From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-qv1-f49.google.com (mail-qv1-f49.google.com [209.85.219.49]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id B10EE29AB05 for ; Sat, 15 Aug 2026 01:38:58 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.219.49 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786757940; cv=none; b=OeMlh4n0bv2CT16QnqZUsD2S8JO7EsRYAbyOPFGOqcyQO7LHz8lFv7ynreSOuPf2pHeQTCFlQMxYIbbRk0Bc0KPfJitBRu5eNS327b3Ed4fY1glWFtZW44b91r8DUVbjGEg40UpQJKxUsdsu9dRs+2Enoyiml39hx/QItezW9wk= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786757940; c=relaxed/simple; bh=mCOXa+UzANBq0YSTWd7h4Gptj1cmZ7Q9m3HFpmaUeyc=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=Kyf5UCn79U8mKUEk/F60Xa1EBw7hUyW9iPl3k+DW0e/09SVRjZx/En0sXFxFQOJkgqQ1gkKa6AeXag1TWXKl5BvOMkzpkuiP46BtCcvDr92/A/FGbW4BTaqCtX9PoVq0cjAHLAIFFFC5SvOnZSNkkObLV91tLQRK8zBsiyAWbbg= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=cChEtWE1; arc=none smtp.client-ip=209.85.219.49 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="cChEtWE1" Received: by mail-qv1-f49.google.com with SMTP id 6a1803df08f44-90898faf46dso7480286d6.1 for ; Fri, 14 Aug 2026 18:38:58 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1786757937; x=1787362737; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to:content-type; bh=0DPz+4csxg4ejb60H4w2G/Kt+5hvp2XVZ2P+UQVR9Dk=; b=cChEtWE1wDypLFTDVZvmbKsaRHG6fe1c6ef+TSesD6EFe1y57VCUfeIqFuQvCLbXjO NUYp+1DXg9haXqwcdBYugSuPmpVe6QkG4Tagm3KHNkpwpiD/ueMNd/U0AWTtfuuGnlJd yzzgCqoz4jUzOfGDhfyoDyIrl7dAHg0RLc7oEzmU5oOppXz329fRquZIbB35kVlMNtGM Bw0Ee3q+td35oSwAjrUtQul4/gi1ifG/hoimC9fsx8BUAsWDynqp6qCy/rKu5THbJYTG Km8ck/RLIp9UeLXxDudrIuMcASdHilHz3wLqOdgiYRlOKufpuASenbfRN5LNJRC04XsW P6xA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1786757937; x=1787362737; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=0DPz+4csxg4ejb60H4w2G/Kt+5hvp2XVZ2P+UQVR9Dk=; b=DU/DZjJu27kluRrUug4kfljunhbRFoM+fOWB3rOCVZL2bmRh0kta2OF2yp39emElWA g5Cek/Hdiy6tjdaOMdPzdWbRB6uUv0UTIhVbUuyV2BRxFLhAEW5B3UMXjvb4uKhnfKfA uqyneqVimwoqJXX4APH1D2E2zC6wGl6yyvSXQDgl50ISKt3W9BePtRoOvcsuQ6OYPKyv /badyePybBymUNYBFMat1eYFPkcJtKjKoHu+QJZm+WNXMt3frtQwJ5XVxqVSNEBSI+BD 39efScVu6mPKLV7mPAKkmAi8XYmRLR0cpbFGBrAF3FYB0/H8bOyCJ/qsyNRiWo8ICOxy Z18g== X-Forwarded-Encrypted: i=1; AHgh+Rr6qg9iSq8EfBOWF2VwV2w6o9r5ieIu3sK0fFFaCA5iVmM6zeWM0D5mZYMm6qAR4qn9gib6WXXDChUol+A=@vger.kernel.org X-Gm-Message-State: AOJu0YymzmitfliPstd6kBkQ2Cw4EoTtjuFezYL6Gua3SRWypR5ouhix AaZ+ytP0g3eZb3tb27Beu5bzWvsQSD1AcyiJs60sNAtDMISmInnrdtpx X-Gm-Gg: AR+sD12okwb1pqaKg5cwRTDKbNzn2MBHHtOT/d3pNxKutE34cay0wcC56XFBokBoVCX UqWtXSg803ocgBGBsL2OW1QhRiVl/CqsH82UTSfEjwwEihMJu77cs1AQzUOSI5zJOMfmzPRp7Pr 4YjXdgKq5vFohteeL+vNPajGD5Pq0NKLG49t9yWemIxxy8dSJL8wfB4B5XYyYi2hhsqPSKlcz+8 gdlFEvb0BeAdigNrDU8YlIf+APscZKexKVTcVAX/qR+HN+8hBYpdxTImyXtdP8edAJBvNqvua0e dID4su7rbz54IljwC9xu/FtN02sIwKhkXL3G8LsCN3VyU96jNAOlDtGZpLghuXI7YlwnMOmwFb4 fIwRtxsELtM+LSFlbxetumAqFzuVV0ixILjJ6baBeFIWi2b5BOk31DVSVJ5LKU+b1DkuklqIgxJ kFk2/R7eZ6VcgyCpHg61KkFX3ZsM+yotaeBFODlT97Y5TS4VlreA+dU+ijRGB5zC5lWrFWkMHmL wtiLIAVrcRYHmpiLdY= X-Received: by 2002:a05:6214:1316:b0:8f2:3472:5b33 with SMTP id 6a1803df08f44-90a91da5cd9mr114078476d6.23.1786757937258; Fri, 14 Aug 2026 18:38:57 -0700 (PDT) Received: from i4-l-hqh5357-03.ad.psu.edu ([130.203.139.71]) by smtp.gmail.com with ESMTPSA id 6a1803df08f44-90a9354d2c3sm30800376d6.38.2026.08.14.18.38.56 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Fri, 14 Aug 2026 18:38:56 -0700 (PDT) From: Shuangpeng Bai To: gregkh@linuxfoundation.org Cc: viro@zeniv.linux.org.uk, r.baldyga@samsung.com, balbi@ti.com, linux-usb@vger.kernel.org, linux-kernel@vger.kernel.org, Shuangpeng Bai , stable@vger.kernel.org Subject: [PATCH] usb: gadget: f_fs: fix use-after-free in ffs_func_unbind Date: Fri, 14 Aug 2026 21:38:18 -0400 Message-ID: <20260815013818.39466-1-shuangpeng.kernel@gmail.com> X-Mailer: git-send-email 2.43.0 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit ffs_func_unbind() continues to access ffs after calling functionfs_unbind(), including taking ffs->eps_lock for endpoint cleanup. However, functionfs_unbind() drops the binding reference to ffs. A concurrent FunctionFS unmount can drop the independent superblock reference. Either put can then release the final reference and free ffs before ffs_func_unbind() finishes its endpoint cleanup. Take a temporary ffs reference for the duration of ffs_func_unbind() and drop it only after all post-unbind cleanup is complete. Fixes: a3058a5d82e2 ("usb: gadget: f_fs: remove redundant ffs_data_get()") Cc: stable@vger.kernel.org Signed-off-by: Shuangpeng Bai --- drivers/usb/gadget/function/f_fs.c | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/drivers/usb/gadget/function/f_fs.c b/drivers/usb/gadget/function/f_fs.c index 44218be1e676..8acad4564b6c 100644 --- a/drivers/usb/gadget/function/f_fs.c +++ b/drivers/usb/gadget/function/f_fs.c @@ -4089,6 +4089,9 @@ static void ffs_func_unbind(struct usb_configuration *c, unsigned count = ffs->eps_count; unsigned long flags; + /* Keep ffs alive until all post-unbind cleanup is complete. */ + ffs_data_get(ffs); + if (ffs->func == func) { ffs_func_eps_disable(func); ffs->func = NULL; @@ -4122,6 +4125,7 @@ static void ffs_func_unbind(struct usb_configuration *c, func->function.ssp_descriptors = NULL; func->interfaces_nums = NULL; + ffs_data_put(ffs); } static struct usb_function *ffs_alloc(struct usb_function_instance *fi) -- 2.43.0