[PATCH] net/9p/usbg: clear stale request context after abort

Qi Zhang posted 1 patch 2 months ago
net/9p/trans_usbg.c | 1 +
1 file changed, 1 insertion(+)
[PATCH] net/9p/usbg: clear stale request context after abort
Posted by Qi Zhang 2 months ago
From: Chengfeng Ye <nicoyip.dev@gmail.com>

usb9pfs_clear_tx() serializes access to the active TX request with
usb9pfs->lock, but leaves in_req->context pointing at the request after
p9_client_cb() drops the transport reference.  A later teardown path can
therefore retrieve the same request after it has been freed:

  CPU 0 (p9_usbg_close)        CPU 1 (usb9pfs_disable)
  lock(usb9pfs->lock)
  req = in_req->context
  p9_client_cb(client, req)
    p9_req_put(client, req)
  unlock(usb9pfs->lock)
  request reaches zero refs
    kmem_cache_free(req)
                                lock(usb9pfs->lock)
                                req = in_req->context
                                read req->t_err

The lock orders the two callbacks, but cannot protect a pointer that
remains published after its reference has been released.  KASAN reported:

  BUG: KASAN: slab-use-after-free in usb9pfs_clear_tx+0x166/0x1b0
  Read of size 4 at addr ffff88810e7420f4 by task poc/94
  Call Trace:
   usb9pfs_clear_tx+0x166/0x1b0
   usb9pfs_disable+0x1d/0x30
   reset_config+0x9d/0x200
   __composite_disconnect+0xa7/0x140
  Allocated by task 93:
   kmem_cache_alloc_noprof+0x141/0x370
   p9_tag_alloc+0x8f/0x5b0
   p9_client_prepare_req+0xff/0x350
   p9_client_rpc+0x1a5/0xac0
  Freed by task 0:
   slab_free_after_rcu_debug+0xa6/0x1e0
   rcu_core+0x50a/0x1850
  Last potentially related work creation:
   kmem_cache_free+0x1db/0x3d0
   p9_req_put+0x164/0x1f0
   usb9pfs_clear_tx+0x120/0x1b0
   p9_usbg_close+0x7e/0x150

Clear in_req->context after the callback while still holding the lock.
This matches the consume-and-clear pattern in usb9pfs_tx_complete(), so
subsequent teardown calls return without touching the released request.
The existing callback and error ordering remain unchanged.

Fixes: a3be076dc174 ("net/9p/usbg: Add new usb gadget function transport")
Cc: stable@vger.kernel.org
Signed-off-by: Chengfeng Ye <nicoyip.dev@gmail.com>
Signed-off-by: Qi Zhang <marsy12010123@gmail.com>
---
 net/9p/trans_usbg.c | 1 +
 1 file changed, 1 insertion(+)

diff --git a/net/9p/trans_usbg.c b/net/9p/trans_usbg.c
index 419cda13a7b5..9a83dff6f3dd 100644
--- a/net/9p/trans_usbg.c
+++ b/net/9p/trans_usbg.c
@@ -439,6 +439,7 @@ static void usb9pfs_clear_tx(struct f_usb9pfs *usb9pfs)
 		req->t_err = -ECONNRESET;
 
 	p9_client_cb(usb9pfs->client, req, REQ_STATUS_ERROR);
+	usb9pfs->in_req->context = NULL;
 }
 
 static void p9_usbg_close(struct p9_client *client)
-- 
2.43.0
Re: [PATCH] net/9p/usbg: clear stale request context after abort
Posted by Michael Grzeschik 2 weeks, 3 days ago
On Sun, Aug 02, 2026 at 11:21:48PM +0800, Qi Zhang wrote:
> From: Chengfeng Ye <nicoyip.dev@gmail.com>
> 
> usb9pfs_clear_tx() serializes access to the active TX request with
> usb9pfs->lock, but leaves in_req->context pointing at the request after
> p9_client_cb() drops the transport reference.  A later teardown path can
> therefore retrieve the same request after it has been freed:
> 
>   CPU 0 (p9_usbg_close)        CPU 1 (usb9pfs_disable)
>   lock(usb9pfs->lock)
>   req = in_req->context
>   p9_client_cb(client, req)
>     p9_req_put(client, req)
>   unlock(usb9pfs->lock)
>   request reaches zero refs
>     kmem_cache_free(req)
>                                 lock(usb9pfs->lock)
>                                 req = in_req->context
>                                 read req->t_err
> 
> The lock orders the two callbacks, but cannot protect a pointer that
> remains published after its reference has been released.  KASAN reported:
> 
>   BUG: KASAN: slab-use-after-free in usb9pfs_clear_tx+0x166/0x1b0
>   Read of size 4 at addr ffff88810e7420f4 by task poc/94
>   Call Trace:
>    usb9pfs_clear_tx+0x166/0x1b0
>    usb9pfs_disable+0x1d/0x30
>    reset_config+0x9d/0x200
>    __composite_disconnect+0xa7/0x140
>   Allocated by task 93:
>    kmem_cache_alloc_noprof+0x141/0x370
>    p9_tag_alloc+0x8f/0x5b0
>    p9_client_prepare_req+0xff/0x350
>    p9_client_rpc+0x1a5/0xac0
>   Freed by task 0:
>    slab_free_after_rcu_debug+0xa6/0x1e0
>    rcu_core+0x50a/0x1850
>   Last potentially related work creation:
>    kmem_cache_free+0x1db/0x3d0
>    p9_req_put+0x164/0x1f0
>    usb9pfs_clear_tx+0x120/0x1b0
>    p9_usbg_close+0x7e/0x150
> 
> Clear in_req->context after the callback while still holding the lock.
> This matches the consume-and-clear pattern in usb9pfs_tx_complete(), so
> subsequent teardown calls return without touching the released request.
> The existing callback and error ordering remain unchanged.
> 
> Fixes: a3be076dc174 ("net/9p/usbg: Add new usb gadget function transport")
> Cc: stable@vger.kernel.org
> Signed-off-by: Chengfeng Ye <nicoyip.dev@gmail.com>
> Signed-off-by: Qi Zhang <marsy12010123@gmail.com>

Acked-by: Michael Grzeschik <mgr@kernel.org>

> ---
>  net/9p/trans_usbg.c | 1 +
>  1 file changed, 1 insertion(+)
> 
> diff --git a/net/9p/trans_usbg.c b/net/9p/trans_usbg.c
> index 419cda13a7b5..9a83dff6f3dd 100644
> --- a/net/9p/trans_usbg.c
> +++ b/net/9p/trans_usbg.c
> @@ -439,6 +439,7 @@ static void usb9pfs_clear_tx(struct f_usb9pfs *usb9pfs)
>  		req->t_err = -ECONNRESET;
>  
>  	p9_client_cb(usb9pfs->client, req, REQ_STATUS_ERROR);
> +	usb9pfs->in_req->context = NULL;
>  }
>  
>  static void p9_usbg_close(struct p9_client *client)
> -- 
> 2.43.0
>