All of lore.kernel.org
 help / color / mirror / Atom feed
* [PATCH] usbip: fix number_of_packets corruption for non-isochronous transfers
@ 2026-09-09  8:09 Markus Mikonsaari
  2026-09-09  8:46 ` gregkh
  0 siblings, 1 reply; 4+ messages in thread
From: Markus Mikonsaari @ 2026-09-09  8:09 UTC (permalink / raw)
  To: valentina.manea.m@gmail.com, shuah@kernel.org,
	gregkh@linuxfoundation.org
  Cc: linux-usb@vger.kernel.org, i@zenithal.me

In the USB/IP protocol, number_of_packets is set to 0xffffffff (-1)
by sender when the transfer is not isochronous.
usbip_pack_pdu() copies this wire value into urb->number_of_packets
unconditionally.

A host controller driver may compute the iso_frame_desc memory requirements
directly from number_of_packets without independently validating it
against the pipe type which produces an undersized allocation.
On dwc_otg, this manifests as a slab-out-of-bounds write in
dwc_otg_hcd_urb_alloc() during a USB/IP attach involving a non-isochronous
transfer.

Correct the number_of_packets to the value the urb was actually
allocated for immediately after usbip_pack_pdu() overwrites it.

Signed-off-by: Markus Mikonsaari <markus.mikonsaari@gofore.com>
---
 drivers/usb/usbip/stub_rx.c | 13 +++++++++++++
 1 file changed, 13 insertions(+)

diff --git a/drivers/usb/usbip/stub_rx.c b/drivers/usb/usbip/stub_rx.c
index 1e9ae578810d..baf511024da2 100644
--- a/drivers/usb/usbip/stub_rx.c
+++ b/drivers/usb/usbip/stub_rx.c
@@ -567,6 +567,17 @@ static void stub_recv_cmd_submit(struct stub_device *sdev,
 		}
 
 		usbip_pack_pdu(pdu, priv->urbs[0], USBIP_CMD_SUBMIT, 0);
+		/*
+		 * number_of_packets is set to -1 by the sender when the transfer is
+		 * not isochronous.
+		 * usbip_pack_pdu() copies this wire value into urb->number_of_packets
+		 * unconditionally, instead of using the correct value in np which was
+		 * used to allocate the urb above. For a non-isochronous transfer this
+		 * leaves number_of_packets at -1 which downstream consumers of this urb
+		 * like host-controller drivers use to allocate iso_frame_desc storage.
+		 * Restore it to what the urb was actually allocated for.
+		 */
+		priv->urbs[0]->number_of_packets = np;
 	} else {
 		for_each_sg(sgl, sg, nents, i) {
 			priv->urbs[i] = usb_alloc_urb(0, GFP_KERNEL);
@@ -579,6 +590,8 @@ static void stub_recv_cmd_submit(struct stub_device *sdev,
 			usbip_pack_pdu(pdu, priv->urbs[i], USBIP_CMD_SUBMIT, 0);
 			priv->urbs[i]->transfer_buffer = sg_virt(sg);
 			priv->urbs[i]->transfer_buffer_length = sg->length;
+			/* see comment about number_of_packets above */
+			priv->urbs[i]->number_of_packets = 0;
 		}
 		priv->sgl = sgl;
 	}
-- 
2.55.0


^ permalink raw reply related	[flat|nested] 4+ messages in thread

end of thread, other threads:[~2026-09-09 12:06 UTC | newest]

Thread overview: 4+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-09  8:09 [PATCH] usbip: fix number_of_packets corruption for non-isochronous transfers Markus Mikonsaari
2026-09-09  8:46 ` gregkh
2026-09-09 10:38   ` Markus Mikonsaari
2026-09-09 12:06   ` [PATCH v2] usbip: fix number_of_packets for non-iso transfers Markus Mikonsaari

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.