From: Mathias Nyman <mathias.nyman@linux.intel.com>
To: <gregkh@linuxfoundation.org>
Cc: <linux-usb@vger.kernel.org>,
Mathias Nyman <mathias.nyman@linux.intel.com>,
Lianqin Hu <hulianqin@vivo.com>,
stable@vger.kernel.org
Subject: [PATCH v2 11/11] xhci: Prevent invalid vdev dereference during sideband unregister
Date: Fri, 9 Oct 2026 18:16:24 +0300 [thread overview]
Message-ID: <20261009151624.618967-12-mathias.nyman@linux.intel.com> (raw)
In-Reply-To: <20261009151624.618967-1-mathias.nyman@linux.intel.com>
Offloaded USB audio devices using the xhci-sideband API store a pointer to
the xhci virtual device (vdev) in the sideband structure when registering.
This pointer typically remains valid throughout the lifetime of the USB
device. If a configured offloaded device requires a reset, the USB core
usually unbinds or notifies the audio driver beforehand, ensuring that the
sideband is unregistered before the vdev is freed.
An exception occurs when the USB core resets a device to recover from a
failed resume, but a subsequent 'address device' request also fails. To
recover in this specific scenario, the xHCI driver disables and re-enables
the slot, which frees and re-allocates the vdev.
xhci_sideband_unregister() later dereferences the stale, previously freed
vdev pointer during disconnect, triggering a kernel oops:
Unable to handle kernel paging request at virtual address dead000000000122
Call trace:
xhci_get_ep_ctx+0x0/0x38
xhci_sideband_unregister+0x68/0xf0
uaudio_disconnect+0x70/0x144
usb_audio_disconnect+0x7c/0x268
usb_unbind_interface+0x13c/0x340
device_release_driver_internal+0x1c4/0x2bc
usb_disable_device+0x84/0x190
usb_disconnect+0xe8/0x338
hub_event+0xbd8/0x19ac
Fix this by preventing the reallocation of the vdev in this specific error
path if the device is registered for sideband use.
Just propagate the error directly to the USB core. It should either retry
enumeration or detect the disconnected device, and handle it accordingly.
Debugging this issue to the dangling vdev pointer, reporting it, testing,
and initial patch with different solution by Lianqin Hu
Reported-by: Lianqin Hu <hulianqin@vivo.com>
Closes: https://lore.kernel.org/linux-usb/TYUPR06MB6217000B59003EDF233D7246D2B22@TYUPR06MB6217.apcprd06.prod.outlook.com/
Tested-by: Lianqin Hu <hulianqin@vivo.com>
Fixes: de66754e9f80 ("xhci: sideband: add initial api to register a secondary interrupter entity")
Cc: stable@vger.kernel.org
Signed-off-by: Mathias Nyman <mathias.nyman@linux.intel.com>
---
drivers/usb/host/xhci.c | 11 +++++++----
1 file changed, 7 insertions(+), 4 deletions(-)
diff --git a/drivers/usb/host/xhci.c b/drivers/usb/host/xhci.c
index 9564dde8bb34..30ac1bc4559b 100644
--- a/drivers/usb/host/xhci.c
+++ b/drivers/usb/host/xhci.c
@@ -4435,10 +4435,13 @@ static int xhci_setup_device(struct usb_hcd *hcd, struct usb_device *udev,
dev_warn(&udev->dev, "Device not responding to setup %s.\n", act);
mutex_unlock(&xhci->mutex);
- ret = xhci_disable_and_free_slot(xhci, udev->slot_id);
- if (!ret) {
- if (xhci_alloc_dev(hcd, udev) == 1)
- xhci_setup_addressable_virt_dev(xhci, udev);
+
+ if (!virt_dev->sideband) {
+ ret = xhci_disable_and_free_slot(xhci, udev->slot_id);
+ if (!ret) {
+ if (xhci_alloc_dev(hcd, udev) == 1)
+ xhci_setup_addressable_virt_dev(xhci, udev);
+ }
}
kfree(command->completion);
kfree(command);
--
2.43.0
next prev parent reply other threads:[~2026-10-09 15:16 UTC|newest]
Thread overview: 26+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-10-09 15:16 [PATCH v2 00/11] xhci features and fixes for usb-next Mathias Nyman
2026-10-09 15:16 ` [PATCH v2 01/11] usb: xhci: return an error if the host is not halted Mathias Nyman
2026-10-09 15:24 ` sashiko-bot
2026-10-09 15:16 ` [PATCH v2 02/11] usb: xhci: Unlock for command abort polling Mathias Nyman
2026-10-09 15:27 ` sashiko-bot
2026-10-10 6:36 ` Michal Pecio
2026-10-09 15:16 ` [PATCH v2 03/11] usb: xhci: fix typos in comments Mathias Nyman
2026-10-09 15:18 ` sashiko-bot
2026-10-09 15:16 ` [PATCH v2 04/11] xhci: check device notification type before forwarding wake event Mathias Nyman
2026-10-09 15:23 ` sashiko-bot
2026-10-09 15:16 ` [PATCH v2 05/11] xhci: dbc: lock the minor IDR on registration failure Mathias Nyman
2026-10-09 15:25 ` sashiko-bot
2026-10-09 15:16 ` [PATCH v2 06/11] usb: xhci: Guarantee URB giveback on Ring Underrun/Overrun Mathias Nyman
2026-10-09 15:25 ` sashiko-bot
2026-10-09 15:16 ` [PATCH v2 07/11] usb: xhci: Don't set the skip flag on non-isoc endpoints Mathias Nyman
2026-10-09 15:23 ` sashiko-bot
2026-10-09 15:16 ` [PATCH v2 08/11] usb: xhci: Shorten the TD skipping loop Mathias Nyman
2026-10-09 15:22 ` sashiko-bot
2026-10-09 15:16 ` [PATCH v2 09/11] usb: xhci: Rework and improve the TD matching and skipping logic Mathias Nyman
2026-10-09 15:34 ` sashiko-bot
2026-10-10 6:16 ` Michal Pecio
2026-10-09 15:16 ` [PATCH v2 10/11] usb: xhci: Fix bounce buffer overflow Mathias Nyman
2026-10-09 15:28 ` sashiko-bot
2026-10-09 15:16 ` Mathias Nyman [this message]
2026-10-09 15:30 ` [PATCH v2 11/11] xhci: Prevent invalid vdev dereference during sideband unregister sashiko-bot
2026-10-09 22:47 ` Mathias Nyman
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20261009151624.618967-12-mathias.nyman@linux.intel.com \
--to=mathias.nyman@linux.intel.com \
--cc=gregkh@linuxfoundation.org \
--cc=hulianqin@vivo.com \
--cc=linux-usb@vger.kernel.org \
--cc=stable@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox