From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 98BAC513572; Wed, 30 Sep 2026 17:37:31 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790789852; cv=none; b=AqppBnSi+OtG49Xzb65Of8rL1cxQG7Kn0urkLv4Aha/fFE7iM3a0BayPZE6+do+VYizopCLjKlBcIXsIip6D7d1LHvf0DujFn6f6jxbZ6JSG4IAbGVUJbpQNrpCGXjE2/9s0TO+waEnND5hA+TkBp8Pq4kpyuTnFIBgDTwZL0MU= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790789852; c=relaxed/simple; bh=V7a22emrDITKItwG/VxWmUgQEz8Pga/XzIlVAdyreM4=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version:Content-Type; b=Rc131QxN0BUNxAOImhA7VnGpM3U+Sf16qWvrP0Az+FfMVepxA0GKt2Er8qD8q2qIH6oBHuUSKisduu/7DHNpv+JbRNtsfbM2JV0En9oXvBNeoZaLfhM3M77/5wxuLHQn36qlN1qka+xTrMgcwRjif5nwOj2ftUPARpVp634jwLk= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=HeVz2qXA; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="HeVz2qXA" Received: by smtp.kernel.org (Postfix) with ESMTPSA id F2FA61F000FF; Wed, 30 Sep 2026 17:37:30 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxfoundation.org; s=korg; t=1790789851; bh=UUT2WtW76xcJEXanPhdrbyMVFK0fIqDQFBh68i6Ghzw=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=HeVz2qXAhaB5UzG5GrShfkAZr+nkSSdIhDky3wSW4Q9W1qJ2auHrja3rz/WXv3yuQ tnmgCfOetb4l4iqgw+SAZH6O5qCmHikvJGZitTW+UbSFLgbQ+u/njDvOYr/RVsa+3w hmVOaqa+O532/R+pJlUy/UeX0utVbT7zfnwGZQmI= From: Greg Kroah-Hartman To: stable@vger.kernel.org Cc: Greg Kroah-Hartman , patches@lists.linux.dev, syzbot+791be35f1fbcc85d06d7@syzkaller.appspotmail.com, stable , Jeffin Philip , Alan Stern , Sasha Levin Subject: [PATCH 6.12 622/877] usb: gadget: f_mass_storage: fix null pointer dereference in fsg_common_set_num_buffers() Date: Wed, 30 Sep 2026 17:25:33 +0200 Message-ID: <20260930152428.072761270@linuxfoundation.org> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260930152414.738996857@linuxfoundation.org> References: <20260930152414.738996857@linuxfoundation.org> User-Agent: quilt/0.69 X-stable: review X-Patchwork-Hint: ignore Precedence: bulk X-Mailing-List: patches@lists.linux.dev List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit 6.12-stable review patch. If anyone has any objections, please let me know. ------------------ From: Jeffin Philip [ Upstream commit 2c0f5ca48674a5b5f9fa4a9c3325aa48053af0bc ] Previously fsg_num_buffers_validate() was removed as it was not necessary due to Kconfig setting the limits for n from 2 to 256 with default as 2. However, setting the page content in such a way that kstrtou8() reflects n value as either 0 or 1 bypasses these restrictions leading to a null pointer dereference if n is 0. Fix this by adding a check for n < 2 and returning -EINVAL if n is either 0 or 1 consistent with Kconfig logic. Reported-by: syzbot+791be35f1fbcc85d06d7@syzkaller.appspotmail.com Closes: https://syzkaller.appspot.com/bug?extid=791be35f1fbcc85d06d7 Fixes: fe5a6c48fd95 ("usb: gadget: storage: get rid of fsg_num_buffers_validate()") Cc: stable Signed-off-by: Jeffin Philip Acked-by: Alan Stern Link: https://patch.msgid.link/20260818035904.10324-1-jeffinphilip14@gmail.com Signed-off-by: Greg Kroah-Hartman [ adjusted context to retain the branch’s existing kcalloc() call instead of kzalloc_objs(). ] Signed-off-by: Sasha Levin Signed-off-by: Greg Kroah-Hartman --- drivers/usb/gadget/function/f_mass_storage.c | 3 +++ 1 file changed, 3 insertions(+) --- a/drivers/usb/gadget/function/f_mass_storage.c +++ b/drivers/usb/gadget/function/f_mass_storage.c @@ -2748,6 +2748,9 @@ int fsg_common_set_num_buffers(struct fs struct fsg_buffhd *bh, *buffhds; int i; + if (n < 2) + return -EINVAL; + buffhds = kcalloc(n, sizeof(*buffhds), GFP_KERNEL); if (!buffhds) return -ENOMEM;