* [PATCH usb-next v1] USB: gadgetfs: Fix use-after-free in gadgetfs_kill_sb
@ 2026-08-28 6:18 Rafael Alejandro Diaz Cruz
2026-08-28 14:00 ` Alan Stern
0 siblings, 1 reply; 2+ messages in thread
From: Rafael Alejandro Diaz Cruz @ 2026-08-28 6:18 UTC (permalink / raw)
To: gregkh
Cc: linux-usb, linux-kernel, Rafael Alejandro Diaz Cruz,
syzbot+4a5c87a01894ca37f25c
When gadgetfs_fill_super() fails, it's error path calls
put_dev() which drops refcount inside the_device to 0
and frees the objet. But the_device pointer is not
cleared, leading to point at freed memory.
VFS will then call gadgetfs_kill_sb() after mount
failure leading to put_dev() to be called on the
already freed pointer.
Fix by setting the_device = NULL during error path
before calling put_dev() inside gadgetfs_fill_super()
so that gadgetfs_kill_sb() skips put_dev().
Reported-by: syzbot+4a5c87a01894ca37f25c@syzkaller.appspotmail.com
Link: https://syzkaller.appspot.com/bug?extid=4a5c87a01894ca37f25c
Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
Signed-off-by: Rafael Alejandro Diaz Cruz <rafad900@gmail.com>
---
drivers/usb/gadget/legacy/inode.c | 2 ++
1 file changed, 2 insertions(+)
diff --git a/drivers/usb/gadget/legacy/inode.c b/drivers/usb/gadget/legacy/inode.c
index d87a8ab51510..77efa984ce84 100644
--- a/drivers/usb/gadget/legacy/inode.c
+++ b/drivers/usb/gadget/legacy/inode.c
@@ -2059,6 +2059,7 @@ gadgetfs_fill_super (struct super_block *sb, struct fs_context *fc)
rc = gadgetfs_create_file(sb, CHIP, dev, &ep0_operations);
if (rc) {
put_dev(dev);
+ the_device = NULL;
goto Enomem;
}
@@ -2066,6 +2067,7 @@ gadgetfs_fill_super (struct super_block *sb, struct fs_context *fc)
* from binding to a controller.
*/
the_device = dev;
+ get_dev(dev);
rc = 0;
goto Done;
--
2.43.0
^ permalink raw reply related [flat|nested] 2+ messages in thread* Re: [PATCH usb-next v1] USB: gadgetfs: Fix use-after-free in gadgetfs_kill_sb
2026-08-28 6:18 [PATCH usb-next v1] USB: gadgetfs: Fix use-after-free in gadgetfs_kill_sb Rafael Alejandro Diaz Cruz
@ 2026-08-28 14:00 ` Alan Stern
0 siblings, 0 replies; 2+ messages in thread
From: Alan Stern @ 2026-08-28 14:00 UTC (permalink / raw)
To: Rafael Alejandro Diaz Cruz
Cc: gregkh, linux-usb, linux-kernel, syzbot+4a5c87a01894ca37f25c
On Thu, Aug 27, 2026 at 11:18:29PM -0700, Rafael Alejandro Diaz Cruz wrote:
> When gadgetfs_fill_super() fails, it's error path calls
> put_dev() which drops refcount inside the_device to 0
> and frees the objet. But the_device pointer is not
> cleared, leading to point at freed memory.
>
> VFS will then call gadgetfs_kill_sb() after mount
> failure leading to put_dev() to be called on the
> already freed pointer.
>
> Fix by setting the_device = NULL during error path
> before calling put_dev() inside gadgetfs_fill_super()
> so that gadgetfs_kill_sb() skips put_dev().
>
> Reported-by: syzbot+4a5c87a01894ca37f25c@syzkaller.appspotmail.com
> Link: https://syzkaller.appspot.com/bug?extid=4a5c87a01894ca37f25c
> Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
> Signed-off-by: Rafael Alejandro Diaz Cruz <rafad900@gmail.com>
> ---
> drivers/usb/gadget/legacy/inode.c | 2 ++
> 1 file changed, 2 insertions(+)
>
> diff --git a/drivers/usb/gadget/legacy/inode.c b/drivers/usb/gadget/legacy/inode.c
> index d87a8ab51510..77efa984ce84 100644
> --- a/drivers/usb/gadget/legacy/inode.c
> +++ b/drivers/usb/gadget/legacy/inode.c
> @@ -2059,6 +2059,7 @@ gadgetfs_fill_super (struct super_block *sb, struct fs_context *fc)
> rc = gadgetfs_create_file(sb, CHIP, dev, &ep0_operations);
> if (rc) {
> put_dev(dev);
> + the_device = NULL;
This is what the description says the patch will do.
> goto Enomem;
> }
>
> @@ -2066,6 +2067,7 @@ gadgetfs_fill_super (struct super_block *sb, struct fs_context *fc)
> * from binding to a controller.
> */
> the_device = dev;
> + get_dev(dev);
So why is this here?
Alan Stern
> rc = 0;
> goto Done;
>
> --
> 2.43.0
>
>
^ permalink raw reply [flat|nested] 2+ messages in thread
end of thread, other threads:[~2026-08-28 14:00 UTC | newest]
Thread overview: 2+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-08-28 6:18 [PATCH usb-next v1] USB: gadgetfs: Fix use-after-free in gadgetfs_kill_sb Rafael Alejandro Diaz Cruz
2026-08-28 14:00 ` Alan Stern
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.