From: "gregkh@linuxfoundation.org" <gregkh@linuxfoundation.org>
To: Markus Mikonsaari <markus.mikonsaari@gofore.com>
Cc: "valentina.manea.m@gmail.com" <valentina.manea.m@gmail.com>,
"shuah@kernel.org" <shuah@kernel.org>,
"linux-usb@vger.kernel.org" <linux-usb@vger.kernel.org>,
"i@zenithal.me" <i@zenithal.me>
Subject: Re: [PATCH] usbip: fix number_of_packets corruption for non-isochronous transfers
Date: Wed, 9 Sep 2026 10:46:24 +0200 [thread overview]
Message-ID: <2026090926-blunt-lushness-1012@gregkh> (raw)
In-Reply-To: <GV2PR05MB10593A82388157FCA3397879898B02@GV2PR05MB10593.eurprd05.prod.outlook.com>
On Wed, Sep 09, 2026 at 08:09:48AM +0000, Markus Mikonsaari wrote:
> In the USB/IP protocol, number_of_packets is set to 0xffffffff (-1)
> by sender when the transfer is not isochronous.
> usbip_pack_pdu() copies this wire value into urb->number_of_packets
> unconditionally.
>
> A host controller driver may compute the iso_frame_desc memory requirements
> directly from number_of_packets without independently validating it
> against the pipe type which produces an undersized allocation.
What driver does that?
> On dwc_otg, this manifests as a slab-out-of-bounds write in
> dwc_otg_hcd_urb_alloc() during a USB/IP attach involving a non-isochronous
> transfer.
>
> Correct the number_of_packets to the value the urb was actually
> allocated for immediately after usbip_pack_pdu() overwrites it.
>
> Signed-off-by: Markus Mikonsaari <markus.mikonsaari@gofore.com>
How was this found and tested?
And did you forget an Assisted-by: tag?
> ---
> drivers/usb/usbip/stub_rx.c | 13 +++++++++++++
> 1 file changed, 13 insertions(+)
>
> diff --git a/drivers/usb/usbip/stub_rx.c b/drivers/usb/usbip/stub_rx.c
> index 1e9ae578810d..baf511024da2 100644
> --- a/drivers/usb/usbip/stub_rx.c
> +++ b/drivers/usb/usbip/stub_rx.c
> @@ -567,6 +567,17 @@ static void stub_recv_cmd_submit(struct stub_device *sdev,
> }
>
> usbip_pack_pdu(pdu, priv->urbs[0], USBIP_CMD_SUBMIT, 0);
> + /*
> + * number_of_packets is set to -1 by the sender when the transfer is
> + * not isochronous.
> + * usbip_pack_pdu() copies this wire value into urb->number_of_packets
> + * unconditionally, instead of using the correct value in np which was
> + * used to allocate the urb above. For a non-isochronous transfer this
> + * leaves number_of_packets at -1 which downstream consumers of this urb
> + * like host-controller drivers use to allocate iso_frame_desc storage.
> + * Restore it to what the urb was actually allocated for.
> + */
> + priv->urbs[0]->number_of_packets = np;
> } else {
> for_each_sg(sgl, sg, nents, i) {
> priv->urbs[i] = usb_alloc_urb(0, GFP_KERNEL);
> @@ -579,6 +590,8 @@ static void stub_recv_cmd_submit(struct stub_device *sdev,
> usbip_pack_pdu(pdu, priv->urbs[i], USBIP_CMD_SUBMIT, 0);
> priv->urbs[i]->transfer_buffer = sg_virt(sg);
> priv->urbs[i]->transfer_buffer_length = sg->length;
> + /* see comment about number_of_packets above */
What comment? That's not the best way to do this...
thanks,
greg k-h
next prev parent reply other threads:[~2026-09-09 8:46 UTC|newest]
Thread overview: 4+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-09 8:09 [PATCH] usbip: fix number_of_packets corruption for non-isochronous transfers Markus Mikonsaari
2026-09-09 8:46 ` gregkh [this message]
2026-09-09 10:38 ` Markus Mikonsaari
2026-09-09 12:06 ` [PATCH v2] usbip: fix number_of_packets for non-iso transfers Markus Mikonsaari
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=2026090926-blunt-lushness-1012@gregkh \
--to=gregkh@linuxfoundation.org \
--cc=i@zenithal.me \
--cc=linux-usb@vger.kernel.org \
--cc=markus.mikonsaari@gofore.com \
--cc=shuah@kernel.org \
--cc=valentina.manea.m@gmail.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.