL1Z9U3yFMcloFAZend/T1apD6Srdiw nP6sUHxN60q9s5YZ3317oM2QfKLhJ01CuhbGM6mLea0FbO/LLUSNK4+tW8cHrn6kw8lbB/wQEg6 Fk4LlOZ8xSLhud3Yjl0oNen1m2wR1Oi3MWUj5ctBfwy2qVQbEKPORSZknGe6EOL03Jf6mBvGCpx l8ZogETR5Cg059Xpq/m7SzY5iR46w05Qw7ALzmX+6mlXXJNDUNZCVoo6I3GVkkojYLK/0Yg6qFG 0pkgPDspyqjTqQcv97w03qTHrxiYKrf4fFaLp2TVnsVEnVnA7nsQKazYY7b3w4La04atfgVPqfA r7EPSGSurS3FYxK1lxC28lRM0z2xpYn087OaqFpIMbj0 X-Received: by 2002:adf:e90f:0:b0:47f:9d0e:f8f with SMTP id ffacd0b85a97d-47fd72e6079mr9559836f8f.26.1785632297667; Sat, 01 Aug 2026 17:58:17 -0700 (PDT) Received: from riacini.speedport.ip (p200300fcd73d5b95e8f13abce6faaab2.dip0.t-ipconnect.de. [2003:fc:d73d:5b95:e8f1:3abc:e6fa:aab2]) by smtp.gmail.com with ESMTPSA id ffacd0b85a97d-47fd41d1a58sm19700843f8f.7.2026.08.01.17.58.15 (version=TLS1_3 cipher=TLS_CHACHA20_POLY1305_SHA256 bits=256/256); Sat, 01 Aug 2026 17:58:16 -0700 (PDT) From: Rituparna Warwatkar To: Greg Kroah-Hartman Cc: linux-usb@vger.kernel.org, linux-kernel@vger.kernel.org, Rituparna Warwatkar , syzbot+ebd045a6645cfb713c95@syzkaller.appspotmail.com Subject: [PATCH] usb: gadget: f_uac2: fix memory leak in sample rate store Date: Sun, 2 Aug 2026 02:58:10 +0200 Message-ID: <20260802005810.92953-1-rwarwatkar@gmail.com> X-Mailer: git-send-email 2.50.1 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" f_uac2_opts_{p,c}_srate_store() duplicate the input page with kstrdup() and then tokenize it with strsep(&split_page, ","). strsep() advances the pointer it is given, so by the time the parsing loop finishes split_page points at the end of the string (or NULL). The subsequent kfree(split_page) therefore frees the wrong pointer (NULL when the whole buffer was consumed), leaking the buffer allocated by kstrdup(): BUG: memory leak unreferenced object 0xffff888112a01e00 (size 64): kstrdup f_uac2_opts_c_srate_store configfs_write_iter vfs_write ksys_write Keep the original allocation in split_page and hand a separate iterator to strsep(), so the buffer is always freed. While at it, handle a kstrdup() failure instead of dereferencing NULL. Both the p_srate and c_srate attributes use the same macro and are fixed together. Fixes: a7339e4f5788 ("usb: gadget: f_uac2: Support multiple sampling rates") Reported-by: syzbot+ebd045a6645cfb713c95@syzkaller.appspotmail.com Closes: https://syzkaller.appspot.com/bug?extid=3Debd045a6645cfb713c95 Signed-off-by: Rituparna Warwatkar --- drivers/usb/gadget/function/f_uac2.c | 8 +++++++- 1 file changed, 7 insertions(+), 1 deletion(-) diff --git a/drivers/usb/gadget/function/f_uac2.c b/drivers/usb/gadget/func= tion/f_uac2.c index 897787d0803..8facf289710 100644 --- a/drivers/usb/gadget/function/f_uac2.c +++ b/drivers/usb/gadget/function/f_uac2.c @@ -2013,6 +2013,7 @@ static ssize_t f_uac2_opts_##name##_store(struct conf= ig_item *item, \ { \ struct f_uac2_opts *opts =3D to_f_uac2_opts(item); \ char *split_page =3D NULL; \ + char *rest; \ int ret =3D -EINVAL; \ char *token; \ u32 num; \ @@ -2027,7 +2028,12 @@ static ssize_t f_uac2_opts_##name##_store(struct con= fig_item *item, \ i =3D 0; \ memset(opts->name##s, 0x00, sizeof(opts->name##s)); \ split_page =3D kstrdup(page, GFP_KERNEL); \ - while ((token =3D strsep(&split_page, ",")) !=3D NULL) { = \ + if (!split_page) { \ + ret =3D -ENOMEM; \ + goto end; \ + } \ + rest =3D split_page; \ + while ((token =3D strsep(&rest, ",")) !=3D NULL) { = \ ret =3D kstrtou32(token, 0, &num); \ if (ret) \ goto end; \ -- 2.47.3