* [PATCH] usb: gadget: composite: pass the validated interface index
@ 2026-09-15 4:09 Aldo Ariel Panzardo
0 siblings, 0 replies; 3+ messages in thread
From: Aldo Ariel Panzardo @ 2026-09-15 4:09 UTC (permalink / raw)
To: Greg Kroah-Hartman
Cc: linux-usb, linux-kernel, stable, Aldo Ariel Panzardo, Chris Mason
composite_setup() validates the low byte of wIndex as an interface
number, but passes the full 16-bit wIndex to the function's get_alt and
set_alt callbacks. FunctionFS reverse-maps the low byte and then uses
the original callback argument to index its fixed-size cur_alt array.
Pass the decoded and validated interface number to the callbacks. This
matches the callback contract and prevents an out-of-bounds cur_alt
access when the high byte of wIndex is nonzero.
Fixes: 2f550553e23c ("usb: gadget: f_fs: Add the missing get_alt callback")
Reported-by: Chris Mason <clm@meta.com>
Link: https://lore.kernel.org/r/3984c9bd-2ac8-424e-9390-7170fdab3c03@meta.com
Cc: stable@vger.kernel.org
Signed-off-by: Aldo Ariel Panzardo <qwe.aldo@gmail.com>
---
drivers/usb/gadget/composite.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/drivers/usb/gadget/composite.c b/drivers/usb/gadget/composite.c
index df39e3487..2aa07eafc 100644
--- a/drivers/usb/gadget/composite.c
+++ b/drivers/usb/gadget/composite.c
@@ -1930,7 +1930,7 @@ composite_setup(struct usb_gadget *gadget, const struct usb_ctrlrequest *ctrl)
break;
spin_lock(&cdev->lock);
- value = f->set_alt(f, w_index, w_value);
+ value = f->set_alt(f, intf, w_value);
if (value == USB_GADGET_DELAYED_STATUS) {
DBG(cdev,
"%s: interface %d (%s) requested delayed status\n",
@@ -1950,7 +1950,7 @@ composite_setup(struct usb_gadget *gadget, const struct usb_ctrlrequest *ctrl)
if (!f)
break;
/* lots of interfaces only need altsetting zero... */
- value = f->get_alt ? f->get_alt(f, w_index) : 0;
+ value = f->get_alt ? f->get_alt(f, intf) : 0;
if (value < 0)
break;
*((u8 *)req->buf) = value;
--
2.43.0
^ permalink raw reply related [flat|nested] 3+ messages in thread
* Re: [PATCH] usb: gadget: composite: pass the validated interface index
[not found] <20260915040947.2829612-1-qwe.aldo@gmail.com>
@ 2026-10-09 3:02 ` Aldo Ariel Panzardo
2026-10-09 11:28 ` Greg Kroah-Hartman
0 siblings, 1 reply; 3+ messages in thread
From: Aldo Ariel Panzardo @ 2026-10-09 3:02 UTC (permalink / raw)
To: Greg Kroah-Hartman; +Cc: Aldo Ariel Panzardo, linux-usb
Hi Greg,
Friendly ping on these five USB gadget patches, all sent September 15:
- usb: gadget: composite: pass the validated interface index
- usb: gadget: configfs: zero-terminate Unicode property data
- usb: gadget: f_printer: use the active RX list in soft reset
- usb: gadget: ncm: validate NDP length against the NTB
- [v2] usb: gadget: ncm: validate the NDP chain before parsing
(v2 incorporates the cyclic chain example from prior review)
Let me know if any of them need changes.
Thanks,
Aldo
^ permalink raw reply [flat|nested] 3+ messages in thread
* Re: [PATCH] usb: gadget: composite: pass the validated interface index
2026-10-09 3:02 ` [PATCH] usb: gadget: composite: pass the validated interface index Aldo Ariel Panzardo
@ 2026-10-09 11:28 ` Greg Kroah-Hartman
0 siblings, 0 replies; 3+ messages in thread
From: Greg Kroah-Hartman @ 2026-10-09 11:28 UTC (permalink / raw)
To: Aldo Ariel Panzardo; +Cc: linux-usb
On Fri, Oct 09, 2026 at 12:02:44AM -0300, Aldo Ariel Panzardo wrote:
> Hi Greg,
>
> Friendly ping on these five USB gadget patches, all sent September 15:
>
> - usb: gadget: composite: pass the validated interface index
> - usb: gadget: configfs: zero-terminate Unicode property data
> - usb: gadget: f_printer: use the active RX list in soft reset
> - usb: gadget: ncm: validate NDP length against the NTB
> - [v2] usb: gadget: ncm: validate the NDP chain before parsing
> (v2 incorporates the cyclic chain example from prior review)
>
> Let me know if any of them need changes.
I am way behind on patches due to travel and the influx of all of these.
Please help out by reviewing other patches on the list to help reduce
the load so that your patches can be gotten to...
thanks,
greg k-h
^ permalink raw reply [flat|nested] 3+ messages in thread
end of thread, other threads:[~2026-10-09 11:28 UTC | newest]
Thread overview: 3+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
[not found] <20260915040947.2829612-1-qwe.aldo@gmail.com>
2026-10-09 3:02 ` [PATCH] usb: gadget: composite: pass the validated interface index Aldo Ariel Panzardo
2026-10-09 11:28 ` Greg Kroah-Hartman
2026-09-15 4:09 Aldo Ariel Panzardo
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox