From: pip-izony <eeodqql09@gmail.com>
To: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Cc: Seungjin Bae <eeodqql09@gmail.com>,
Kyungtae Kim <Kyungtae.Kim@dartmouth.edu>,
Alan Stern <stern@rowland.harvard.edu>,
Kees Cook <kees@kernel.org>,
Dan Carpenter <dan.carpenter@linaro.org>,
David Mosberger <davidm@egauge.net>,
linux-usb@vger.kernel.org, linux-kernel@vger.kernel.org
Subject: [PATCH v4 2/2] usb: host: max3421: Reject hub port requests for non-existent ports
Date: Mon, 18 May 2026 18:49:02 -0400 [thread overview]
Message-ID: <20260518224901.1887013-3-eeodqql09@gmail.com> (raw)
In-Reply-To: <20260518224901.1887013-1-eeodqql09@gmail.com>
From: Seungjin Bae <eeodqql09@gmail.com>
The `max3421_hub_control()` function handles USB hub class requests
to the virtual root hub. The `GetPortStatus` case correctly rejects
requests with `index != 1`, since the virtual root hub has only a
single port. However, the `ClearPortFeature` and `SetPortFeature`
cases lack the same check.
Fix this by extending the `index != 1` rejection to both cases,
matching the existing behavior of `GetPortStatus`.
Fixes: 2d53139f3162 ("Add support for using a MAX3421E chip as a host driver.")
Suggested-by: Alan Stern <stern@rowland.harvard.edu>
Reviewed-by: Alan Stern <stern@rowland.harvard.edu>
Signed-off-by: Seungjin Bae <eeodqql09@gmail.com>
---
v3: New patch in v3, suggested by Alan Stern.
v3 -> v4: No functional changes.
drivers/usb/host/max3421-hcd.c | 4 ++++
1 file changed, 4 insertions(+)
diff --git a/drivers/usb/host/max3421-hcd.c b/drivers/usb/host/max3421-hcd.c
index 3d6b351dcb1a..73e76d0e6973 100644
--- a/drivers/usb/host/max3421-hcd.c
+++ b/drivers/usb/host/max3421-hcd.c
@@ -1685,6 +1685,8 @@ max3421_hub_control(struct usb_hcd *hcd, u16 type_req, u16 value, u16 index,
case ClearHubFeature:
break;
case ClearPortFeature:
+ if (index != 1)
+ goto error;
switch (value) {
case USB_PORT_FEAT_SUSPEND:
break;
@@ -1728,6 +1730,8 @@ max3421_hub_control(struct usb_hcd *hcd, u16 type_req, u16 value, u16 index,
break;
case SetPortFeature:
+ if (index != 1)
+ goto error;
switch (value) {
case USB_PORT_FEAT_LINK_STATE:
case USB_PORT_FEAT_U1_TIMEOUT:
--
2.43.0
prev parent reply other threads:[~2026-05-18 22:49 UTC|newest]
Thread overview: 13+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-05-17 0:01 [PATCH] usb: host: max3421: Fix shift-out-of-bounds in max3421_hub_control() pip-izony
2026-05-17 0:07 ` [PATCH v2] " pip-izony
2026-05-17 1:15 ` Alan Stern
2026-05-17 18:11 ` Seungjin Bae
2026-05-17 5:49 ` [PATCH] " Greg Kroah-Hartman
2026-05-17 18:19 ` Seungjin Bae
2026-05-18 5:19 ` Greg Kroah-Hartman
2026-05-17 19:03 ` [PATCH v3 1/2] " pip-izony
2026-05-17 19:03 ` [PATCH v3 2/2] usb: host: max3421: Reject hub port requests for non-existent ports pip-izony
2026-05-18 21:54 ` Alan Stern
2026-05-18 22:37 ` Seungjin Bae
2026-05-18 22:49 ` [PATCH v4 1/2] usb: host: max3421: Fix shift-out-of-bounds in max3421_hub_control() pip-izony
2026-05-18 22:49 ` pip-izony [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260518224901.1887013-3-eeodqql09@gmail.com \
--to=eeodqql09@gmail.com \
--cc=Kyungtae.Kim@dartmouth.edu \
--cc=dan.carpenter@linaro.org \
--cc=davidm@egauge.net \
--cc=gregkh@linuxfoundation.org \
--cc=kees@kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-usb@vger.kernel.org \
--cc=stern@rowland.harvard.edu \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.