From mboxrd@z Thu Jan 1 00:00:00 1970 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: base64 Subject: usb: host: xhci_debugfs: Fix a null pointer dereference in xhci_debugfs_create_endpoint() From: Jia-Ju Bai Message-Id: Date: Sat, 4 May 2019 15:30:53 +0800 To: Greg KH Cc: mathias.nyman@intel.com, linux-usb@vger.kernel.org, linux-kernel@vger.kernel.org List-ID: T24gMjAxOS81LzQgMTQ6MzMsIEdyZWcgS0ggd3JvdGU6Cj4gT24gU2F0LCBNYXkgMDQsIDIwMTkg YXQgMTE6Mzc6NDhBTSArMDgwMCwgSmlhLUp1IEJhaSB3cm90ZToKPj4gSW4geGhjaV9kZWJ1Z2Zz X2NyZWF0ZV9zbG90KCksIGt6YWxsb2MoKSBjYW4gZmFpbCBhbmQKPj4gZGV2LT5kZWJ1Z2ZzX3By aXZhdGUgd2lsbCBiZSBOVUxMLgo+PiBJbiB4aGNpX2RlYnVnZnNfY3JlYXRlX2VuZHBvaW50KCks IGRldi0+ZGVidWdmc19wcml2YXRlIGlzIHVzZWQgd2l0aG91dAo+PiBhbnkgbnVsbC1wb2ludGVy IGNoZWNrLCBhbmQgY2FuIGNhdXNlIGEgbnVsbCBwb2ludGVyIGRlcmVmZXJlbmNlLgo+Pgo+PiBU byBmaXggdGhpcyBidWcsIGEgbnVsbC1wb2ludGVyIGNoZWNrIGlzIGFkZGVkIGluCj4+IHhoY2lf ZGVidWdmc19jcmVhdGVfZW5kcG9pbnQoKS4KPj4KPj4gVGhpcyBidWcgaXMgZm91bmQgYnkgYSBy dW50aW1lIGZ1enppbmcgdG9vbCBuYW1lZCBGSVpaRVIgd3JpdHRlbiBieSB1cy4KPj4KPj4gU2ln bmVkLW9mZi1ieTogSmlhLUp1IEJhaSA8YmFpamlhanUxOTkwQGdtYWlsLmNvbT4KPiBWZXJ5IHJh cmUgY2FzZSwgYnV0IG5pY2UgZml4LiAgWW91IHNob3VsZCBwdXQgInBvdGVudGlhbCIgaW4geW91 cgo+IHN1YmplY3QgbGluZSBhcyB0aGlzIGlzIHNvbWV0aGluZyB0aGF0IG5vIG9uZSBzaG91bGQg ZXZlciBoaXQgOikKCk9rYXksIEdyZWcsIHRoYW5rcyBmb3IgdGhpcyBhZHZpY2UgOikKCgpCZXN0 IHdpc2hlcywKSmlhLUp1IEJhaQo= From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org X-Spam-Level: X-Spam-Status: No, score=-3.8 required=3.0 tests=DKIM_SIGNED,DKIM_VALID, DKIM_VALID_AU,FREEMAIL_FORGED_FROMDOMAIN,FREEMAIL_FROM, HEADER_FROM_DIFFERENT_DOMAINS,MAILING_LIST_MULTI,SIGNED_OFF_BY,SPF_PASS autolearn=unavailable autolearn_force=no version=3.4.0 Received: from mail.kernel.org (mail.kernel.org [198.145.29.99]) by smtp.lore.kernel.org (Postfix) with ESMTP id 71FA8C46470 for ; Sat, 4 May 2019 07:31:05 +0000 (UTC) Received: from vger.kernel.org (vger.kernel.org [209.132.180.67]) by mail.kernel.org (Postfix) with ESMTP id 40FD720859 for ; Sat, 4 May 2019 07:31:05 +0000 (UTC) Authentication-Results: mail.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="ge81vD4k" Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1726258AbfEDHa6 (ORCPT ); Sat, 4 May 2019 03:30:58 -0400 Received: from mail-pl1-f195.google.com ([209.85.214.195]:38944 "EHLO mail-pl1-f195.google.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1726178AbfEDHa6 (ORCPT ); Sat, 4 May 2019 03:30:58 -0400 Received: by mail-pl1-f195.google.com with SMTP id e92so3805885plb.6; Sat, 04 May 2019 00:30:58 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=subject:to:cc:references:from:message-id:date:user-agent :mime-version:in-reply-to:content-transfer-encoding:content-language; bh=EwweiBCfeJ/cKJj/kqdEZt5KyrfkU7tGiFKFsGG/ynM=; b=ge81vD4ktejLRqGTFd9opeJ/bQJ81OT/HtLTZzaN081dOnSgLk/b4K2qCWI3DuNOFL hfc4X2tNsk30NvPs1jLB+XcdWr20To+HKWCNte0d21hYM1a1a3ttIoQiVLyjK5uLvCxa oTMnOHFyaCUcu/vlLC+M1HGJnrERA1RECs9fwpDdoE60z3e16wsUl42bRcglYlOSKszs eMeuMwtXjpPLHTUCkZfhYQZ5sbBS//NQ9P3FMM3GVL5EKiucHHGacmZT3j9U8Znnlcyq LWl3+W5m//QptC1QEeeWS73cG4dRjlK94XBzIDJ5oXfwDlnwtOIu5KfjbTkVD5xBBC1Z 4l7Q== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:subject:to:cc:references:from:message-id:date :user-agent:mime-version:in-reply-to:content-transfer-encoding :content-language; bh=EwweiBCfeJ/cKJj/kqdEZt5KyrfkU7tGiFKFsGG/ynM=; b=iZZKs1gOGgDXJ8tUZ9GQlpebNb+0uqHRZ4jjug/8Qg0GaW8opuuXjB/M3bLPrdLQ1P yMXDKBem3JXgMlokH5Mr9Y6JX2v8EUnVJkQjanI5RcAOHcKmxgUhiCX0T+/qSjESrv6u Fb0KGLVgEBtyV7qfr8oRQa1Nfu3++/4q/A2wrGxVSYHTNlftJTG+Bke0bOSVyq/47LBS pRUXIb3fSq0zIVAf2N10APx+pBd/21wNadI8zPPnofGXCcb0mRtuTlwHLKYNKouS3b91 vA0dFEX3Iy5YHfEYwGWGkkt+76AtqGIoOXfp+Vg92py8/e11ZI9OUzswIyneawKtKx/m foGA== X-Gm-Message-State: APjAAAU8h27rtCdSZfE3wczdSrW/i6jpdwsDVIOHAUpC4wn1hIqfVlr6 YMZGn5tJCDnocs4Yys4In58zcK/t X-Google-Smtp-Source: APXvYqwQuHJjllCV9Zt2vI8TIT03UGNOh62eAd7zsJvPGi1g80RArlbgZHfIrLj+U/y4d+XrSyu0jg== X-Received: by 2002:a17:902:2702:: with SMTP id c2mr16524210plb.277.1556955057920; Sat, 04 May 2019 00:30:57 -0700 (PDT) Received: from ?IPv6:2402:f000:1:1501:200:5efe:166.111.71.43? ([2402:f000:1:1501:200:5efe:a66f:472b]) by smtp.gmail.com with ESMTPSA id j6sm5711397pfe.107.2019.05.04.00.30.55 (version=TLS1_2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Sat, 04 May 2019 00:30:56 -0700 (PDT) Subject: Re: [PATCH] usb: host: xhci_debugfs: Fix a null pointer dereference in xhci_debugfs_create_endpoint() To: Greg KH Cc: mathias.nyman@intel.com, linux-usb@vger.kernel.org, linux-kernel@vger.kernel.org References: <20190504033748.17964-1-baijiaju1990@gmail.com> <20190504063340.GA26311@kroah.com> From: Jia-Ju Bai Message-ID: Date: Sat, 4 May 2019 15:30:53 +0800 User-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Thunderbird/52.2.0 MIME-Version: 1.0 In-Reply-To: <20190504063340.GA26311@kroah.com> Content-Type: text/plain; charset="UTF-8"; format="flowed" Content-Transfer-Encoding: 7bit Content-Language: en-US Sender: linux-usb-owner@vger.kernel.org Precedence: bulk List-ID: X-Mailing-List: linux-usb@vger.kernel.org Message-ID: <20190504073053.a-ZXI6vHiDTsbRDpi1vd2aQeSH4C9G6tId-V2XA7Zmo@z> On 2019/5/4 14:33, Greg KH wrote: > On Sat, May 04, 2019 at 11:37:48AM +0800, Jia-Ju Bai wrote: >> In xhci_debugfs_create_slot(), kzalloc() can fail and >> dev->debugfs_private will be NULL. >> In xhci_debugfs_create_endpoint(), dev->debugfs_private is used without >> any null-pointer check, and can cause a null pointer dereference. >> >> To fix this bug, a null-pointer check is added in >> xhci_debugfs_create_endpoint(). >> >> This bug is found by a runtime fuzzing tool named FIZZER written by us. >> >> Signed-off-by: Jia-Ju Bai > Very rare case, but nice fix. You should put "potential" in your > subject line as this is something that no one should ever hit :) Okay, Greg, thanks for this advice :) Best wishes, Jia-Ju Bai