* [PATCH] usb: renesas_usbhs: Check pipe allocation in host pipe init
@ 2026-06-22 11:45 Haoxiang Li
2026-06-25 13:55 ` Greg KH
0 siblings, 1 reply; 2+ messages in thread
From: Haoxiang Li @ 2026-06-22 11:45 UTC (permalink / raw)
To: gregkh, kees; +Cc: linux-usb, linux-kernel, Haoxiang Li
usbhsh_pipe_init_for_host() allocates pipes with usbhs_dcp_malloc()
or usbhs_pipe_malloc(), both of which may return NULL. The returned
pointer is dereferenced unconditionally when clearing pipe->mod_private.
Check the returned pipe before using it to avoid a NULL pointer
dereference on pipe allocation/setup failure.
Signed-off-by: Haoxiang Li <haoxiang_li2024@163.com>
---
drivers/usb/renesas_usbhs/mod_host.c | 3 +++
1 file changed, 3 insertions(+)
diff --git a/drivers/usb/renesas_usbhs/mod_host.c b/drivers/usb/renesas_usbhs/mod_host.c
index f7ef3a9f82a4..11244cf3408d 100644
--- a/drivers/usb/renesas_usbhs/mod_host.c
+++ b/drivers/usb/renesas_usbhs/mod_host.c
@@ -1441,6 +1441,9 @@ static void usbhsh_pipe_init_for_host(struct usbhs_priv *priv)
dir_in);
}
+ if (!pipe)
+ return;
+
pipe->mod_private = NULL;
}
}
--
2.25.1
^ permalink raw reply related [flat|nested] 2+ messages in thread
* Re: [PATCH] usb: renesas_usbhs: Check pipe allocation in host pipe init
2026-06-22 11:45 [PATCH] usb: renesas_usbhs: Check pipe allocation in host pipe init Haoxiang Li
@ 2026-06-25 13:55 ` Greg KH
0 siblings, 0 replies; 2+ messages in thread
From: Greg KH @ 2026-06-25 13:55 UTC (permalink / raw)
To: Haoxiang Li; +Cc: kees, linux-usb, linux-kernel
On Mon, Jun 22, 2026 at 07:45:21PM +0800, Haoxiang Li wrote:
> usbhsh_pipe_init_for_host() allocates pipes with usbhs_dcp_malloc()
> or usbhs_pipe_malloc(), both of which may return NULL. The returned
> pointer is dereferenced unconditionally when clearing pipe->mod_private.
>
> Check the returned pipe before using it to avoid a NULL pointer
> dereference on pipe allocation/setup failure.
>
> Signed-off-by: Haoxiang Li <haoxiang_li2024@163.com>
> ---
> drivers/usb/renesas_usbhs/mod_host.c | 3 +++
> 1 file changed, 3 insertions(+)
>
> diff --git a/drivers/usb/renesas_usbhs/mod_host.c b/drivers/usb/renesas_usbhs/mod_host.c
> index f7ef3a9f82a4..11244cf3408d 100644
> --- a/drivers/usb/renesas_usbhs/mod_host.c
> +++ b/drivers/usb/renesas_usbhs/mod_host.c
> @@ -1441,6 +1441,9 @@ static void usbhsh_pipe_init_for_host(struct usbhs_priv *priv)
> dir_in);
> }
>
> + if (!pipe)
> + return;
No, you just leaked memory and caused the system to be in an unknown
state, which is probably worse off than the crash that would have
happened.
Please fix this properly, if you really have ever hit this before.
thanks,
greg k-h
^ permalink raw reply [flat|nested] 2+ messages in thread
end of thread, other threads:[~2026-06-25 13:56 UTC | newest]
Thread overview: 2+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-06-22 11:45 [PATCH] usb: renesas_usbhs: Check pipe allocation in host pipe init Haoxiang Li
2026-06-25 13:55 ` Greg KH
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox