From nobody Fri Oct 2 01:56:05 2026 Received: from mail-pg1-f170.google.com (mail-pg1-f170.google.com [209.85.215.170]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id C31E0440A00 for ; Thu, 6 Aug 2026 09:36:57 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.215.170 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786009019; cv=none; b=oHAI47REu6sYYLDBTWHMQxl26mb9Mddi/aDa6+wxivRi5XhSKFfdxABsGR/M8GwEsdZt7FKUk/mRShrAPzi9BPYscIgzJuaAJiWdld/q59G6qOUWPLoR3oIiyfMGK71ov7iTOHhjtz6bOeEUif+FYVN6b53ElmgKUhJ5RYNPeSM= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786009019; c=relaxed/simple; bh=b+l5kijwg7xqkug1cUOat0L12FhdH5xWFmrLKtjJQAw=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=XJXYEid69R/dJGa7hFZa7NeG0k2zEAWA45sXdp0KEJ3emfYLOfbcQj1/emQqmR5PBAdizPnkjADpPSuFAxz7mCdUt+5+Kri2UV46qVAGEmlOwpmvR2gfBaNjUcEF3SLaGyyrKE+IaWvC0cTE8473va47vu6Xqgy58DzLpLqZuVA= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=fGugs4rM; arc=none smtp.client-ip=209.85.215.170 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="fGugs4rM" Received: by mail-pg1-f170.google.com with SMTP id 41be03b00d2f7-c9e0b89e228so1274940a12.1 for ; Thu, 06 Aug 2026 02:36:57 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1786009017; x=1786613817; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to:content-type; bh=xuKKBDjdJMpXUXcqM87Kpr9WDhoVOO+MdV9hJTMzecQ=; b=fGugs4rM6o/WolkPDKOV4Rx/K2gmkmOrQeKnkHklabzUZznKrkcFMk2O4yLtKeSR2Y 981HhbhPWUgr+ZOb6S1ccKOqnSG6KxcQ3cgJlR2kMke8CkfiPlTth6wPZiOmQQmbvUBu k3tlfLMX14f3nmZEEnZ5de6S7LTlbldD7PW5Gy297KzfKyPzXTDeZS6RHEUkr/dfgPvw G5a9/xGg1C6DOrhOINHTvwZVyNVStfwUQkgqcwJG13rjCZXqnNB+zBSNE48wwfGs+ZxD wzSPzMKFH8Y7uJpmNYCsKx7IVcSueSDPg0A+kxau+JdD7wnIs2QFJNAfp2klRFukwDVk ZzAQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1786009017; x=1786613817; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=xuKKBDjdJMpXUXcqM87Kpr9WDhoVOO+MdV9hJTMzecQ=; b=SvKHJPd7+0AuMMV8+DSNEw0eGouyI/75qf47pyFumfQjeyVegZMp9I35acu2LzfBcy YBNQ+x7YXNCksYPgJzzUzYs3+k3jAE/QZDgs4LV3kir5EUnmvlx9J7FyvbY37m8o+hx+ zVx8nxJtZWoj2P1pgwJGtsIlwanWmZfWNi8RmW411cX7PPeMZBXVyDWmtEjtCTqYoqJQ H3/quzXV5jMsYE7ef/CjS6tLb+wZGIVoGOoFImuribePjv2uln4vo4Rjm5kS3dDK5fkN 9tcNyKkWQH4AzfVVlI/y09KX/De6fQ+nUG/DMiz9zhxyaLzwNaG39oImAk0AaYmMPW1L cXJg== X-Forwarded-Encrypted: i=1; AHgh+RpjPadH62SRX/0OrCNGWgqKLygZyNNR+YdnIrwoUXgSWUngvmV5FXJFj4vmFOTue1AsMhsLz0BhbL284Sk=@vger.kernel.org X-Gm-Message-State: AOJu0Yy8VXLGkcT6X2cmLyEU2qK8TZzxkUeUzTbqavx1Eqt5c6n/puDw UNXsDeGMIan5+th7j0w8nI+7cK4ZhKvUop7Uj+ylDTy4i5sKoK3ri+hP X-Gm-Gg: AR+sD13G+XSR07mmP6PGkltx9UOWf6FRmOpGXu3b6nuu3qEDDoFAf1chXFoOCXB79dC BiywDQtoB199OzfZJkiH8fqBObVl/Cx9FYNB+ZhZqrVtsQJz9m4ITgVU+uM8I6pjSNT5GA+tBlu YVyPgoWxPb0LKqqxIqNjIkJSt1cEODFKJiLvwWvH33QXbm8qveTt+mLcbO5YoW7Sb+PX9LrhxL9 kkvOcLj8dJLBEwuU2ruJc5z7AW/d8opYZWyRHo5TtskBJbLb+lP/VrpUi2Z4DxpA3w1WSKsSX3g GFJtiHEjrAXaiuspDxOucFDmn4u1xzz/foaV7d5R76kW8GsUNRa4FYPxx+fk3qTPjAD/AsH21YP ioIZUBEfKdixhXfgGH/GfGf7avRIngzRTadrLW1KCxWBL3DI6J9N/Y0xcigElnHujMKRwBtmIMz Yz5lSJRpqZRGsRMh9QejWxSVhTxXvaoGKnK3nDQgfVsYcb42ydEXKG4+GyUV4ivWwO2k3Eter4f w== X-Received: by 2002:a05:6a21:1b85:b0:3c8:d3a4:7b40 with SMTP id adf61e73a8af0-3cb85ded978mr17550129637.2.1786009016964; Thu, 06 Aug 2026 02:36:56 -0700 (PDT) Received: from amd.ban-spse ([165.204.217.251]) by smtp.gmail.com with ESMTPSA id 5a478bee46e88-315867a68fdsm45917973eec.25.2026.08.06.02.36.54 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 06 Aug 2026 02:36:56 -0700 (PDT) From: Chaithanya Lagisetty To: Greg Kroah-Hartman Cc: Christophe JAILLET , Kees Cook , Julian Scheel , Pavel Hofman , linux-usb@vger.kernel.org, linux-kernel@vger.kernel.org, syzbot+87c10526d2cfa8d14ff6@syzkaller.appspotmail.com Subject: [PATCH] usb: gadget: f_uac2: fix memory leak in sample rate parsing Date: Thu, 6 Aug 2026 09:36:39 +0000 Message-ID: <20260806093639.781501-1-nagachaithanya9911@gmail.com> X-Mailer: git-send-email 2.43.0 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" The UAC2_ATTRIBUTE store macro duplicates the input string with kstrdup() and then tokenises the copy with strsep(). strsep() advances the pointer it is given, so once the string has been fully consumed that pointer is NULL and no longer refers to the start of the allocation. The macro passed the same pointer to both strsep() and the final kfree(), so kfree() was called on NULL (or a mid-buffer address) and the buffer returned by kstrdup() was leaked on every write to attributes such as p_srate and c_srate. Keep the pointer returned by kstrdup() in a stable variable used for kfree() and iterate with a separate cursor passed to strsep(). Fixes: a7339e4f5788 ("usb: gadget: f_uac2: Support multiple sampling rates") Reported-by: syzbot+87c10526d2cfa8d14ff6@syzkaller.appspotmail.com Closes: https://syzkaller.appspot.com/bug?extid=3D87c10526d2cfa8d14ff6 Signed-off-by: Chaithanya Lagisetty --- drivers/usb/gadget/function/f_uac2.c | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/drivers/usb/gadget/function/f_uac2.c b/drivers/usb/gadget/func= tion/f_uac2.c index 897787d0803c..2cbdaf6a7db9 100644 --- a/drivers/usb/gadget/function/f_uac2.c +++ b/drivers/usb/gadget/function/f_uac2.c @@ -2013,6 +2013,7 @@ static ssize_t f_uac2_opts_##name##_store(struct conf= ig_item *item, \ { \ struct f_uac2_opts *opts =3D to_f_uac2_opts(item); \ char *split_page =3D NULL; \ + char *iter =3D NULL; \ int ret =3D -EINVAL; \ char *token; \ u32 num; \ @@ -2027,7 +2028,8 @@ static ssize_t f_uac2_opts_##name##_store(struct conf= ig_item *item, \ i =3D 0; \ memset(opts->name##s, 0x00, sizeof(opts->name##s)); \ split_page =3D kstrdup(page, GFP_KERNEL); \ - while ((token =3D strsep(&split_page, ",")) !=3D NULL) { \ + iter =3D split_page; \ + while ((token =3D strsep(&iter, ",")) !=3D NULL) { \ ret =3D kstrtou32(token, 0, &num); \ if (ret) \ goto end; \ --=20 2.43.0