Netdev List
 help / color / mirror / Atom feed
From: Marc Kleine-Budde <mkl@pengutronix.de>
To: netdev@vger.kernel.org
Cc: davem@davemloft.net, kuba@kernel.org, linux-can@vger.kernel.org,
	kernel@pengutronix.de, Fan Wu <fanwu01@zju.edu.cn>,
	stable@vger.kernel.org, Song Li <songl@zju.edu.cn>,
	Marc Kleine-Budde <mkl@pengutronix.de>
Subject: [PATCH net 17/22] can: ems_usb: use usb_kill_urb() to stop the intr URB
Date: Mon, 28 Sep 2026 20:45:24 +0200	[thread overview]
Message-ID: <20260928193312.553632-18-mkl@pengutronix.de> (raw)
In-Reply-To: <20260928193312.553632-1-mkl@pengutronix.de>

From: Fan Wu <fanwu01@zju.edu.cn>

The intr URB submitted in ems_usb_start() is not anchored, and its
completion handler ems_usb_read_interrupt_callback() resubmits it, so
it stays in flight as long as the interface is up. But unlink_all_urbs()
stops this URB with usb_unlink_urb(), which only initiates an
asynchronous unlink and returns without waiting for the handler.

The handler can therefore still be running while ems_usb_disconnect()
frees its data: it reads the transfer buffer dev->intr_in_buffer, which
is kfree()d there, and dereferences the private context, which is
released via free_candev() together with the network device.

Fix this by stopping the intr URB with usb_kill_urb(), which waits
until the handler has returned, so the frees in ems_usb_disconnect()
happen strictly after the last callback.

The handler treats the -ENOENT completion of a killed URB as terminal and
does not take RTNL or any sleeping lock, so the resubmit loop is cut and
no RTNL deadlock occurs.

This issue was found by an in-house static analysis tool.

Fixes: 702171adeed3 ("ems_usb: Added support for EMS CPC-USB/ARM7 CAN/USB interface")
Cc: stable@vger.kernel.org
Co-developed-by: Song Li <songl@zju.edu.cn>
Signed-off-by: Song Li <songl@zju.edu.cn>
Signed-off-by: Fan Wu <fanwu01@zju.edu.cn>
Link: https://patch.msgid.link/20260923030522.409344-1-fanwu01@zju.edu.cn
Signed-off-by: Marc Kleine-Budde <mkl@pengutronix.de>
---
 drivers/net/can/usb/ems_usb.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/drivers/net/can/usb/ems_usb.c b/drivers/net/can/usb/ems_usb.c
index 24cf8f651f8f..2d31f0b86859 100644
--- a/drivers/net/can/usb/ems_usb.c
+++ b/drivers/net/can/usb/ems_usb.c
@@ -748,7 +748,7 @@ static void unlink_all_urbs(struct ems_usb *dev)
 {
 	int i;
 
-	usb_unlink_urb(dev->intr_urb);
+	usb_kill_urb(dev->intr_urb);
 
 	usb_kill_anchored_urbs(&dev->rx_submitted);
 
-- 
2.53.0


  parent reply	other threads:[~2026-09-28 19:33 UTC|newest]

Thread overview: 26+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-28 18:45 [PATCH net 0/22] pull-request: can 2026-09-28 Marc Kleine-Budde
2026-09-28 18:45 ` [PATCH net 01/22] can: dev: can_dropped_invalid_skb: drop CAN XL frames on non-CAN XL devices Marc Kleine-Budde
2026-09-28 19:36   ` netdev-bot+sinfo
2026-09-28 18:45 ` [PATCH net 02/22] can: skb: make echo skb freeing safe in any IRQ context Marc Kleine-Budde
2026-09-28 18:45 ` [PATCH net 03/22] can: skb: make CAN skb allocation failure paths IRQ-safe Marc Kleine-Budde
2026-09-28 18:45 ` [PATCH net 04/22] can: dev: can_put_echo_skb(): free skb on invalid echo index Marc Kleine-Budde
2026-09-28 18:45 ` [PATCH net 05/22] can: dev: init_can_skb(): restore skb header initialization Marc Kleine-Budde
2026-09-28 18:45 ` [PATCH net 06/22] can: j1939: j1939_sk_bind(): fix j1939_ecu leak when re-bind failed Marc Kleine-Budde
2026-09-28 18:45 ` [PATCH net 07/22] can: isotp: check the frame type, not just the length Marc Kleine-Budde
2026-09-28 18:45 ` [PATCH net 08/22] can: cc770: platform_get_irq(): propagate the error Marc Kleine-Budde
2026-09-28 18:45 ` [PATCH net 09/22] can: cc770: fix the clock divider check on the platform bus Marc Kleine-Budde
2026-09-28 18:45 ` [PATCH net 10/22] can: kvaser_pciefd: fix use-after-free in bec poll timer Marc Kleine-Budde
2026-09-28 18:45 ` [PATCH net 11/22] can: m_can: pci: add missing pm_runtime_dont_use_autosuspend() call Marc Kleine-Budde
2026-09-28 18:45 ` [PATCH net 12/22] can: m_can: m_can_class_suspend(): fix suspend deinit() error path Marc Kleine-Budde
2026-09-28 18:45 ` [PATCH net 13/22] can: sun4i_can: sun4ican_probe(): fix clk leak Marc Kleine-Budde
2026-09-28 18:45 ` [PATCH net 14/22] can: xilinx_can: set CAN FD flags on received frames Marc Kleine-Budde
2026-09-28 18:45 ` [PATCH net 15/22] can: mcp251xfd: mcp251xfd_probe(): reject devices without match data Marc Kleine-Budde
2026-09-28 18:45 ` [PATCH net 16/22] can: hi311x: drop hi3110_lock before free_irq() on open failure Marc Kleine-Budde
2026-09-28 18:45 ` Marc Kleine-Budde [this message]
2026-09-28 18:45 ` [PATCH net 18/22] usb: f81604: fix struct f81604_int_data size mismatch Marc Kleine-Budde
2026-09-28 18:45 ` [PATCH net 19/22] can: gs_usb: kill RX URBs before destroying the netdevs Marc Kleine-Budde
2026-09-28 18:45 ` [PATCH net 20/22] can: gs_usb: add workarounds for HScanT USB to CAN adapter Marc Kleine-Budde
2026-09-28 18:45 ` [PATCH net 21/22] can: kvaser_usb: validate command format before parsing in hydra receive path Marc Kleine-Budde
2026-09-28 18:45 ` [PATCH net 22/22] can: peak_usb: fix missing CAN_ERR_FLAG when reporting error counters Marc Kleine-Budde
2026-09-29  1:09 ` [PATCH net 0/22] pull-request: can 2026-09-28 Jakub Kicinski
2026-09-29 21:12   ` Marc Kleine-Budde

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260928193312.553632-18-mkl@pengutronix.de \
    --to=mkl@pengutronix.de \
    --cc=davem@davemloft.net \
    --cc=fanwu01@zju.edu.cn \
    --cc=kernel@pengutronix.de \
    --cc=kuba@kernel.org \
    --cc=linux-can@vger.kernel.org \
    --cc=netdev@vger.kernel.org \
    --cc=songl@zju.edu.cn \
    --cc=stable@vger.kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox