From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-pj1-f48.google.com (mail-pj1-f48.google.com [209.85.216.48]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 84F373A6B7F for ; Wed, 29 Jul 2026 19:38:15 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.216.48 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785353896; cv=none; b=VxXrJkxL8G6MDyBERPpQRvjrwR65V+1JQOQbne/GPvWjor4/WFJW6BY3i+aX4K9C2NYGKn05XGQZ82nQJqdsjQZ+yqynl2UjoBlXf8fEhXJZfTVyOI6I9ulSzAAroI27XSJmK6xnsvDnoBUQ0Hn2DtQyTmNwy2riN8SENzwQ9CY= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785353896; c=relaxed/simple; bh=XwNgm9ATHQcGjGNk+lydH01xqpvPa6t/7xgikX+lowA=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=mGJru9O4d2E3e/gHbtNzOyBUhrjpk5ldb1fU1gcRCnVtugm0GHLgpNgh+onse4NeCQTr30gDIp5X4xAt5VvR7vaYTkQxGlkubiCKL3WgcqESoMkOf/ZwKy5dTL5RyMejm3tND90i447Z4Y1TGEaBVmwf3bkNh7naQYNm3BVSSs0= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=ce+KNrPd; arc=none smtp.client-ip=209.85.216.48 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="ce+KNrPd" Received: by mail-pj1-f48.google.com with SMTP id 98e67ed59e1d1-38dc4553f62so1371868a91.0 for ; Wed, 29 Jul 2026 12:38:15 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1785353895; x=1785958695; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=fGQJH3HgC5JOXAIct0TTf3DXud55D/ZhU/Mkkd98GCc=; b=ce+KNrPdEf/PjsNGndTJTBbc6MejYsxI89RZB4tjuchBrVwLAzCIg8y5O7gOZ/j8n5 isd0JudEcgwpdbDMPcxb9kVGXUtGt0waDhS2VMYd5t+J45MEU74wfFzT/PeitsW1d6xg gOYzxhaMr/HgPluSo6senSVNlVl+AIPzYeLeDu0fUV1xHgi0sa37Mp+CCTPIoXi6QWFr /NVQiUAVhz/XfzapYk78YweFV/7KQp8gFiKcJKSfBye1qycFYb9wNmfm/MfIn4597bug vfIJL14iqIFpJo4lL92We67iQzoiUN13MhRWxaHrYvZyxq+UjRzrCgaHpjBlAyX1cD5a CJHg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785353895; x=1785958695; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=fGQJH3HgC5JOXAIct0TTf3DXud55D/ZhU/Mkkd98GCc=; b=Oll2exteBjfTu9hb65YoRKGaljLiRB6mrZ64R/eSq1tXml66WHs68ORLVeOo6N+fI0 ISlKtIm+Kxmk00dronIHpq3NmHWXnrY5qXYsFLQuYbiG1DeEQcnyGk1tXlJ/pgQKkoI9 2Z/lHWSIRo35ZQo0QDeLohjnBs9RqQRZzAGCrH2JqoH+fHO4bMuW3xQplkjefGJT34b3 hWtuPJIim5/4cNfREv5sraUn0mLoRhAPP8IG6mswOLlqMnDRXBqxEeRwi5JdPegEE2po /VfNyf5/DCf4W9QMh6/8snuphfKqcrXViZhoNn/55ZgihPszIwMxRIHwZaovW5b70Ro1 on1g== X-Forwarded-Encrypted: i=1; AHgh+Ror6HFZPHI2sGajddJ9IvM+jAAgfd0miL6IDxTV/YpvDaY6gMEOk3sfz7OIEPHsItudeWxujsQTvhF+Wr4=@vger.kernel.org X-Gm-Message-State: AOJu0YwHjMWVq1NO8xXLneBL73lwzg0goqPWFX2nGeL2q9343VmcgSSn WG12WMNb9CLzmNEW4Wg/YqkJjcOS0chIvqt3JYj6lCtOzUNJneSd0+YE X-Gm-Gg: AR+sD11UlR2MccRleUBtnkgeaVJjvHOU47fVsDWHtguQpru7DEZs7dDHu/rdb7pk1Am +OwVWzcUDJGdWFXYsvOJaXuAWvE6s6jvHDmTonUotHdgMip34HmPDNpvYN2SN3+KbSNcAv3pAhH qZtXsvJllhGFYo0JCd89P40mTYWcBojgi3hJElK5L8I2h/1JN1F/24xpFQQsezkQ76KjSU4lAP0 clvvRqPkLIdqcK0EqVB9Ka+9vYV4tFYb80BPArT3ETvUMxeuXLzwQPyV7grDjlxnYhCmEf+T+oM JnxntTQIqTVmXkHAhPvuR09GxJghE1qSFkthO18NEakAWJsfBfTpaOkrQdZVN8XTlmPPSv7oHXn Tv+CNIvU4tQ8oCs0Bnr97RaZaQAo9iFkEYLyWCVVNkv4WztTS165pVvHvo3DLb/0QWFFtotTyHZ Hx5e3YEax2m8n6ZTy7CLXSeAOnRIUuOjTtrYkIyli4uMsTInHHb80E/rwE1FfDNSZ4 X-Received: by 2002:a17:90b:498f:b0:37f:9ce3:ca95 with SMTP id 98e67ed59e1d1-38f993843fdmr155523a91.30.1785353894717; Wed, 29 Jul 2026 12:38:14 -0700 (PDT) Received: from Default ([2409:40f4:100c:ca91:db1d:88f3:514:9ded]) by smtp.gmail.com with ESMTPSA id 5a478bee46e88-31504927a7bsm14207721eec.0.2026.07.29.12.38.08 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 29 Jul 2026 12:38:14 -0700 (PDT) From: Jeffin Philip To: syzbot@kernel.org Cc: christophe.jaillet@wanadoo.fr, gregkh@linuxfoundation.org, kees@kernel.org, linux-kernel@vger.kernel.org, linux-usb@vger.kernel.org, nogikh@google.com, syzbot@lists.linux.dev, syzkaller-bugs@googlegroups.com, tiwai@suse.de, Jeffin Philip Subject: Re: [PATCH] usb: gadget: midi2: Fix null-pointer dereference in f_midi2_free_ep_reqs Date: Thu, 30 Jul 2026 01:07:45 +0530 Message-ID: <20260729193746.313378-1-jeffinphilip14@gmail.com> X-Mailer: git-send-email 2.55.0 In-Reply-To: References: Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit On Wed, 29 Jul 2026 11:04:54 +0200, syzbot wrote: > > From: Aleksandr Nogikh > > A null-pointer dereference occurs in f_midi2_free_ep_reqs() when attempting > to clean up an endpoint that was never initialized. > > When configuring the MIDI 2.0 gadget via configfs and setting the block > direction to SNDRV_UMP_DIR_INPUT, the initialization of the midi1_ep_out > endpoint is explicitly skipped during the gadget bind phase > (f_midi2_bind()). As a result, the usb_ep->card field remains NULL. > > Later, when the host sets the alternate setting, f_midi2_set_alt() > unconditionally stops both the IN and OUT endpoints by calling > f_midi2_stop_eps(), which in turn calls f_midi2_free_ep_reqs() for both > endpoints. When f_midi2_free_ep_reqs() is called for the uninitialized > midi1_ep_out, it attempts to dereference usb_ep->card to determine the > number of requests to free, leading to a crash. > > Fix this by using usb_ep->num_reqs instead of usb_ep->card->info.num_reqs > in f_midi2_free_ep_reqs(). usb_ep->num_reqs is correctly set during > f_midi2_init_ep() and remains 0 if the endpoint was never initialized, > safely avoiding the loop. For consistency, apply the same change to > f_midi2_alloc_ep_reqs(). > > Oops: general protection fault, probably for non-canonical address > 0xdffffc00000000ee: 0000 [#1] SMP KASAN NOPTI > KASAN: null-ptr-deref in range [0x0000000000000770-0x0000000000000777] > ... > RIP: 0010:f_midi2_free_ep_reqs drivers/usb/gadget/function/f_midi2.c:1166 > [inline] > RIP: 0010:f_midi2_stop_eps+0x28e/0x4d0 > drivers/usb/gadget/function/f_midi2.c:1246 > ... > Call Trace: > > f_midi2_set_alt+0x11c/0xf00 drivers/usb/gadget/function/f_midi2.c:1296 > composite_setup+0x1ffd/0x3480 drivers/usb/gadget/composite.c:1933 > configfs_composite_setup+0xbd/0x100 drivers/usb/gadget/configfs.c:1877 > > Fixes: 8b645922b223 ("usb: gadget: Add support for USB MIDI 2.0 function driver") > Assisted-by: Gemini:gemini-3.5-flash Gemini:gemini-3.1-pro-preview syzbot > Reported-by: syzbot+bbb6dad313f4aaa8da6b@syzkaller.appspotmail.com > Closes: https://syzkaller.appspot.com/bug?extid=bbb6dad313f4aaa8da6b > Link: https://syzkaller.appspot.com/ai_job?id=8ce30b1a-8cf7-4e38-bcf7-1f69e6f6313f > Signed-off-by: Aleksandr Nogikh Closes: https://syzkaller.appspot.com/bug?extid=01a17afb30637396955e Thanks, Jeffin.