From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-oi1-f200.google.com (mail-oi1-f200.google.com [209.85.167.200]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 352AA2E612E for ; Tue, 11 Aug 2026 05:21:14 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.167.200 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786425675; cv=none; b=cjdYXUXtp/M6uqmNtxFuawFVoKZLSvMZSZtEU/zYFPKuAJNWYu7gDASi2Zuk41GhGxTz3XEwumMzRwQ+DK5XHzncMRVcSG+U5dYrGk4vg6P6Jkpu/amSf2PRYStBdsMVBuMfEh+wH0OpFZzQJyOcvaddBVmUo+US9ByUhAEY7Mc= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786425675; c=relaxed/simple; bh=NX8V8QsHeWCZiN+/0un9LC0GFe7HGk60oeaNdWX3Y2s=; h=MIME-Version:Date:In-Reply-To:Message-ID:Subject:From:To: Content-Type; b=tEtGBj/+duHD2gGiOBUh0oWyHlmftagNay//kKfcOuJVY1UQaDCzi/Nxbmpin1RZ1Me0igvsVZbtHpohMXtflUAb3SmLlDzL7ix6T1NIob5GXZWXbKoQ6Nj2ITXolvCvE5vvA6Xul/FRLJbotnh85v7iLtfWBdflZe37b54CXJI= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=fail (p=none dis=none) header.from=syzkaller.appspotmail.com; spf=pass smtp.mailfrom=M3KW2WVRGUFZ5GODRSRYTGD7.apphosting.bounces.google.com; arc=none smtp.client-ip=209.85.167.200 Authentication-Results: smtp.subspace.kernel.org; dmarc=fail (p=none dis=none) header.from=syzkaller.appspotmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=M3KW2WVRGUFZ5GODRSRYTGD7.apphosting.bounces.google.com Received: by mail-oi1-f200.google.com with SMTP id 5614622812f47-4ab4af22d09so2851915b6e.0 for ; Mon, 10 Aug 2026 22:21:13 -0700 (PDT) X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1786425673; x=1787030473; h=content-type:to:from:subject:message-id:in-reply-to:date :mime-version:x-gm-message-state:from:to:cc:subject:date:message-id :reply-to:content-type; bh=RRwsTxWmLZPfK6Y0cSu9KPlr8l0sMUGXhQmb5yGl9XI=; b=nzbjcZ4GdZVoEHxKBxW6Kb3Le9HNzfHoiHQUxiC1MnJmoSunKFScjd6m4IhENgDxT6 KvvFa/6ZvorFCIPFeg0jkjvhMabqsqbETI6tk9NezhPXr59NzUA6w91ZVTvu7lq08I6c cSsuW0jsh0JpnwEhURlXdqU7QDD7+IOuZeMIU1hQBJRZnMnhzjZOLuZ0g46hxI+q4sKL 3jIsX1SaDvIDhBKPluipSmmVsKnLCCBh6jjajYkL+cxTYqNLgW2kEwrSvLfXG2yVTW3m GMSs1rtUMEmnW23v2AoRQ0hMmF+tfvTl5OfdMWj+mo1pw/UA9Ywl4icE4AOcOHWdKis9 amFw== X-Gm-Message-State: AOJu0YwdC6Wo/HoZRnuQ8y02A0Js/8IbJSnUC0TZIBlBh7Z/wTnsorQ5 Ih0Hr40HUoz86xS/D0z/bFq8I40Ht0ikfvMEENX6fquYC16bGjw2hlldl84AzF900BJrVTGNBDn tFP+IaHfLtBBsS4EwTsTfZs8Wjb+8tGgSNTEJRqfyVqMacyjbde+ApqC918Q= Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 X-Received: by 2002:a05:6808:30a1:b0:49a:8f0d:cdd2 with SMTP id 5614622812f47-4b1fd64777amr569244b6e.5.1786425673187; Mon, 10 Aug 2026 22:21:13 -0700 (PDT) Date: Mon, 10 Aug 2026 22:21:13 -0700 In-Reply-To: <6a78d160.01d0871a.3a0d52.0090.GAE@google.com> X-Google-Appengine-App-Id: s~syzkaller X-Google-Appengine-App-Id-Alias: syzkaller Message-ID: <6a7ab149.01d0871a.3a0d52.00bf.GAE@google.com> Subject: Forwarded: Re: WARNING: refcount bug in trace_suspend_resume (2) From: syzbot To: linux-kernel@vger.kernel.org, syzkaller-bugs@googlegroups.com Content-Type: text/plain; charset="UTF-8" For archival purposes, forwarding an incoming command email to linux-kernel@vger.kernel.org, syzkaller-bugs@googlegroups.com. *** Subject: Re: WARNING: refcount bug in trace_suspend_resume (2) Author: khiemtranzo532001@gmail.com #syz test: https://git.kernel.org/pub/scm/linux/kernel/git/gregkh/usb.git usb-next >From 7793c39a61d25917c6047a9b7fb4d666bcc2b227 Mon Sep 17 00:00:00 2001 From: Nguyen Quang Le Kien Date: Tue, 11 Aug 2026 12:46:21 +0800 Subject: [PATCH] usb: gadget: fix refcount underflow in gadgetfs_bind() error path gadgetfs_bind() calls get_dev() only on the success path, but gadgetfs_unbind() called from the enomem error label unconditionally calls put_dev(). When bind fails (e.g. ENOMEM), put_dev() fires without a matching get_dev(), leaving the refcount unbalanced. A subsequent close of the ep0 file descriptor calls dev_release() -> put_dev() which hits zero and frees the object; then gadgetfs_kill_sb() calls put_dev(the_device) again on the already-freed pointer, triggering a refcount underflow and use-after-free. Fix by calling get_dev() at the start of gadgetfs_bind(), before any error path that invokes gadgetfs_unbind(), so the reference is always balanced regardless of whether bind succeeds or fails. Reported-by: syzbot+8496ab5e117502750445@syzkaller.appspotmail.com Closes: https://syzkaller.appspot.com/bug?extid=8496ab5e117502750445 Signed-off-by: Nguyen Quang Le Kien --- drivers/usb/gadget/legacy/inode.c | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/drivers/usb/gadget/legacy/inode.c b/drivers/usb/gadget/legacy/inode.c index d87a8ab51..d6551a4ce 100644 --- a/drivers/usb/gadget/legacy/inode.c +++ b/drivers/usb/gadget/legacy/inode.c @@ -1682,6 +1682,8 @@ static int gadgetfs_bind(struct usb_gadget *gadget, dev->gadget = gadget; gadget->ep0->driver_data = dev; + get_dev (dev); + /* preallocate control response and buffer */ dev->req = usb_ep_alloc_request (gadget->ep0, GFP_KERNEL); if (!dev->req) @@ -1696,7 +1698,6 @@ static int gadgetfs_bind(struct usb_gadget *gadget, spin_lock_irq(&dev->lock); dev->state = STATE_DEV_UNCONNECTED; spin_unlock_irq(&dev->lock); - get_dev (dev); return 0; enomem: -- 2.34.1