From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from mail-wm0-f48.google.com ([74.125.82.48]:39039 "EHLO mail-wm0-f48.google.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1728929AbeGRUcM (ORCPT ); Wed, 18 Jul 2018 16:32:12 -0400 Received: by mail-wm0-f48.google.com with SMTP id h20-v6so4013666wmb.4 for ; Wed, 18 Jul 2018 12:52:46 -0700 (PDT) Date: Wed, 18 Jul 2018 20:52:27 +0100 From: Sudip Mukherjee To: Greg Kroah-Hartman Cc: stable@vger.kernel.org, Jordan Glover , Mathias Nyman Subject: request for 4.14-stable: 2278446e2b7cd33ad894b32e7eb63afc7db6c86e Message-ID: <20180718195227.2bcp3jo6d4d4ryfd@debian> MIME-Version: 1.0 Content-Type: multipart/mixed; boundary="ivn4ltqd4cnv7hec" Content-Disposition: inline Sender: stable-owner@vger.kernel.org List-ID: --ivn4ltqd4cnv7hec Content-Type: text/plain; charset=us-ascii Content-Disposition: inline Hi Greg, This was missing in 4.14-stable. Please apply to your queue. -- Regards Sudip --ivn4ltqd4cnv7hec Content-Type: text/x-diff; charset=us-ascii Content-Disposition: attachment; filename="0001-xhci-Fix-USB3-NULL-pointer-dereference-at-logical-di.patch" >>From 5015bf2e6c6b1e0d110206e59aacb5787faae86f Mon Sep 17 00:00:00 2001 From: Mathias Nyman Date: Mon, 14 May 2018 11:57:23 +0300 Subject: [PATCH] xhci: Fix USB3 NULL pointer dereference at logical disconnect. commit 2278446e2b7cd33ad894b32e7eb63afc7db6c86e upstream Hub driver will try to disable a USB3 device twice at logical disconnect, racing with xhci_free_dev() callback from the first port disable. This can be triggered with "udisksctl power-off --block-device " or by writing "1" to the "remove" sysfs file for a USB3 device in 4.17-rc4. USB3 devices don't have a similar disabled link state as USB2 devices, and use a U3 suspended link state instead. In this state the port is still enabled and connected. hub_port_connect() first disconnects the device, then later it notices that device is still enabled (due to U3 states) it will try to disable the port again (set to U3). The xhci_free_dev() called during device disable is async, so checking for existing xhci->devs[i] when setting link state to U3 the second time was successful, even if device was being freed. The regression was caused by, and whole thing revealed by, Commit 44a182b9d177 ("xhci: Fix use-after-free in xhci_free_virt_device") which sets xhci->devs[i]->udev to NULL before xhci_virt_dev() returned. and causes a NULL pointer dereference the second time we try to set U3. Fix this by checking xhci->devs[i]->udev exists before setting link state. The original patch went to stable so this fix needs to be applied there as well. Fixes: 44a182b9d177 ("xhci: Fix use-after-free in xhci_free_virt_device") Cc: Reported-by: Jordan Glover Tested-by: Jordan Glover Signed-off-by: Mathias Nyman Signed-off-by: Greg Kroah-Hartman Signed-off-by: Sudip Mukherjee --- drivers/usb/host/xhci-hub.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/drivers/usb/host/xhci-hub.c b/drivers/usb/host/xhci-hub.c index 00b8d4cdcac3..c01d1f3a1c7d 100644 --- a/drivers/usb/host/xhci-hub.c +++ b/drivers/usb/host/xhci-hub.c @@ -366,7 +366,7 @@ int xhci_find_slot_id_by_port(struct usb_hcd *hcd, struct xhci_hcd *xhci, slot_id = 0; for (i = 0; i < MAX_HC_SLOTS; i++) { - if (!xhci->devs[i]) + if (!xhci->devs[i] || !xhci->devs[i]->udev) continue; speed = xhci->devs[i]->udev->speed; if (((speed >= USB_SPEED_SUPER) == (hcd->speed >= HCD_USB3)) -- 2.11.0 --ivn4ltqd4cnv7hec--