From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-qk1-f171.google.com (mail-qk1-f171.google.com [209.85.222.171]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 5856332C8B for ; Sun, 14 Jun 2026 15:22:48 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.222.171 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1781450570; cv=none; b=tSkE0gn2Hy5LPLMtRtIawEzkqA6srprKpfuf6yKt65282hWgaqAa3fAgv1+Fv+7JOjrqgGJW02VuLh/J/MV7uQeCDDrNZ2ZCGk2KTOIfTRxzCSfNu3aqNCio0M8WJGtD/1CJIIaa7OkHzJ393iJ1cLdldzH3ouZypIQQJrpMB8E= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1781450570; c=relaxed/simple; bh=wdJNW15WRnR6mm7uLGWwYjcVt2wSr8fK7OPrm9yFFmk=; h=From:To:Subject:Date:Message-ID:MIME-Version:Content-Type; b=F5XGdbWa+76vcLPkQECnawst/YNbVlncAFox/gCgrd3WXe4auTlbCgzcTeR2Yu3tiHqBAIgP75xJkVucdh5qDw0PJQCy6eZUvzap4YccmTVvL2gz/mI8+goHhvbhb9ScdbOCKnZXV61c//7bwnPI5rCnogqgpqdqCReGpvLDvQE= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=eBvSLUvh; arc=none smtp.client-ip=209.85.222.171 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="eBvSLUvh" Received: by mail-qk1-f171.google.com with SMTP id af79cd13be357-9158643e538so241361285a.1 for ; Sun, 14 Jun 2026 08:22:48 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1781450567; x=1782055367; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:message-id:date:subject:to :from:from:to:cc:subject:date:message-id:reply-to; bh=GO3hFfMczhC5hkmHG+NBK+mHvTn3MyYz4TwN692B5ao=; b=eBvSLUvhZ8WFA6my1USHRz+4FIx2prWqNmEdREcLtfYK9vrvMxdy8c9Fop8rBT67OU JKd2OKGRdPzjUpVf8ZHq2P4OXtTDko8XnSMlQeFF34J+0rckFQaq8wSah2CNyLVlNaHa OU7YuGgycRaNLoB43dmqc4pIBLDNI+7Ab85VyeYyCSGyxUmAHCyjeA227fVFDWbod0+K z1dJmg+Q406PpFjQEQ7/XhoE/YQ+QZ33bqHssQtA9pxqNtytUu8i4Mo634MSdef3K+eF MbLn7kkO6mNZTwrYPMp/+CQgShgnKEFPDrfa4dADEjLfArK7gJtnynSo2jfq3OdodFbo Z7kQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1781450567; x=1782055367; h=content-transfer-encoding:mime-version:message-id:date:subject:to :from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date:message-id :reply-to; bh=GO3hFfMczhC5hkmHG+NBK+mHvTn3MyYz4TwN692B5ao=; b=RiSx9OPTuUEetrdDvH5vmdcscjqPepU06IxLAaryjeGek6ZXbegXkYEIdiZ9OM8Qqo jxBCjwDZ22bhG9xR699HVVO/uxLHg9pbIec0zvDj6D9UIF2jPCSdb7c+L30sW3ji8EYe OsgcxM0oLL0Q/pq1b0ccon7hxMQ0LIxPuwZb3Kd87ig31fWNryO0z/6LPQzTPPI2qWrr Mrzk11nAZad2dc2Jg18U9n5Em3zqIvk0TQDcA1zb5hovoavcArLSRUeGdesfedorVqlc jA9vR0WZfGTlv5kRL29pQXWM/lCkaDSW466ksuCZO02TYkcI8ixCPQNy7Ylyv01pCk4a aovg== X-Forwarded-Encrypted: i=1; AFNElJ/AMck/3sJ71OF4iF3HpUK4PnVZvFcEN4TcDtlSiKN+aCSLtHT33J9ekP/YUYp4Owfa7rVG314YLACvpBM=@vger.kernel.org X-Gm-Message-State: AOJu0Yyc0zpFkIV6v2gji5VtPSiru3aAEhNXGIEXIG2DOAgHB1LIx6E3 bSREBO/LRCsKTjPmth86qjeL5QEI8aj2FYPw8NoqglO86YShbdTtf+fS1hZwLmex7iw= X-Gm-Gg: Acq92OHtlsq6G+mtlXuL3AaQAxPDU++CuRe8N/E9v3DTLybnzYwcBav/TQ2XommJDaP /CONLd3aMqpxh/A+KDREZtMAKh4hmorlnB19eKBaeLkikyaPjjA0/NDut4HJe1/6X95aLE2QEKp AHUAOcKwNPRi3ea9V4qyLOKIxKClBvr5M3FtLlu3YjkZvck7WL6TOrNO410b69S7FgRBOT7D1MB DyFXnvpha0fY1TQLaKs+rV1m3nblQ0B4n2bUrtkMPXe29k2W9WkFVhi56KbBiLqdkuqEk2Bnmqm qEYBGBqPH1wOUy/Ljyp+G/uP5vEbYY+UkQ5oAznerPE48da79p+vTSlHkliXlHLV4B3f9VxUThh gWP2KJfUBs0F/pfalMH40uRBS7/Tus6yOtgZ1MX11dnEBx+SL3m0meX0pGLJpel651jyn1ljgCo afydn01CkGoO71j+TgeTO1sWcXHwn5F6/0CV7N6BR3C9/xNOHhg3jHIA== X-Received: by 2002:a05:620a:198f:b0:915:a6ca:f12a with SMTP id af79cd13be357-9161bfa0f5dmr1744290685a.54.1781450567313; Sun, 14 Jun 2026 08:22:47 -0700 (PDT) Received: from localhost.localdomain ([168.92.225.3]) by smtp.gmail.com with ESMTPSA id af79cd13be357-9161a04f5b7sm788985085a.38.2026.06.14.08.22.46 (version=TLS1_3 cipher=TLS_CHACHA20_POLY1305_SHA256 bits=256/256); Sun, 14 Jun 2026 08:22:47 -0700 (PDT) From: Shuangpeng Bai To: heikki.krogerus@linux.intel.com, gregkh@linuxfoundation.org, linux-usb@vger.kernel.org, linux-kernel@vger.kernel.org Subject: [BUG] KASAN: slab-out-of-bounds in select_usb_power_delivery_show Date: Sun, 14 Jun 2026 11:22:45 -0400 Message-ID: <178144969600.60470.6584137935143789620@gmail.com> X-Mailer: git-send-email 2.47.1 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: 7bit Hi Kernel Maintainers, I hit the following report while testing current upstream kernel: KASAN: slab-out-of-bounds in select_usb_power_delivery_show on commit: e8c2f9fdadee7cbc75134dc463c1e0d856d6e5c7 (May 25 2026) The reproducer and .config files are here. https://gist.github.com/shuangpengbai/79c08ada299b3ae37b7a0af292ca413f I'm happy to test debug patches or provide additional information. Reported-by: Shuangpeng Bai [ 102.318332] BUG: KASAN: slab-out-of-bounds in select_usb_power_delivery_show (drivers/usb/typec/class.c:1642) [ 102.319225] Read of size 8 at addr ffff888117d2f2c0 by task cat/8378 [ 102.319943] Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2 04/01/2014 [ 102.319952] Call Trace: [ 102.320044] select_usb_power_delivery_show (drivers/usb/typec/class.c:1642) [ 102.320066] dev_attr_show (drivers/base/core.c:2421) [ 102.320081] sysfs_kf_seq_show (fs/sysfs/file.c:65) [ 102.320085] seq_read_iter (fs/seq_file.c:231) [ 102.320107] vfs_read (fs/read_write.c:493 fs/read_write.c:574) [ 102.320140] ksys_read (fs/read_write.c:717) [ 102.320146] do_syscall_64 (arch/x86/entry/syscall_64.c:63 arch/x86/entry/syscall_64.c:94) [ 102.320160] entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:121) [ 102.334419] Allocated by task 1129 on cpu 0 at 52.398062s: [ 102.336306] tcpm_fw_get_caps (./include/linux/device/devres.h:59 ./include/linux/device/devres.h:63 drivers/usb/typec/tcpm/tcpm.c:7986) [ 102.336658] tcpm_register_port (drivers/usb/typec/tcpm/tcpm.c:8519) [ 102.337014] fusb302_probe (drivers/usb/typec/tcpm/fusb302.c:1759) [ 102.337349] i2c_device_probe (drivers/i2c/i2c-core-base.c:591) [ 102.341175] i2c_acpi_add_device (drivers/i2c/i2c-core-acpi.c:291 drivers/i2c/i2c-core-acpi.c:305) [ 102.342660] i2c_register_adapter (drivers/i2c/i2c-core-base.c:1594) [ 102.343044] i801_probe (drivers/i2c/busses/i2c-i801.c:1665) [ 102.347449] The buggy address belongs to the object at ffff888117d2f280 [ 102.347449] which belongs to the cache kmalloc-64 of size 64 [ 102.348432] The buggy address is located 0 bytes to the right of [ 102.348432] allocated 64-byte region [ffff888117d2f280, ffff888117d2f2c0) [ 102.376916] Kernel panic - not syncing: KASAN: panic_on_warn set ... Best, Shuangpeng