* [PATCH v2] usb: gadget: f_tcm: avoid NULL dereference in usbg_make_tpg()
@ 2026-09-15 8:05 pavankumaryalagada
0 siblings, 0 replies; only message in thread
From: pavankumaryalagada @ 2026-09-15 8:05 UTC (permalink / raw)
To: gregkh
Cc: michael.christie, nab, mkp, leitao, skhan, linux-usb,
linux-kernel, Yalagada Pavan Kumar, syzbot+a9efa71b884a23e74153,
stable
From: Yalagada Pavan Kumar <pavankumaryalagada@gmail.com>
usbg_make_tpg() can race with creation of USB gadget function
instance. tcm_alloc_inst() adds the function instance to
tpg_instances before configfs links the item to its parent group.
As a result, usbg_make_tpg() can find the instance while its
ci_group is still NULL. Passing this item to
configfs_depend_item_unlocked() then causes a NULL pointer
dereference.
Verify that ci_group is set before calling configfs_depend_item_unlocked()
and fail TPG creation if the item has not been linked yet.
keep this validation in f_tcm instead of changing the configfs API to
accept unlinked items.
Reported-by: syzbot+a9efa71b884a23e74153@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=a9efa71b884a23e74153
Fixes: 4bb8548df632 ("usb: gadget: f_tcm: add configfs support")
Cc: stable@vger.kernel.org
Signed-off-by: Yalagada Pavan Kumar <pavankumaryalagada@gmail.com>
---
Changes in v2:
- Move the NULL check from configfs to f_tcm.
- Restore configfs_depend_item_unlocked() to its original behaviour
v1: https://lore.kernel.org/all/20260914094426.25595-1-pavankumaryalagada@gmail.com/T/
---
drivers/usb/gadget/function/f_tcm.c | 3 +++
1 file changed, 3 insertions(+)
diff --git a/drivers/usb/gadget/function/f_tcm.c b/drivers/usb/gadget/function/f_tcm.c
index 9e6d4f39900a..2c2cf1164edf 100644
--- a/drivers/usb/gadget/function/f_tcm.c
+++ b/drivers/usb/gadget/function/f_tcm.c
@@ -1682,6 +1682,9 @@ static struct se_portal_group *usbg_make_tpg(struct se_wwn *wwn,
if (!try_module_get(opts->dependent))
goto unlock_inst;
} else {
+ if (!READ_ONCE(opts->func_inst.group.cg_item.ci_group))
+ goto unlock_inst;
+
/*
* configfs_depend_item_unlocked() may acquire the configfs
* root inode lock when the target belongs to a different
--
2.43.0
^ permalink raw reply related [flat|nested] only message in thread
only message in thread, other threads:[~2026-09-15 8:05 UTC | newest]
Thread overview: (only message) (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-15 8:05 [PATCH v2] usb: gadget: f_tcm: avoid NULL dereference in usbg_make_tpg() pavankumaryalagada
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox