From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 2DC944E7806; Thu, 17 Sep 2026 15:59:05 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789660746; cv=none; b=bAAOKZ6VhZfeqJui1BWzHgzwqdSFdIK90OUrL4oVPtYX99ma0yXa6pTPW0wImAjDhCqr889N4a43WjdkHCBG+SkIF4zhAgha3nReTxzaRtRtEiNGoXFD31rpM9pvx7Zfid2iz+mwFNtb/cibPm99/jklL4jbQPZg8j9IEhj/IQ0= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789660746; c=relaxed/simple; bh=iueXkBz53hPk4E13MUhbfZoY0hTwhExdafJuWvsQCk0=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=kytK5Pi+l5EZdyTQS4uMbsYGYNYfRwxJ99acT29vQrCLsH4woHumptQtw1lvTZww/xyZulqQ6eAzGxr2VBNGZNs9EPLNYvz27IcFsCB3NDfz7Xh7XKygAJYx7gKmv6OzQzCNgDzm3h0ulHY7DVwysBdOIgdxVj7iSi2YxoFHTk0= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=JP0g2A4I; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="JP0g2A4I" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 8604D1F000FF; Thu, 17 Sep 2026 15:59:04 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxfoundation.org; s=korg; t=1789660745; bh=OAp3PjnWZnD6Y3UEG1L8MlgkFQJcwLfmYv9u6hhKENY=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=JP0g2A4IA/OUfIZ4opMipLJwA0X7IP0NqN0KDlZ5hFCTO4H4/bE6ztjlorhll3Hfx KfROo1tyTAH5kisWNanbaO4nD14Kzs7uS7eucPyP1klxk0ZmPk+fU6GTH13cLdhsWd aA3PpSY+fuPhxbOASJGbUS/DDzo96ZGHXnny5RSs= From: Greg Kroah-Hartman To: stable@vger.kernel.org Cc: Greg Kroah-Hartman , patches@lists.linux.dev, Gary Guo , Sasha Levin Subject: [PATCH 7.2 694/733] usb: xusbatm: dont rely on id table pointer arithmetic Date: Thu, 17 Sep 2026 16:16:42 +0100 Message-ID: <20260917151410.118917957@linuxfoundation.org> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260917151350.597953846@linuxfoundation.org> References: <20260917151350.597953846@linuxfoundation.org> User-Agent: quilt/0.69 X-stable: review X-Patchwork-Hint: ignore Precedence: bulk X-Mailing-List: patches@lists.linux.dev List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit 7.2-stable review patch. If anyone has any objections, please let me know. ------------------ From: Gary Guo [ Upstream commit eb6cd6d3d8abeac5d7e8251b898067184afdad8a ] The current code is broken when dynamic ID is involved; in such cases usb_device_id parameter of probe lives on the heap and the pointer arithmetic will get an index that is wildly out of bound. xusbatm initialize the USB device IDs dynamically so it can just use driver_info too. Even with conversion, xusbatm still cannot support dynamic IDs, so also set no_dynamic_id. Signed-off-by: Gary Guo Link: https://patch.msgid.link/20260707-usb_dyn_id_uaf-v2-6-632dcf3adfba@garyguo.net Signed-off-by: Greg Kroah-Hartman Signed-off-by: Sasha Levin --- drivers/usb/atm/xusbatm.c | 6 ++++-- 1 file changed, 4 insertions(+), 2 deletions(-) diff --git a/drivers/usb/atm/xusbatm.c b/drivers/usb/atm/xusbatm.c index 0befbf63d1cc8..5c1e1f5215555 100644 --- a/drivers/usb/atm/xusbatm.c +++ b/drivers/usb/atm/xusbatm.c @@ -79,7 +79,7 @@ static int xusbatm_bind(struct usbatm_data *usbatm, struct usb_interface *intf, const struct usb_device_id *id) { struct usb_device *usb_dev = interface_to_usbdev(intf); - int drv_ix = id - xusbatm_usb_ids; + int drv_ix = id->driver_info; int rx_alt = rx_altsetting[drv_ix]; int tx_alt = tx_altsetting[drv_ix]; struct usb_interface *rx_intf = xusbatm_find_intf(usb_dev, rx_alt, rx_endpoint[drv_ix]); @@ -168,7 +168,8 @@ static struct usb_driver xusbatm_usb_driver = { .name = xusbatm_driver_name, .probe = xusbatm_usb_probe, .disconnect = usbatm_usb_disconnect, - .id_table = xusbatm_usb_ids + .id_table = xusbatm_usb_ids, + .no_dynamic_id = 1, }; static int __init xusbatm_init(void) @@ -190,6 +191,7 @@ static int __init xusbatm_init(void) xusbatm_usb_ids[i].match_flags = USB_DEVICE_ID_MATCH_DEVICE; xusbatm_usb_ids[i].idVendor = vendor[i]; xusbatm_usb_ids[i].idProduct = product[i]; + xusbatm_usb_ids[i].driver_info = i; xusbatm_drivers[i].driver_name = xusbatm_driver_name; xusbatm_drivers[i].bind = xusbatm_bind; -- 2.53.0