From nobody Mon Sep 28 19:23:38 2026 Received: from mail-pj1-f48.google.com (mail-pj1-f48.google.com [209.85.216.48]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id B76F53A75A7 for ; Tue, 18 Aug 2026 08:33:29 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.216.48 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787042011; cv=none; b=IYDnRyQEZ/kG51ijpfg3XtjB0kZuurRDYcfIfUQRp/J8rhRXbp0nsPXqC5onFo402SaPMdX4I1xGXMycxJPnuo7wZSI4khvXgfSuAqyOPyu2PsDJO7oYiIq6o/ynA3CwEq7xD+9oN+OVtjWRevhZbtFucnaln4TXhRRXd2dg2fo= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787042011; c=relaxed/simple; bh=RlsS7vAu3DE/r5tm5+GKRG8WE9EmSc1cMP6e7fbOCVU=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=XGRPFTpmq4Ysp9R9qhuYrnVr+G10+E1IT6xsjGprpiLu9p8hOIleN9oaLL8ydS3xUCGLBICN+S8fn+cobXTE10t6DvLnksJU1momeW18vJNiuKwLKNPoXlusLt8b/c+9QgqKMj0tdKEzyjBj/Zr0cCRDeSY2I8LsRYVgDnxqub0= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=FbazJZhL; arc=none smtp.client-ip=209.85.216.48 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="FbazJZhL" Received: by mail-pj1-f48.google.com with SMTP id 98e67ed59e1d1-384930ca5e2so4905292a91.3 for ; Tue, 18 Aug 2026 01:33:29 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1787042009; x=1787646809; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to:content-type; bh=srZLzFpNfDNrD79+dnb6Flm08rVfyHpmgm9TRApXS9U=; b=FbazJZhLJC5zX3DES6CHukut/CyoJuVmjFufMTFroVu7H9+eMJiv/4W/Jx7+N6Q9gR Uu2VBvmDIU+BlnCabCX11wo7rr6dnvBmi8LL9zukHQ6+dImrljL7sq1l2bUiKLd9k/BL VLwK286v13Cmj0cO6vE/qUVVsKrneHNStRwSB6SpB0axfWJRRfClMs4fjs2VNgjiEMpk sM2GgbPaRcf+TplZPflzOMzBPp0urZs43UXapdawl26GtY0kPf1gzBZ9I/gKmxoyIaf7 Kj8gYqmgpZgRJwtCDJOJnPOUhQRexOvww2fAVbFPewQ2UPYVwxcFnUB/FrN1C6hmTh5A 0Rpw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1787042009; x=1787646809; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=srZLzFpNfDNrD79+dnb6Flm08rVfyHpmgm9TRApXS9U=; b=XdJnwTrEW9rh2kWdNPO7/qEFOZGbN0ooCwDEImmOKMbMRWRgqL4qsQ7SK6dkgiMkuT esDxpvVmxsMxQJMeFGmaIvr5k6lw/+8jWGYqiUaDp8Pr6F6jGrCen74hK82YSo1qCTex LmwoBGHoSpxBUMMENUecyy42jbsDS3EUvKHSQObkBz9ewNUDvFsTR6Sj7LpPlclpfaV5 F8+g8mtTX51CjwcskUHwVqfZeu43ge8t2kI99yvCB+0Q6f2z7mZ799znMY3mA1V88RCc tS2aNyJOJ61X00+PoA5NnzlmbVYo5fe1GEAl5O9nSGRDscYDcod30khzwxNFyWpPem8A Ee7A== X-Forwarded-Encrypted: i=1; AHgh+RpmidzosabtFoBtxmw/Es4raMUhVHSMCFzfANl3OfeYyjz3QXZ8p/JcoVzJX7MMx+4OLYz9CyY/VzRXxOs=@vger.kernel.org X-Gm-Message-State: AOJu0YzPHHAVVFeg6cMW9XdhnRmPK87moUaP12PPpe6wQLZxKnUox9/T oICJCm0uLIcmlz/fbb/l2YMV5iJd/7jJkzDJ7hULyRzxz5m30bNXRT5m X-Gm-Gg: AR+sD12VEfjr714KGz7R6gHipIP4GHcpBibxZPNLuFF4Q9GM6pG64wf75W46m4fkEn1 QhH09kSx58h2Z7TYG/LnXSsOjjmfUoXt/hbxpudetqLgOrIkeJvTcv8zKEd1tluzbNjpZsHvNIx fhx3pqpXEQ2CrDtiqenVITkK3W9RLicEXoewukuYOUY2ffICkPHaMOvHtVjnpBiMWwrqPvxFQ9N LaJzB9Em7sAp+KS5Mjfyeqc8S/h4y1QsVhXtNhq5o4CGozMGirQvVa1R0PDw0RJORzjfLDgSRAv T7cEW47pB400vr62a2GSRZwy383G+5scsFgrMO9N2evA7qTavPNO7gd/qFytlaXe//GgR4bey1Z HW7e2q/T69gyL7G91d/7wI09g5cLqc5szxbIjJq0YfQhL1iCSNxOxLnzN5TiH4fI2FAfxzKzEiW 8f9AlQzFHHRblGG9GBJ13cqrVE49LC4QD0yHeelVJuUpD/+pRehLZ5Ic7Zlhby+hFikL0= X-Received: by 2002:a17:90b:5291:b0:36a:5d1f:7b6 with SMTP id 98e67ed59e1d1-3933bd18849mr34288276a91.2.1787042008953; Tue, 18 Aug 2026 01:33:28 -0700 (PDT) Received: from localhost ([2402:e280:3e0d:544:91b3:77c4:f31d:d706]) by smtp.gmail.com with ESMTPSA id 5a478bee46e88-326794c0c94sm27801981eec.9.2026.08.18.01.33.27 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Tue, 18 Aug 2026 01:33:28 -0700 (PDT) From: Vaibhav Nagare X-Google-Original-From: Vaibhav Nagare To: stern@rowland.harvard.edu, gregkh@linuxfoundation.org Cc: linux-usb@vger.kernel.org, linux-kernel@vger.kernel.org, stable@vger.kernel.org, Vaibhav Nagare Subject: [PATCH] usb: ehci: fix QTD list corruption in qh_completions Date: Tue, 18 Aug 2026 14:03:23 +0530 Message-ID: <20260818083323.2270580-1-vnagare@redhat.com> X-Mailer: git-send-email 2.54.0 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" In qh_completions(), when completing a URB at a URB boundary (last->urb !=3D urb), ehci_urb_done() is called which drops ehci->lock via usb_hcd_giveback_urb() for the completion callback. While the lock is dropped, a concurrent ehci_urb_dequeue() (e.g. from a TX timeout recovery) can modify the QTD list, making the 'tmp' pointer saved by list_for_each_safe() stale. Continuing iteration with a stale pointer leads to list_del() corruption and a kernel panic: list_del corruption. prev->next should be ff27e4e01aefa580, but was ff27e4e01aefa1c0 kernel BUG at lib/list_debug.c:51! Call Trace: qh_completions+0x28f/0x640 ehci_work.part.0+0x1d5/0x330 ehci_irq+0x3d2/0x490 This was observed on systems with an HPE iLO5 Virtual NIC (cdc_ncm) where repeated NETDEV WATCHDOG TX timeouts trigger concurrent URB unlinks that race with the qh_completions lock-drop window. Fix this by freeing the completed QTD and restarting the list scan via the existing rescan label after ehci_urb_done(). This is safe because already-processed QTDs have been removed via list_del() and the list is strictly shrinking, guaranteeing forward progress. Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2") Cc: stable@vger.kernel.org Signed-off-by: Vaibhav Nagare --- drivers/usb/host/ehci-q.c | 11 ++++++++++- 1 file changed, 10 insertions(+), 1 deletion(-) diff --git a/drivers/usb/host/ehci-q.c b/drivers/usb/host/ehci-q.c index ba37a9fcab92..c715648e97ab 100644 --- a/drivers/usb/host/ehci-q.c +++ b/drivers/usb/host/ehci-q.c @@ -328,7 +328,16 @@ qh_completions (struct ehci_hcd *ehci, struct ehci_qh = *qh) if (last) { if (likely (last->urb !=3D urb)) { ehci_urb_done(ehci, last->urb, last_status); - last_status =3D -EINPROGRESS; + /* + * ehci_urb_done() drops ehci->lock for the + * completion callback. The QTD list may have + * been modified (e.g. by URB unlink during + * TX timeout recovery). The 'tmp' saved by + * list_for_each_safe() may be stale. + * Free last and restart the scan. + */ + ehci_qtd_free(ehci, last); + goto rescan; } ehci_qtd_free (ehci, last); last =3D NULL; --=20 2.54.0