From nobody Mon Sep 28 11:40:15 2026 Received: from mail-oa1-f47.google.com (mail-oa1-f47.google.com [209.85.160.47]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id DA6C41419A4 for ; Sat, 22 Aug 2026 03:21:59 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.160.47 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787368921; cv=none; b=i0rW3h+M6CPTV1o2lrwdVwnttXiYGS4rREu4rD2zEWXxebgaVHeio7YXG5Ch2KMQF81sWm5X33MAckA96MAMLuPAI4LlK9cCHklIWfLv+xpkyEeDkqZ9+jEw6iG5zPTdc/1XrEz91SR+mCdI/kFvyIybng754V+ioEDxCRN2lIk= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787368921; c=relaxed/simple; bh=z+TAOGYOtcu12SbF1K+K3yYGj291CeN7wZLybOW+9FI=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=P9aHPpAtZXH/enq1KSFsitvMlB2CtG64zZ3k2t2UrhCOPVaDHGMHHgu8YhyPBNSoR1kc2rCcR4Uh/mST76r6rljIR0fCB7eEhgGPp6Ac7XNXKEbBTSJq+vsvry7BmqIc8O6iWrF91jhJJ1LwSWrK/+ECYAOEnL65JWWyIrIo3ZQ= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=MK/n1ADk; arc=none smtp.client-ip=209.85.160.47 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="MK/n1ADk" Received: by mail-oa1-f47.google.com with SMTP id 586e51a60fabf-446f87b6de1so2439263fac.3 for ; Fri, 21 Aug 2026 20:21:59 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1787368918; x=1787973718; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to:content-type; bh=vstGHMul09KvLuSLJGGZQ3AA3r1UZzwZL60ziR6ObN0=; b=MK/n1ADkK7vEFU12NTCgfE2vo8B+Lt9zMQH/NvxmmdEn+Cn12HClV+YE65XVnUvoM+ C8nNtThNJW73p0xfftVnM44z5t7gFtUA2HuTgk6Mpl+k+jGS5tuOTyc4hoMGGgp1bcqw lFVzhvV9khFExJSVT7v+smPPeTRKndPEMtzZuIpSiGa2kwI1aW/vedzqManWJw1VhV7G G4Ahuw3FFeIN9+kmz4QVohdCBEUT1uYdML8ln+7B2ZxZ+/eB/GAa9iRD2QArBNbZu6fe oQUETlihnGTzEedCJfA098T1VLgY/TgoGgucfq5ib3fWyQ/N8BS4GZUHtvjnLyzIqUjx BUzw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1787368918; x=1787973718; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=vstGHMul09KvLuSLJGGZQ3AA3r1UZzwZL60ziR6ObN0=; b=Wev2R/rvIh+tFiJ8d1nosj14pr2vTwak3Agt3kBwPiZ1lLxWOLoVSTNGaq49aOgsa4 AK1EnJCt8zs1sE0IhNMpns1yMwTpeBMQ9RUqYWTVhr5S42o8GskYheMgluscXh48cTZs WwM6syENEIVLHuwi5Luaq+xVvdpEXFli2GJdDyQISSdCXPHAm1KJuiVn70Xzrt5moS8g tgs3haPxe2av5KZlNmLIGATQnFInRfzeuLpYo7RrVIpeqc0Af+zhKsc6+k14FHCd1Wuu Bl1Vh3xc30oIZuvAaLUIEAPP5mMe6ZaqKIiBjmcNWpaHBfeudjWZTTYEmn8vl8hKfTl6 wwOw== X-Forwarded-Encrypted: i=1; AHgh+RrZVA4R87v67sGr/4Kgay1BTK+ofMcj8yE1EskBoch3lX20bguQ32M2sqtMfc+pYvF/yT8LGPQBxveEJRs=@vger.kernel.org X-Gm-Message-State: AFuF++lRxYrnkkoTvmXMYwq3W4VbNj8L8CqLhNh7Uz1SKfGP+TyvFFD/ v20FTuhSxNAcZgLMfkdcvB5mmAp1ephr+8PGNugQygbL4FAJtaAYAzMX/4GeX7Hb6d0= X-Gm-Gg: AR+sD123PHH4wVWpxbupqXK5ROxDCju9S0TbyZ9aRqXj8VwHpLLq3DDUHyBZgBkuTvG PvvtCs1hYtOqNi0KWZo+d0gfX5DlvBO3KPQBsuW5UsOumFzWZ8DTIMuTPbHF4AbQl7IqW8httNG bwxwRLMDMdgqFib+evd0br5ERYJO65MhdKhR1NwGuraKCDGfzJpAgBD32HoS3O/Vi8aMB+PHEtd L4qUwyg287UQ9ca7kD8iI149aKOCBNp8zCNn8vjlnn7c0Ic3k+6qLqfLqiCKvRaW2qASDKIN+BY UraMmEltfNLgFThcHu2NNsqeX9kq4BmuKu2zv8A8VcbEJs9lLdjk6lYVd3LgV1qzo0bwfynk2oj xQDGVU5aM7Yz58UzXuvHExp22H1urqFL5lwA0Hs6ZTqC/xUvaNok7LtxiiQpEMIqo5BCz0rSyNG sfwzzelXbZdZCBf7n8cvAiGdxkWhbi5vHNnpeXt0si+Umap5pOe2VS9c7TbRacANKAtIaeBmKhi 8XjRJufCVh91DerTTWuesBwRZtySW/AyCmPmckKwsv1HE9rlVEq X-Received: by 2002:a05:6a00:bb91:b0:84e:2382:f4f0 with SMTP id d2e1a72fcca58-851f9a4b169mr18015621b3a.4.1787363079384; Fri, 21 Aug 2026 18:44:39 -0700 (PDT) Received: from hanzj-mi.. (ec2-99-79-140-187.ca-central-1.compute.amazonaws.com. [99.79.140.187]) by smtp.gmail.com with ESMTPSA id d2e1a72fcca58-8520f03b250sm158740b3a.34.2026.08.21.18.44.34 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Fri, 21 Aug 2026 18:44:39 -0700 (PDT) From: hanzhijian To: Greg Kroah-Hartman Cc: linux-usb@vger.kernel.org, linux-kernel@vger.kernel.org, hanzhijian , syzbot+28cf08dec5895bd562e6@syzkaller.appspotmail.com Subject: [PATCH] usb: gadget: loopback: fix memory leak on bind failure Date: Sat, 22 Aug 2026 09:44:27 +0800 Message-ID: <20260822014427.2476530-1-hanzhijian1991@gmail.com> X-Mailer: git-send-email 2.43.0 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" loopback_bind() assigns descriptors via usb_assign_descriptors() but the function has no unbind callback, so when configfs_composite_bind() fails after usb_add_function() succeeds (for example when usb_gadget_check_config() fails), purge_configs_funcs() only calls the unbind callback and the descriptors are never freed. Add an unbind callback that calls usb_free_all_descriptors(), matching the pattern used by other functions such as f_acm, so the descriptors are released when the function is unbound. Reported-by: syzbot+28cf08dec5895bd562e6@syzkaller.appspotmail.com Link: https://syzkaller.appspot.com/bug?extid=3D28cf08dec5895bd562e6 Signed-off-by: hanzhijian --- drivers/usb/gadget/function/f_loopback.c | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/drivers/usb/gadget/function/f_loopback.c b/drivers/usb/gadget/= function/f_loopback.c index d2d07fb49..bf4038cfc 100644 --- a/drivers/usb/gadget/function/f_loopback.c +++ b/drivers/usb/gadget/function/f_loopback.c @@ -216,6 +216,11 @@ static int loopback_bind(struct usb_configuration *c, = struct usb_function *f) return 0; } =20 +static void loopback_unbind(struct usb_configuration *c, struct usb_functi= on *f) +{ + usb_free_all_descriptors(f); +} + static void lb_free_func(struct usb_function *f) { struct f_lb_opts *opts; @@ -442,6 +447,7 @@ static struct usb_function *loopback_alloc(struct usb_f= unction_instance *fi) =20 loop->function.name =3D "loopback"; loop->function.bind =3D loopback_bind; + loop->function.unbind =3D loopback_unbind; loop->function.set_alt =3D loopback_set_alt; loop->function.disable =3D loopback_disable; loop->function.strings =3D loopback_strings; --=20 2.43.0