From nobody Fri Oct 2 09:22:05 2026 Received: from mail-pg1-f174.google.com (mail-pg1-f174.google.com [209.85.215.174]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 5DAF337AA65 for ; Mon, 3 Aug 2026 10:17:22 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.215.174 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785752243; cv=none; b=PKjsSYZk7SXAYFOto3rQVa0QLSnfaffhcx0YUXsCnPZfqB9Qf5YlVk6Y4lbeaGT5dkyh+Qi+h1PJSB76T/J3Ex/rrs8gmG4YdkWLntX1HtfhX6gpnurGRYpz4T4vcDLow9nCRa0Wnd7UKLx/AgPvhVmbahgU2xUr/ZMLfmEyqqQ= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785752243; c=relaxed/simple; bh=N8lr4PhpdwnLHM3UOch1jueU2anoDcJwMvyA9m3ih0U=; h=From:To:Cc:Subject:Date:Message-Id:MIME-Version; b=WIOScZ5faVdH0+q5lt3WdPU7t6BCHvW+AjjPt70tNRGKMtqvisLMDskToDOmJZeS6Kb27k+c7mPjc3HACpYpBzVjL+j1XqIItkXqO0zAj3fu3xQ64YfRlD/EPGCuKSexrCc7w2rRfDBSUChVJqX/yskWE4qqoyr1Hq2f4dnLM0o= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=KGyWlkD5; arc=none smtp.client-ip=209.85.215.174 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="KGyWlkD5" Received: by mail-pg1-f174.google.com with SMTP id 41be03b00d2f7-c9e0b89e228so1607974a12.1 for ; Mon, 03 Aug 2026 03:17:22 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1785752242; x=1786357042; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to:content-type; bh=hthDC2Kbdeq2qaz2x8s8OZb7AI2FDOI03M6IYBfIxS4=; b=KGyWlkD5K7I0xP5xY5TghinBA4RuMhbLOhloQzQPvW4dhoDU1URe9fs1iHLTIjmzyz kgzCvKZm2uJuI3ABYBPyCl+L1Zix6YSNIj9Fgu+85Rb/1pZYORuV27B5nyGk/rFetJnh 3mZKMR+fSxebcl1NFNY+yWN1mJgC29oaTwLyNG/O287xFzVUpJ06EdhMxekYHInlBWAG vPDN7YlYEn8SfUMcATrd8Vf/31uegg4tNV0dN6IbEJfn4I4W71Ak9sR64fNScuKzEnHp fdZVe6B/+spnTly6Gi+iEBW9OzqcdXtkIvqPZor+kWzWw0AhsaxRWhGXyukPCd9JfWJ2 4eHw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785752242; x=1786357042; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=hthDC2Kbdeq2qaz2x8s8OZb7AI2FDOI03M6IYBfIxS4=; b=TCSZ2yD2yIbI6lFiPyXYrpY4hHApg2P3DwXuSkCG04BsJJfSc+yiB1JdQ+Z+ZSrnqN dYraTVwcJL2g2KdWKJhEsSZbDpWotVpqdYt+9V8yjsuTGIG1ds8Ttc8l03JTWZ0PbRVa EmPXBc+T1foPKQ/q87I0+cm11fieC0L2i2itoK5pl6jaj3g88AKitVKoHAv9G39lT+bt uvBhoIlxPGPZ/KtX4jy349HN0bwDVV0LQcbxk5IU0BsYeWYgs3pAvkM0MxQc5dpIJw5J t7VVF+jqZJPOvwF64nVq6bi3lTpxn2Tqb055iPhpZ4xOV+PwnTDEoOaRO5YC/n7gpUrY sxpw== X-Forwarded-Encrypted: i=1; AHgh+Rps+fItSaXNStU6FuHZ5yGQhnwfLTn3LVeCCACFzfAfGvL7XDOABh6UzSQYxwl9RTK9iKeo7Ln8KVvo8fk=@vger.kernel.org X-Gm-Message-State: AOJu0Yw5+xXziU71ZlSxzSH5oCiHwYXPyXRujVrkyW0712dZO1+URiC5 5EzZe/u1fYp/LmitOtcu6kcwvaWAzicuEdBHI+iywSWFUu6wNcS0iLXv8L6Yz1af2No= X-Gm-Gg: AR+sD10+bFM7w5fmDdYkHLRtxEnGrsQ0vpZ/fSJroVP8VjooE06jTj1rhtyrI6whF3N sCEViJq/9d3Pg/ZXDtMnCXECFGxI+0AkXB3pligyrFPsVFB+46LHEnNd99Rd5MFJ0pG6l/A2bxN nRe/EJcCVu0/oGWie6BYH1OJQq9HaCKFDYRWZKgOTiUPqANX3lDuOE4ByVougImPWrI1AqAgnQY 8n/aIXS+ZI5b7d8vjwp99AbbxX/W5/+ZsRa8dhktimwly/UxuSojb3h1HJprvVFhPtoP4YdsGt1 oSpQd4F2OHh3qYqsh67JaPj3PAqpQt8aC6TvYEjN3eFyCGatP2QQa1XYg4II5SBESLGrYfwtBCN pldvqrQBUR1GD/sok9RWKkabCQNMwyJ1TbOL0zfk/gmRioVdCQPmTEnMb9fyEQKqxTUpTqAK6vo wwW8pgNeU3do3/ou9JyZeJ97hcfNHPGZ3ocX72TRsGdZ/8JqYmk1oO4wds48nyCwF9SLvrfB015 G8wf//bsOqwvw== X-Received: by 2002:a05:6a21:1fc3:b0:3c3:90de:60e2 with SMTP id adf61e73a8af0-3c92a951846mr8695669637.65.1785752241763; Mon, 03 Aug 2026 03:17:21 -0700 (PDT) Received: from ML-GYSUBT565.ECARX.COM.CN ([101.47.164.95]) by smtp.gmail.com with ESMTPSA id a92af1059eb24-13fab132cc4sm29359598c88.2.2026.08.03.03.17.19 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 03 Aug 2026 03:17:21 -0700 (PDT) From: Nguyen Quang Le Kien To: 3chas3@gmail.com Cc: gregkh@linuxfoundation.org, linux-usb@vger.kernel.org, linux-kernel@vger.kernel.org, netdev@vger.kernel.org, linux-atm-general@lists.sourceforge.net, accessrunner-general@lists.sourceforge.net, Nguyen Quang Le Kien , syzbot+24eb38c789655fc43663@syzkaller.appspotmail.com Subject: [PATCH] usb: atm: cxacru: fix use-after-free in cxacru_poll_status Date: Mon, 3 Aug 2026 18:17:16 +0800 Message-Id: <20260803101716.2592486-1-khiemtranzo532001@gmail.com> X-Mailer: git-send-email 2.34.1 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" In cxacru_unbind(), cancel_delayed_work_sync() was conditionally skipped when poll_state was CXPOLL_STOPPED. However, a work item previously scheduled when poll_state was CXPOLL_POLLING may still be pending in the workqueue at the time poll_state transitions to CXPOLL_STOPPED. Skipping cancel_delayed_work_sync() in this case allows the work to fire after cxacru_data is freed, causing a use-after-free when cxacru_poll_status() attempts to acquire instance->poll_state_serialize. Fix this by always calling cancel_delayed_work_sync() regardless of poll_state, ensuring no pending or in-flight work can access the freed instance. Reported-by: syzbot+24eb38c789655fc43663@syzkaller.appspotmail.com Closes: https://syzkaller.appspot.com/bug?extid=3D24eb38c789655fc43663 Signed-off-by: Nguyen Quang Le Kien --- drivers/usb/atm/cxacru.c | 10 +--------- 1 file changed, 1 insertion(+), 9 deletions(-) diff --git a/drivers/usb/atm/cxacru.c b/drivers/usb/atm/cxacru.c index f1900c567..fd644ae52 100644 --- a/drivers/usb/atm/cxacru.c +++ b/drivers/usb/atm/cxacru.c @@ -1231,8 +1231,6 @@ static void cxacru_unbind(struct usbatm_data *usbatm_= instance, struct usb_interface *intf) { struct cxacru_data *instance =3D usbatm_instance->driver_data; - int is_polling =3D 1; - usb_dbg(usbatm_instance, "cxacru_unbind entered\n"); =20 if (!instance) { @@ -1243,17 +1241,11 @@ static void cxacru_unbind(struct usbatm_data *usbat= m_instance, mutex_lock(&instance->poll_state_serialize); BUG_ON(instance->poll_state =3D=3D CXPOLL_SHUTDOWN); =20 - /* ensure that status polling continues unless - * it has already stopped */ - if (instance->poll_state =3D=3D CXPOLL_STOPPED) - is_polling =3D 0; - /* stop polling from being stopped or started */ instance->poll_state =3D CXPOLL_SHUTDOWN; mutex_unlock(&instance->poll_state_serialize); =20 - if (is_polling) - cancel_delayed_work_sync(&instance->poll_work); + cancel_delayed_work_sync(&instance->poll_work); =20 usb_kill_urb(instance->snd_urb); usb_kill_urb(instance->rcv_urb); --=20 2.34.1