From nobody Mon Sep 28 15:34:34 2026 Received: from mail-pl1-f171.google.com (mail-pl1-f171.google.com [209.85.214.171]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 643C22C15A0 for ; Thu, 20 Aug 2026 08:46:02 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.214.171 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787215563; cv=none; b=QRsNYd9HqNza4tu5VN3uaFDg3qNZvEM2Qj32qwimMW764oGDCLqA5FRcuCqrZBGI3IWykS2ZG7hQjPhl/al44Ejut1V47E0KBrc3GcUNeqdOU01Eu8wvlO7AoAYfsbdjWxVC5ENUW1eOyLAtJw9Lr28AxqmtYniM5ws4RVkTGBw= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787215563; c=relaxed/simple; bh=HahRdRZ7rEXECKhD0wf0GCLX8sapc833UetJWo8hm5Q=; h=From:To:Cc:Subject:Date:Message-Id:In-Reply-To:References: MIME-Version; b=gAYiBfSfu8phKBGhGlnW5bX0Yf8Mxo7VVOEo2zn2i86S8tatoZXjlKWl0dJo16P7knOZU4rygotBQxPbnbuPfD7cU7KtCPuvpmetzureB59GK5/jestoZspfVNyryK+4G4Sl4S6wTkCYyz2m2Q3zDB8ktI6gsAGRhIiE006/TaQ= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=gxscBStO; arc=none smtp.client-ip=209.85.214.171 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="gxscBStO" Received: by mail-pl1-f171.google.com with SMTP id d9443c01a7336-2cacb8416a1so16808805ad.1 for ; Thu, 20 Aug 2026 01:46:02 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1787215562; x=1787820362; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=UIptc2Pyic8RLfsRCuTURjR3M5LHBGZIonYSyw9G1vs=; b=gxscBStO1VpqlsASEoyBNHZiWVEQzI4+uSAnPWGQ5nPh7y/KKlw4bPG6/1mhrRsUD7 HW9gY55Qy72+gnt+GZ+NMRtQd7jf0WJhs0skVsVu2qs5dCbdnYyIUrgmXhsDb1MhDWix oCpsUXXP+SCqMAdX5sckxzU+52z9Q2FHOlqSaYbSloD109Z4ey4hxCXcYp96PaeF6XCz xcplrmmLr+kmV5sY7gMeDirWgn+NG7oG0yjDffKbKbWUxvrI1rRAVbhVaTQ0A3QjOiH7 xg+zc0GbyVnO4RoPqF2mAfl//Bp98bXjd69VoukhmpxZdHJ8XnzZZT3m5WT+v2mWtP46 jKLg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1787215562; x=1787820362; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=UIptc2Pyic8RLfsRCuTURjR3M5LHBGZIonYSyw9G1vs=; b=rZTrJgy1//fd14ifn0AMG2iyrXrbzqBcZOCpDPSJP//2621GP8R60uvAFMzJHxBLYb WSorKSAyDtvWzEw+S6/muh5OJnilgAeWwAGr+P7YoiqWuZgLQOeqlgGpjTzK0ZbLYmor UHDFsISLK2gO3/aMxcditArQD4RtLEDgR9b+lwbrfEIMJZkrqqQ8x709irvNxJ7acTUY DSq+9WPU97fg44mw9SySuaD8F//K9Ib/BrBs/zzRZzDPjn5fApmTPi/p8C6oqPW6Tbwv +r64LiD77F487l7nFZbIee5xdb4m8fJPVo6o76Lw1eJDBpQxqIgIAJMSVj6qTcbk7npd racg== X-Forwarded-Encrypted: i=1; AHgh+RpIaQX44GKjHv0Ds1ibIpGm57Un/Qj3s43MM2XlWxoEBX6EMGTOLZExd/cycYL7sUJibgvN1ucZBvpFm0w=@vger.kernel.org X-Gm-Message-State: AFuF++k3f0qU1fJU5m1aYkmi7j+GdfUnB7Sxp9VqfgPnPKLy+XSAdx0h MaB5XoDgX5nk81i8V4vFH78k345edBwMigyZeysFm4o407WUKxCEIPrR X-Gm-Gg: AR+sD13Iy0gAJjnTz622cRhAPi6IxcsHy8ixj15QeMTGhOSscO+sOP7sw9LvhWykIcJ yc2GW7J3J8+99WQh/GhyA0u608vrjB3iKREY1x8Fy1Ia2kMySpkcUz7ldtKd84XDV3VpnavqLA2 b3VZ/azWeCq+lCQmdrqUO812MVZPF90kqSbTODS4njle3D1AYAYZi6nk4HQXPPBkKTpH0Yw6Opw XLYY6LoGrLouZl9/h5Xpyhyg9SGfTMU7kpKlBxmWsDij2Dpgqtrzo8GpyYLt53X0Rw9/MtbUyiz F/ijF/0BI2jbRs/BC2JoJA48m5NFvFiAOyAj8B2oo1muOEE4hulxNIXpuhpZR3K3zRFZvfYyq5F vlu61kgQt9ICeZ5mY9Fg/Mbo+ufsjm1B1DOysRKI4izSBQcK9KSGWblf8/U2FnJ1Z3P5Ts0MW6i rBLYfUqGwQi/UD/GkBx9RVv8Th/UV/xsyd5L+w75NCc8WTT6Hzc9XUoCA0B99TjwISDH8p8+DXc kqIv16zDtMhD9qLgVM0ilyp X-Received: by 2002:a17:902:d4c6:b0:2c9:c517:d070 with SMTP id d9443c01a7336-2d5fd5b0008mr184056225ad.3.1787215561696; Thu, 20 Aug 2026 01:46:01 -0700 (PDT) Received: from ML-GYSUBT565.ECARX.COM.CN ([101.47.164.95]) by smtp.gmail.com with ESMTPSA id 5a478bee46e88-327bf173b02sm14731169eec.27.2026.08.20.01.45.59 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 20 Aug 2026 01:46:01 -0700 (PDT) From: Nguyen Quang Le Kien To: gregkh@linuxfoundation.org Cc: rafael@kernel.org, dakr@kernel.org, driver-core@lists.linux.dev, linux-kernel@vger.kernel.org, Nguyen Quang Le Kien , syzbot+87188222c77c0dbbdb4d@syzkaller.appspotmail.com, stable@vger.kernel.org Subject: [PATCH v4] driver core: avoid klist_remove() on unattached knode_driver Date: Thu, 20 Aug 2026 16:45:57 +0800 Message-Id: <20260820084557.129908-1-khiemtranzo532001@gmail.com> X-Mailer: git-send-email 2.34.1 In-Reply-To: <2026082042-coma-moody-5b4e@gregkh> References: <2026082042-coma-moody-5b4e@gregkh> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" usb_driver_claim_interface() sets dev->driver directly and skips device_bind_driver() when the interface is not yet registered, so the device can reach teardown with dev->driver set but knode_driver never added to the driver's klist_devices. __device_release_driver() then unconditionally calls klist_remove() on the unattached node, which dereferences a NULL klist pointer in klist_put() and crashes. Only remove the node if the device is actually bound. Use device_is_bound() rather than klist_node_attached() directly: the latter is a raw klist API and does not NULL-check dev->p, while device_is_bound() is the standard bound-state check used throughout driver core (driver_bound(), __device_attach()). Fixes: 94e7b1c5ff20 ("[PATCH] Add a klist to struct device_driver for the d= evices bound to it.") Reported-by: syzbot+87188222c77c0dbbdb4d@syzkaller.appspotmail.com Closes: https://syzkaller.appspot.com/bug?extid=3D87188222c77c0dbbdb4d Cc: stable@vger.kernel.org Signed-off-by: Nguyen Quang Le Kien --- Changes in v4: - add a changelog below the --- line, as required by submitting-patches.rst - add Cc: stable@vger.kernel.org, Fixes: points to a released kernel Changes in v3: - document in the commit message why device_is_bound() is used instead of klist_node_attached() - add Fixes: tag Changes in v2: - use device_is_bound() instead of klist_node_attached() as the bound check, per review --- drivers/base/dd.c | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/drivers/base/dd.c b/drivers/base/dd.c index 60c005223..4154b4499 100644 --- a/drivers/base/dd.c +++ b/drivers/base/dd.c @@ -1354,7 +1354,8 @@ static void __device_release_driver(struct device *de= v, struct device *parent) device_unbind_cleanup(dev); device_links_driver_cleanup(dev); =20 - klist_remove(&dev->p->knode_driver); + if (device_is_bound(dev)) + klist_remove(&dev->p->knode_driver); device_pm_check_callbacks(dev); =20 bus_notify(dev, BUS_NOTIFY_UNBOUND_DRIVER); --=20 2.34.1