Linux USB
 help / color / mirror / Atom feed
From: Mathias Nyman <mathias.nyman@linux.intel.com>
To: sashiko-reviews@lists.linux.dev
Cc: linux-usb@vger.kernel.org
Subject: Re: [PATCH v2 11/11] xhci: Prevent invalid vdev dereference during sideband unregister
Date: Sat, 10 Oct 2026 01:47:05 +0300	[thread overview]
Message-ID: <2b9e7969-bb78-4874-b5e0-0321d31d3beb@linux.intel.com> (raw)
In-Reply-To: <sashiko-outbox-165777@kernel.org>

On 10/9/26 18:30, sashiko-bot@kernel.org wrote:
> Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
> - [High] xhci: TOCTOU race and Use-After-Free in sideband registration
> --
> 
> commit 7085c7c59881c747b14aeec07262203621aaa8b5
> Author: Mathias Nyman <mathias.nyman@linux.intel.com>
> xhci: Prevent invalid vdev dereference during sideband unregister
> 
> This commit prevents the reallocation of the xhci virtual device in the setup
> device error path if a sideband is registered. It aims to fix a kernel oops
> caused by dereferencing a stale vdev pointer during USB audio disconnect.
> 
> Closes: https://lore.kernel.org/linux-usb/TYUPR06MB6217000B59003EDF233D7246D2B22@TYUPR06MB6217.apcprd06.prod.outlook.com/
> 
>> diff --git a/drivers/usb/host/xhci.c b/drivers/usb/host/xhci.c
>> --- a/drivers/usb/host/xhci.c
>> +++ b/drivers/usb/host/xhci.c
>> @@ -4435,10 +4435,13 @@ static int xhci_setup_device(struct usb_hcd *hcd, struct usb_device *udev,
>>   		dev_warn(&udev->dev, "Device not responding to setup %s.\n", act);
>>   
>>   		mutex_unlock(&xhci->mutex);
>> -		ret = xhci_disable_and_free_slot(xhci, udev->slot_id);
>> -		if (!ret) {
>> -			if (xhci_alloc_dev(hcd, udev) == 1)
>> -				xhci_setup_addressable_virt_dev(xhci, udev);
>> +
>> +		if (!virt_dev->sideband) {
>> +			ret = xhci_disable_and_free_slot(xhci, udev->slot_id);
> 
> [Severity: High]
> Can this lockless check introduce a Time-Of-Check to Time-Of-Use (TOCTOU)
> race condition leading to a use-after-free?
> 
> If an asynchronous caller like snd_usb_rediscover_devices() calls
> xhci_sideband_register() concurrently, it acquires xhci->lock, reads
> xhci->devs[slot_id], and attaches the sideband.
> 
> If this lockless check evaluates to true just before the sideband is
> attached, we proceed to xhci_disable_and_free_slot() without the lock:
> 
> xhci_setup_device()
>      if (!virt_dev->sideband) {
>          xhci_disable_and_free_slot()
>              xhci_free_virt_device()
>                  xhci->devs[slot_id] = NULL;
>                  kfree(dev);
> 
> Because xhci_free_virt_device() does not hold xhci->lock, it can free the
> device immediately after xhci_sideband_register() attaches the sideband,
> leaving the sideband with a dangling pointer to a freed vdev.

Not an issue, or extremely unlikely.

This xhci_setup_device() codepath is called during usb device (re-)enumeration.
In this case problematic case is after a failed usb port resume calling reset-resume.

This means that the suspended audio class interface driver would have to register
audio sideband before the audio class interface itself resumed, and do this
while the parent port is mid resume.

Mathias

      reply	other threads:[~2026-10-09 22:47 UTC|newest]

Thread overview: 24+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-10-09 15:16 [PATCH v2 00/11] xhci features and fixes for usb-next Mathias Nyman
2026-10-09 15:16 ` [PATCH v2 01/11] usb: xhci: return an error if the host is not halted Mathias Nyman
2026-10-09 15:24   ` sashiko-bot
2026-10-09 15:16 ` [PATCH v2 02/11] usb: xhci: Unlock for command abort polling Mathias Nyman
2026-10-09 15:27   ` sashiko-bot
2026-10-09 15:16 ` [PATCH v2 03/11] usb: xhci: fix typos in comments Mathias Nyman
2026-10-09 15:18   ` sashiko-bot
2026-10-09 15:16 ` [PATCH v2 04/11] xhci: check device notification type before forwarding wake event Mathias Nyman
2026-10-09 15:23   ` sashiko-bot
2026-10-09 15:16 ` [PATCH v2 05/11] xhci: dbc: lock the minor IDR on registration failure Mathias Nyman
2026-10-09 15:25   ` sashiko-bot
2026-10-09 15:16 ` [PATCH v2 06/11] usb: xhci: Guarantee URB giveback on Ring Underrun/Overrun Mathias Nyman
2026-10-09 15:25   ` sashiko-bot
2026-10-09 15:16 ` [PATCH v2 07/11] usb: xhci: Don't set the skip flag on non-isoc endpoints Mathias Nyman
2026-10-09 15:23   ` sashiko-bot
2026-10-09 15:16 ` [PATCH v2 08/11] usb: xhci: Shorten the TD skipping loop Mathias Nyman
2026-10-09 15:22   ` sashiko-bot
2026-10-09 15:16 ` [PATCH v2 09/11] usb: xhci: Rework and improve the TD matching and skipping logic Mathias Nyman
2026-10-09 15:34   ` sashiko-bot
2026-10-09 15:16 ` [PATCH v2 10/11] usb: xhci: Fix bounce buffer overflow Mathias Nyman
2026-10-09 15:28   ` sashiko-bot
2026-10-09 15:16 ` [PATCH v2 11/11] xhci: Prevent invalid vdev dereference during sideband unregister Mathias Nyman
2026-10-09 15:30   ` sashiko-bot
2026-10-09 22:47     ` Mathias Nyman [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=2b9e7969-bb78-4874-b5e0-0321d31d3beb@linux.intel.com \
    --to=mathias.nyman@linux.intel.com \
    --cc=linux-usb@vger.kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox