From nobody Sat Aug 1 21:31:00 2026 Received: from mail-oa1-f70.google.com (mail-oa1-f70.google.com [209.85.160.70]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 0786F2745E for ; Sat, 1 Aug 2026 16:43:39 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.160.70 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785602621; cv=none; b=FtyfYJadWE94DkoRZ9GSYBtpN8caTOX5yGBFAoy35L4c4zGQNCV/8EAydgyGAG7T+d/1wuav5gl7fzVYFMDSSP+H0E5iq8UrnqJHWPrTMxFtyEBPjjOnjvMpB08akblefF0dki8kR9bCKUq2eDFaeUOGqH8ZPkniEkJTnyk2vXk= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785602621; c=relaxed/simple; bh=IcbjSEXRRa4btqz0wsg5G4Iy9TDZ0vWFtDLzmDVH5ck=; h=MIME-Version:Date:In-Reply-To:Message-ID:Subject:From:To: Content-Type; b=ILB+kKSsmOlqYUFTH0inVs8xAhHzVAHa3IPiKLludkNQizEA1ly120kP0r+/yKD0ejyocEA32Qnm+AfcV/ABywBN5vGaf0LykFa9hjzQ/C34CAYMh/BNN8r92QgR18oJwxAriwqgg/V7wgYu5DUQQU/CGED/e2gEIK7BkvKnuDk= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=fail (p=none dis=none) header.from=syzkaller.appspotmail.com; spf=pass smtp.mailfrom=M3KW2WVRGUFZ5GODRSRYTGD7.apphosting.bounces.google.com; arc=none smtp.client-ip=209.85.160.70 Authentication-Results: smtp.subspace.kernel.org; dmarc=fail (p=none dis=none) header.from=syzkaller.appspotmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=M3KW2WVRGUFZ5GODRSRYTGD7.apphosting.bounces.google.com Received: by mail-oa1-f70.google.com with SMTP id 586e51a60fabf-451acf33124so1000595fac.0 for ; Sat, 01 Aug 2026 09:43:39 -0700 (PDT) X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785602619; x=1786207419; h=content-type:to:from:subject:message-id:in-reply-to:date :mime-version:x-gm-message-state:from:to:cc:subject:date:message-id :reply-to:content-type; bh=l62vzBwPnIS7hGgeXcBDvRa9Dx3QmugvrQ9O5MTCzxA=; b=Lb7UG6Ci6R2Vx3UkUuopAPwPslfmFZb0M6Ch5rZtk5UjoWuAlFC5UaCmqD3WMY1Yru wQ0nQqVd0pNQY9QB8CgrW7BRJINoeHaavRCb6vbbkkF/4Y9psuPAfTgji3fyt4FIOF0K Snlx8nqcWqNgOHUFQn22ACFUP680ZuygIwEuQAj2Ytwz0DFRB3x2Dvc0qTBYEm3JmQ5g T29yk2p32aw2ghPNqYDuFawTCUU9YSCYmPsxhXRi7yUrQ4byfc6kbjrdcUtQh0LNv08m pnMEYs9cmj43/czOZJmPfxKkotuN+vdhHLiGGHs1+cVW33p7jmpa5p8bmIKl37h37TYm 3VEg== X-Gm-Message-State: AOJu0YxZgh387EpHPHkgBIFM8ATKWk4fXf8TUstoACRxIe5Ios7Pm8PV dJnwJau5q9NMV6znuVB1a8EY6GoMbvwKimisLWquLnlzhPw3pd7u4YGQUKaw5dVyUvWohj7gbQY wAz9Qx16nH7N7DsKOhpM51kU7eKHdTBErpiIM68kENq7GaZa7Iqy6btFEfCU= Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 X-Received: by 2002:a05:6808:13c8:b0:4ab:2abe:f031 with SMTP id 5614622812f47-4af5e03dca4mr9065821b6e.6.1785602618974; Sat, 01 Aug 2026 09:43:38 -0700 (PDT) Date: Sat, 01 Aug 2026 09:43:38 -0700 In-Reply-To: <6a6cd832.1aa927e4.17d4bf.0009.GAE@google.com> X-Google-Appengine-App-Id: s~syzkaller X-Google-Appengine-App-Id-Alias: syzkaller Message-ID: <6a6e223a.f794c993.27aeb.0013.GAE@google.com> Subject: Forwarded: #syz test: git://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git 11028ab62899 From: syzbot To: linux-kernel@vger.kernel.org, syzkaller-bugs@googlegroups.com Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" For archival purposes, forwarding an incoming command email to linux-kernel@vger.kernel.org, syzkaller-bugs@googlegroups.com. *** Subject: #syz test: git://git.kernel.org/pub/scm/linux/kernel/git/torvalds/= linux.git 11028ab62899 Author: rwarwatkar@gmail.com From a6329c2864899c7c7ac2c20b9d3e04bf598c6870 Mon Sep 17 00:00:00 2001 From: Rituparna Warwatkar Date: Sat, 1 Aug 2026 03:31:03 +0000 Subject: [PATCH] usb: gadget: uvc: don't pack struct uvcg_extension_unit_descriptor kmemleak reports the baSourceID and bmControls arrays allocated by the UVC extension-unit configfs attributes as leaked, e.g.: BUG: memory leak unreferenced object 0xffff888114fee2c0 (size 8): __kmalloc_noprof uvcg_extension_ba_source_id_store configfs_write_iter vfs_write ksys_write The arrays are not actually leaked: they are reachable through xu->desc.baSourceID / xu->desc.bmControls and are freed when the extension unit is removed. The problem is that struct uvcg_extension_unit_descriptor is marked __packed, so these two heap pointers are stored at unaligned offsets (22 and 31). kmemleak only scans memory on pointer-aligned boundaries, so it never sees the pointers and reports the arrays as unreferenced. Unlike the UAPI struct uvc_extension_unit_descriptor, this is a purely in-memory staging structure: baSourceID and bmControls are pointers, not inline arrays, and the wire descriptor is assembled field by field in UVC_COPY_XU_DESCRIPTOR(). Nothing relies on the packed layout, so the __packed attribute is unnecessary and only serves to misalign the pointers. Drop __packed so the pointers are naturally aligned and visible to kmemleak, silencing the false positive. Fixes: 0525210c9840 ("usb: gadget: uvc: Allow definition of XUs in configfs= ") Reported-by: syzbot+54927260acba030187a6@syzkaller.appspotmail.com Closes: https://syzkaller.appspot.com/bug?extid=3D54927260acba030187a6 Signed-off-by: Rituparna Warwatkar --- drivers/usb/gadget/function/uvc_configfs.h | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/drivers/usb/gadget/function/uvc_configfs.h b/drivers/usb/gadge= t/function/uvc_configfs.h index 9391614135e..5a882afbce4 100644 --- a/drivers/usb/gadget/function/uvc_configfs.h +++ b/drivers/usb/gadget/function/uvc_configfs.h @@ -176,7 +176,7 @@ struct uvcg_extension_unit_descriptor { u8 bControlSize; u8 *bmControls; u8 iExtension; -} __packed; +}; struct uvcg_extension { struct config_item item; -- 2.47.3