* [PATCH usb-next v2] USB: gadget: Fix UAF in gadgetfs_fill_super()
@ 2026-09-05 0:35 Rafael Alejandro Diaz Cruz
0 siblings, 0 replies; only message in thread
From: Rafael Alejandro Diaz Cruz @ 2026-09-05 0:35 UTC (permalink / raw)
To: gregkh
Cc: linux-usb, stable, linux-kernel, Rafael Alejandro Diaz Cruz,
syzbot+4a5c87a01894ca37f25c, Alan Stern
When gadgetfs_fill_super() fails, it's error path calls
put_dev() which drops refcount inside the_device to 0
and frees the objet. But the_device pointer is not
cleared, leading to point at freed memory.
VFS will then call gadgetfs_kill_sb() after mount
failure leading to put_dev() to be called on the
already freed pointer.
Fix by setting the_device = NULL during error path
before calling put_dev() inside gadgetfs_fill_super()
so that gadgetfs_kill_sb() skips put_dev().
Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
Reported-by: syzbot+4a5c87a01894ca37f25c@syzkaller.appspotmail.com
Link: https://syzkaller.appspot.com/bug?extid=4a5c87a01894ca37f25c
Signed-off-by: Rafael Alejandro Diaz Cruz <rafad900@gmail.com>
Reviewed-by: Alan Stern <stern@rowland.harvard.edu>
---
Changes from v1:
Removed unecessary reference to syzkaller in the description.
Added Reviewed-by: tag.
drivers/usb/gadget/legacy/inode.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/drivers/usb/gadget/legacy/inode.c b/drivers/usb/gadget/legacy/inode.c
index d87a8ab51510..3e2bce7543d4 100644
--- a/drivers/usb/gadget/legacy/inode.c
+++ b/drivers/usb/gadget/legacy/inode.c
@@ -2059,6 +2059,7 @@ gadgetfs_fill_super (struct super_block *sb, struct fs_context *fc)
rc = gadgetfs_create_file(sb, CHIP, dev, &ep0_operations);
if (rc) {
put_dev(dev);
+ the_device = NULL;
goto Enomem;
}
--
2.43.0
^ permalink raw reply related [flat|nested] only message in thread
only message in thread, other threads:[~2026-09-05 0:36 UTC | newest]
Thread overview: (only message) (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-05 0:35 [PATCH usb-next v2] USB: gadget: Fix UAF in gadgetfs_fill_super() Rafael Alejandro Diaz Cruz
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.