From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from mail.linuxfoundation.org ([140.211.169.12]:33380 "EHLO mail.linuxfoundation.org" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1751788AbdJOOHc (ORCPT ); Sun, 15 Oct 2017 10:07:32 -0400 Subject: Patch "USB: serial: console: fix use-after-free on disconnect" has been added to the 4.13-stable tree To: johan@kernel.org, andreyknvl@google.com, gregkh@linuxfoundation.org Cc: , From: Date: Sun, 15 Oct 2017 16:07:08 +0200 Message-ID: <15080764281174@kroah.com> MIME-Version: 1.0 Content-Type: text/plain; charset=ANSI_X3.4-1968 Content-Transfer-Encoding: 8bit Sender: stable-owner@vger.kernel.org List-ID: This is a note to let you know that I've just added the patch titled USB: serial: console: fix use-after-free on disconnect to the 4.13-stable tree which can be found at: http://www.kernel.org/git/?p=linux/kernel/git/stable/stable-queue.git;a=summary The filename of the patch is: usb-serial-console-fix-use-after-free-on-disconnect.patch and it can be found in the queue-4.13 subdirectory. If you, or anyone else, feels it should not be added to the stable tree, please let know about it. >>From bd998c2e0df0469707503023d50d46cf0b10c787 Mon Sep 17 00:00:00 2001 From: Johan Hovold Date: Wed, 4 Oct 2017 11:01:12 +0200 Subject: USB: serial: console: fix use-after-free on disconnect From: Johan Hovold commit bd998c2e0df0469707503023d50d46cf0b10c787 upstream. A clean-up patch removing two redundant NULL-checks from the console disconnect handler inadvertently also removed a third check. This could lead to the struct usb_serial being prematurely freed by the console code when a driver accepts but does not register any ports for an interface which also lacks endpoint descriptors. Fixes: 0e517c93dc02 ("USB: serial: console: clean up sanity checks") Reported-by: Andrey Konovalov Acked-by: Greg Kroah-Hartman Signed-off-by: Johan Hovold Signed-off-by: Greg Kroah-Hartman --- drivers/usb/serial/console.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) --- a/drivers/usb/serial/console.c +++ b/drivers/usb/serial/console.c @@ -265,7 +265,7 @@ static struct console usbcons = { void usb_serial_console_disconnect(struct usb_serial *serial) { - if (serial->port[0] == usbcons_info.port) { + if (serial->port[0] && serial->port[0] == usbcons_info.port) { usb_serial_console_exit(); usb_serial_put(serial); } Patches currently in stable-queue which might be from johan@kernel.org are queue-4.13/usb-serial-console-fix-use-after-free-on-disconnect.patch queue-4.13/alsa-caiaq-fix-stray-urb-at-probe-error-path.patch queue-4.13/usb-serial-cp210x-fix-partnum-regression.patch queue-4.13/usb-serial-option-add-support-for-tp-link-lte-module.patch queue-4.13/usb-serial-cp210x-add-support-for-elv-tfd500.patch queue-4.13/usb-serial-qcserial-add-dell-dw5818-dw5819.patch queue-4.13/usb-serial-console-fix-use-after-free-after-failed-setup.patch queue-4.13/usb-serial-ftdi_sio-add-id-for-cypress-wiced-dev-board.patch