From: Wentao Liang <vulab@iscas.ac.cn>
To: alex.aring@gmail.com
Cc: andrew+netdev@lunn.ch, davem@davemloft.net, edumazet@google.com,
kuba@kernel.org, linux-kernel@vger.kernel.org,
linux-wpan@vger.kernel.org, marcel@holtmann.org,
miquel.raynal@bootlin.com, netdev@vger.kernel.org,
pabeni@redhat.com, stefan@datenfreihafen.org,
Wentao Liang <vulab@iscas.ac.cn>,
stable@vger.kernel.org
Subject: [PATCH] ieee802154: atusb: Fix URB reference leak in atusb_work_urbs()
Date: Thu, 17 Sep 2026 11:48:21 +0000 [thread overview]
Message-ID: <20260917114821.2149704-1-vulab@iscas.ac.cn> (raw)
usb_get_from_anchor() hands over a reference to the URB, which the caller
has to release. atusb_work_urbs() never does, so every URB collected from
the idle anchor keeps an extra reference: the reference count grows on
each retry cycle and the URBs are never freed on disconnect. Drop the
reference after a successful submission, and after the URB has been put
back on the idle anchor when submission failed, as the HCD holds its own
reference while the URB is in flight.
Fixes: 7490b008d123 ("ieee802154: add support for atusb transceiver")
Cc: stable@vger.kernel.org
Signed-off-by: Wentao Liang <vulab@iscas.ac.cn>
---
drivers/net/ieee802154/atusb.c | 6 ++++++
1 file changed, 6 insertions(+)
diff --git a/drivers/net/ieee802154/atusb.c b/drivers/net/ieee802154/atusb.c
index 5f7fc4ee7a07..3dbb142eccb2 100644
--- a/drivers/net/ieee802154/atusb.c
+++ b/drivers/net/ieee802154/atusb.c
@@ -180,9 +180,15 @@ static void atusb_work_urbs(struct work_struct *work)
if (!urb)
return;
ret = atusb_submit_rx_urb(atusb, urb);
+ if (!ret)
+ usb_put_urb(urb);
} while (!ret);
+ /* The reference obtained above is dropped once the URB is back
+ * on the idle anchor.
+ */
usb_anchor_urb(urb, &atusb->idle_urbs);
+ usb_put_urb(urb);
dev_warn_ratelimited(&usb_dev->dev,
"atusb_in: can't allocate/submit URB (%d)\n", ret);
schedule_delayed_work(&atusb->work,
--
2.34.1
next reply other threads:[~2026-09-17 11:48 UTC|newest]
Thread overview: 3+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-17 11:48 Wentao Liang [this message]
2026-09-19 7:46 ` [PATCH] ieee802154: atusb: Fix URB reference leak in atusb_work_urbs() Miquel Raynal
2026-09-21 15:14 ` krzk
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260917114821.2149704-1-vulab@iscas.ac.cn \
--to=vulab@iscas.ac.cn \
--cc=alex.aring@gmail.com \
--cc=andrew+netdev@lunn.ch \
--cc=davem@davemloft.net \
--cc=edumazet@google.com \
--cc=kuba@kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-wpan@vger.kernel.org \
--cc=marcel@holtmann.org \
--cc=miquel.raynal@bootlin.com \
--cc=netdev@vger.kernel.org \
--cc=pabeni@redhat.com \
--cc=stable@vger.kernel.org \
--cc=stefan@datenfreihafen.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox