From nobody Sat Aug 1 21:31:01 2026 Received: from mail-ot1-f69.google.com (mail-ot1-f69.google.com [209.85.210.69]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 1E53D3B14D4 for ; Sat, 1 Aug 2026 16:45:31 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.210.69 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785602733; cv=none; b=ESdKawkNI1usgkFJm7gG6agEJhdvLUwCwpfPmXZK7GyO0w9GGQ9/IRXYP1RFZdGDihAl9fftGxxYP/tlHy7DGP7hpnUmn8IyVoNvc3Xk8gqiLnCnB/poP3nyL0qsojVyqosRblbdTzQ6fE7wZjPOwmA1Sa/dd4cemSQKTIcIEOE= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785602733; c=relaxed/simple; bh=Z1g2palsRquKJcq740feYFa/8B3M5pv3DUPzKXFeC8s=; h=MIME-Version:Date:In-Reply-To:Message-ID:Subject:From:To: Content-Type; b=ZcIK9dAzD57j054ODOVXpr9Y8Z34XgEOff/H6ASQjX4LFfTr/4R6gdiTohQ0SWvkcJhCMJFlm1XE9TeogwUS4TNdQJ/if7b0O4VmyXRPi7/4DkUQxCRSSvrxUkJ6A8uIXFvPnU4Ovy0Z07u+Vo3mxLEeXhisviHzvNvWTGUfJJ0= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=fail (p=none dis=none) header.from=syzkaller.appspotmail.com; spf=pass smtp.mailfrom=M3KW2WVRGUFZ5GODRSRYTGD7.apphosting.bounces.google.com; arc=none smtp.client-ip=209.85.210.69 Authentication-Results: smtp.subspace.kernel.org; dmarc=fail (p=none dis=none) header.from=syzkaller.appspotmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=M3KW2WVRGUFZ5GODRSRYTGD7.apphosting.bounces.google.com Received: by mail-ot1-f69.google.com with SMTP id 46e09a7af769-7ead32f5c6aso1062647a34.1 for ; Sat, 01 Aug 2026 09:45:31 -0700 (PDT) X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785602731; x=1786207531; h=content-type:to:from:subject:message-id:in-reply-to:date :mime-version:x-gm-message-state:from:to:cc:subject:date:message-id :reply-to:content-type; bh=B05G49rp1D+2axrdtai1bLRdJjMvEWL+hXFpafrVv+A=; b=s0CkECfrxPb5joC4tLkXRm3ankuAS3S2K7HwxVkpEt6Oum9hT0dIhF1ewVaCiktBDW G+brGeHM1RMjOF3/AodwdxFxZb7c0wdj6iWj1wKFgl9nS/sCEVgqGT8LLfcGY2bQdRYs fVF+9P5Nc6vmwi+6gZTt6Mh85v8qjwGJmK5tYjzVU7NCt0EQdjjvcex4WUO8BivrPlgu 0+YNBaZniQQ2FWi/QASop+lD8zlwvuRtou/rqx/povmDtBGL7H4AJH81G1ETicwM7fpt oX9IHCYzAlnZwcXLSQM6lI5C05DfSvAC1ZXuM+d+fK0MH3Jwdk24XvlyZeiFTUl3URvF iv+Q== X-Gm-Message-State: AOJu0YwMPGs71GanThAh9w7otJ3MZcGseFfWRkMs0fDfzoqltjMt6HmB 9taCi7EvnBuSmZSRYwMqkA9hBm1y6kZlxFP/icpcH8tFsh5S4rTqCbGzciZSNtyBjBoDVSPqP6F 0um+t6qJOikmVjxN/P0OpjmGXTZMtwUnuGMnYnVPei2tI0+eZp0GzGNxKikw= Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 X-Received: by 2002:a05:6808:c3ee:b0:496:11f1:f2b5 with SMTP id 5614622812f47-4af5e1b817bmr8814817b6e.10.1785602731018; Sat, 01 Aug 2026 09:45:31 -0700 (PDT) Date: Sat, 01 Aug 2026 09:45:30 -0700 In-Reply-To: <6a6cd832.1aa927e4.17d4bf.0009.GAE@google.com> X-Google-Appengine-App-Id: s~syzkaller X-Google-Appengine-App-Id-Alias: syzkaller Message-ID: <6a6e22aa.1aa927e4.17d4bf.0010.GAE@google.com> Subject: Forwarded: #syz test From: syzbot To: linux-kernel@vger.kernel.org, syzkaller-bugs@googlegroups.com Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" For archival purposes, forwarding an incoming command email to linux-kernel@vger.kernel.org, syzkaller-bugs@googlegroups.com. *** Subject: #syz test Author: rwarwatkar@gmail.com From a6329c2864899c7c7ac2c20b9d3e04bf598c6870 Mon Sep 17 00:00:00 2001 From: Rituparna Warwatkar Date: Sat, 1 Aug 2026 03:31:03 +0000 Subject: [PATCH] usb: gadget: uvc: don't pack struct uvcg_extension_unit_descriptor kmemleak reports the baSourceID and bmControls arrays allocated by the UVC extension-unit configfs attributes as leaked, e.g.: BUG: memory leak unreferenced object 0xffff888114fee2c0 (size 8): __kmalloc_noprof uvcg_extension_ba_source_id_store configfs_write_iter vfs_write ksys_write The arrays are not actually leaked: they are reachable through xu->desc.baSourceID / xu->desc.bmControls and are freed when the extension unit is removed. The problem is that struct uvcg_extension_unit_descriptor is marked __packed, so these two heap pointers are stored at unaligned offsets (22 and 31). kmemleak only scans memory on pointer-aligned boundaries, so it never sees the pointers and reports the arrays as unreferenced. Unlike the UAPI struct uvc_extension_unit_descriptor, this is a purely in-memory staging structure: baSourceID and bmControls are pointers, not inline arrays, and the wire descriptor is assembled field by field in UVC_COPY_XU_DESCRIPTOR(). Nothing relies on the packed layout, so the __packed attribute is unnecessary and only serves to misalign the pointers. Drop __packed so the pointers are naturally aligned and visible to kmemleak, silencing the false positive. Fixes: 0525210c9840 ("usb: gadget: uvc: Allow definition of XUs in configfs= ") Reported-by: syzbot+54927260acba030187a6@syzkaller.appspotmail.com Closes: https://syzkaller.appspot.com/bug?extid=3D54927260acba030187a6 Signed-off-by: Rituparna Warwatkar --- drivers/usb/gadget/function/uvc_configfs.h | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/drivers/usb/gadget/function/uvc_configfs.h b/drivers/usb/gadge= t/function/uvc_configfs.h index 9391614135e..5a882afbce4 100644 --- a/drivers/usb/gadget/function/uvc_configfs.h +++ b/drivers/usb/gadget/function/uvc_configfs.h @@ -176,7 +176,7 @@ struct uvcg_extension_unit_descriptor { u8 bControlSize; u8 *bmControls; u8 iExtension; -} __packed; +}; struct uvcg_extension { struct config_item item; -- 2.47.3