From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id A2CF843D4EE; Tue, 21 Jul 2026 21:59:03 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784671144; cv=none; b=WA3G0Li936RxkXbbQ+I1L+VfYHVgnLTDGlZVcMGX6atlyvKU1tQyDlFvzsny9XC5qEeI366TOB9Z3+OWYSu1sDIagWtq3ZrzitbLvSU0qFgbLue8kmgFtBf5gOIdO0oY2crR3dRfEPp1P2WacVnjv0v1H8jn2NvcY0j640ZjKMs= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1784671144; c=relaxed/simple; bh=YyqFGc7aOiNmwJUj9etauh1AqB2CoRgUjou+gGZ2ku4=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=JJUBrclJCtS1s3AB451BaaA42drkXu3j+fJv+IM8Y6F5Rv/TnvMqMPeiSlxeQUYyXe0gX1sxvxsPotj0ynlfRD1gggAQHPK1xqI95F6SbsTT62ENnQ4hmRxsiu+fINC/HW5lAm4DJf0ASYSpXuaimTpN+UweJc75exhIoIwVZqM= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=zb7xWWBn; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="zb7xWWBn" Received: by smtp.kernel.org (Postfix) with ESMTPSA id D1F761F000E9; Tue, 21 Jul 2026 21:59:02 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxfoundation.org; s=korg; t=1784671143; bh=9ZZpVFmB/U0dKv64x0iuf4cGlduXERZ7v0zfNAiiSvU=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=zb7xWWBnV6qOBbm+3JFwuHw6fd6+Vc5kim331O11VC/+e15iqsryol/Jd4tkQ90CT ydswCaSRF61g7JHXq76qsUDAL3JCxFnrG/gTyoSkrwMrhmHYTgXALcaXMQFqMVHlWh vce7+aQjT/WGW1bViY3ppgK/PtWrjKhimACyjWLk= From: Greg Kroah-Hartman To: stable@vger.kernel.org Cc: Greg Kroah-Hartman , patches@lists.linux.dev, syzbot+ad2aac2febc3bedf0962@syzkaller.appspotmail.com, stable , Johan Hovold Subject: [PATCH 5.15 136/843] USB: iowarrior: fix use-after-free on disconnect Date: Tue, 21 Jul 2026 17:16:11 +0200 Message-ID: <20260721152409.075361822@linuxfoundation.org> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260721152405.946368001@linuxfoundation.org> References: <20260721152405.946368001@linuxfoundation.org> User-Agent: quilt/0.69 X-stable: review X-Patchwork-Hint: ignore Precedence: bulk X-Mailing-List: patches@lists.linux.dev List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit 5.15-stable review patch. If anyone has any objections, please let me know. ------------------ From: Johan Hovold commit bc0e4f16c44e50daa0b1ea729934baa3b4815dee upstream. Submitted write URBs are not stopped on close() and therefore need to be stopped unconditionally on disconnect() to avoid use-after-free in the completion handler. Fixes: b5f8d46867ca ("USB: iowarrior: fix use-after-free after driver unbind") Fixes: 946b960d13c1 ("USB: add driver for iowarrior devices.") Reported-by: syzbot+ad2aac2febc3bedf0962@syzkaller.appspotmail.com Link: https://lore.kernel.org/all/6a0ce39b.170a0220.39a13.0007.GAE@google.com/ Cc: stable Signed-off-by: Johan Hovold Link: https://patch.msgid.link/20260523170523.1074563-1-johan@kernel.org Signed-off-by: Greg Kroah-Hartman --- drivers/usb/misc/iowarrior.c | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) --- a/drivers/usb/misc/iowarrior.c +++ b/drivers/usb/misc/iowarrior.c @@ -920,13 +920,15 @@ static void iowarrior_disconnect(struct /* prevent device read, write and ioctl */ dev->present = 0; + /* write urbs are not stopped on close() so kill unconditionally */ + usb_kill_anchored_urbs(&dev->submitted); + if (dev->opened) { /* There is a process that holds a filedescriptor to the device , so we only shutdown read-/write-ops going on. Deleting the device is postponed until close() was called. */ usb_kill_urb(dev->int_in_urb); - usb_kill_anchored_urbs(&dev->submitted); wake_up_interruptible(&dev->read_wait); wake_up_interruptible(&dev->write_wait); mutex_unlock(&dev->mutex);