From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-yx1-f45.google.com (mail-yx1-f45.google.com [74.125.224.45]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id BE425434E2F for ; Fri, 31 Jul 2026 15:04:43 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=74.125.224.45 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785510285; cv=none; b=FdLp1GzcdxPxbqgYd03eV0iqDa1P1FiAJoZ0r2wd2BO/kcEoRBhQNbQoU3Z+ZujbahK0LKlTxk84oxOs/zflGI3D+bkL4zG+exfs2IZhWgAC3eraCNpr1NzV68IEqpdI7cBxTy/WZ1ciaaV9uJuV+Iasw8sAkde7zYPn3SGrgWg= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785510285; c=relaxed/simple; bh=9XfU8m9tSyay/7H/o/K6AIyEgpODnHxgJIw/8azuWlo=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=XlhVRsl1oAtIiINZ/Tdt7TyexMZLRVtiQSL8mk7cPFKZoF88ZZ5lZwOmC+aPiTZlbYJSiwI4gqUk5NYajf6VAKCBCxAfR0YOP9TwM7SdTWNUzM5gJgjw3CHYXlEK0TSzw75AiBffq3cTU+2fTeFSNUolIt9e43KKz6Jgneo3hjQ= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=SUr7H4e6; arc=none smtp.client-ip=74.125.224.45 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="SUr7H4e6" Received: by mail-yx1-f45.google.com with SMTP id 956f58d0204a3-664a5193741so145456d50.1 for ; Fri, 31 Jul 2026 08:04:43 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1785510282; x=1786115082; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to:content-type; bh=mEC1T4rg4Niur9mZ8qTP+i49mzDy92w7tFYDv9o49ew=; b=SUr7H4e697+V/jwq8y89EJBxfuV4MCYiQkitZ9qQ9F3Coa93ZTuR3j3dDLUXE6Tpb6 rq/nQY1KtlO/gEMvcLtYQygfCNx0WoimdpoH+VMe/e9N1WGzyShdGAOaZcYJYHo3h3Tk 7scqqfJ9rD3TN/xbPXXgESF+dDogfw+/JF9IX6h6keUu5sBpIMcva//3i0kgNrpGakv6 Ka2w83H2qoihShKgtmA8Zf0EcVF3QbORpUhfsR6Nsaz0B6hBAKPfB6Qf43PHlXVPxvS+ Wun3j+kARZjwrT/FQHOoigGnC4jpVt8Op9IJZ/zN264k0X6H5/ykhdqRlQsRsTnAr0cj hHhw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785510282; x=1786115082; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=mEC1T4rg4Niur9mZ8qTP+i49mzDy92w7tFYDv9o49ew=; b=AYuW4yEiClsa71RIrqNMoxAM+x+ExvZmzQKMjhHM3k2CAHcHU4X4V6Iv9DqapdWAsu TMW5eE4sc9Go1xWZagu9gWreDQG3nnkXKDKgIAk9O/MFGvcTHP/KR5UVh1vuXTkaGP7k Cus3xA2UsNGbdsTN3eaS5qLMi7KY7ojm/+VuCrm4RnnOfnlVnqNdmkEqBmbUYGNx8Hko H1CznQHZkXaSDJ4KcjG9AXdl18/aTS4n0IP/crxY5jMfdj9RigI5k8hYvnFt2bCVttB0 XF2ez3bEC7Szg5y0gu5hsqtq2NZNuoFKi3Jztl8gZ3zuch2VnXG9FHf10RbS0thuhWf+ btwg== X-Forwarded-Encrypted: i=1; AHgh+RozGzyBB8ncLZHV7ckqY3+mU4l273OpVISjZ/GKlw+BNsuN8zGdBw1Xg5uziAXBcsZMy61B/1QSuP42SdY=@vger.kernel.org X-Gm-Message-State: AOJu0YztV78lbkXnSreogsI9ong4QBqybSgPmi4Ic2IRIkRoDg8nkIQ0 tVo3EEN6KdsibQ2ywPIU/F4eKAmOYqFNIUKTvv+Z+4sYxVwX/XiURzWh X-Gm-Gg: AR+sD10X0hpL7rXDOwt5beBQe3Wx4sU6armmwU7y413AgPB699TAkuxay4APtZRT34G Ssv9Hh3NZk967G4geDdASB1naP99XWn2tvpEMiLQ7YfBLBaH0F7Z48o7BMDL4rFb7RCOAVnD3gl NpC1VVRLiDucxV71mf7HgxTNfe98PbvJomLzAIRxYcdnlQjgywgV7g+DbdKJYUVIvsU9S1hkNUC 4ZRjS9fNRrBz4YcvVHAAC8sVJyAQgIrWbh0oIqE7+LX97tLj6bqiU2FGb8U/aamWN/yLSf4Rl4M vTjIXqNL2THnMaIUOdZZ3mtj/n9bt8QHUY4esom+hUIpvy4G6l2J1WFl4k6K191sAuhBb3kFSp1 NZFnYGcWOEL0ZXmzjm8YhfWr7EgSR3CobibRiDm4X1KSEQpEe+laropDl1EogzrkGxFEBItaKNm /mZiYIvohDwdqNZ/T+0m2h2VnznZbZLAKSgBrtiMF61j3/wQQfwKTbyelBxhUh7ui6xg3s1cEqe vZJDPB95Nwg5+iJ00iMBMcxUwWWUQxwGrM1uYxoGQaqea9fgBFaqh8= X-Received: by 2002:a05:690e:4544:10b0:668:99c7:2bc6 with SMTP id 956f58d0204a3-6694f23f018mr216528d50.3.1785510282473; Fri, 31 Jul 2026 08:04:42 -0700 (PDT) Received: from localhost.localdomain (45.78.65.84.16clouds.com. [45.78.65.84]) by smtp.gmail.com with ESMTPSA id 956f58d0204a3-66948cff867sm696184d50.4.2026.07.31.08.04.39 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Fri, 31 Jul 2026 08:04:42 -0700 (PDT) From: Chengfeng Ye To: Eric Van Hensbergen , Latchesar Ionkov , Dominique Martinet , Christian Schoenebeck , Greg Kroah-Hartman , Michael Grzeschik Cc: v9fs@lists.linux.dev, linux-kernel@vger.kernel.org, Chengfeng Ye , stable@vger.kernel.org Subject: [PATCH] net/9p/usbg: fix descriptor cleanup use-after-free Date: Fri, 31 Jul 2026 23:04:14 +0800 Message-ID: <20260731150414.3135662-1-nicoyip.dev@gmail.com> X-Mailer: git-send-email 2.43.0 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit usb9pfs_free_func() frees the f_usb9pfs object before calling usb_free_all_descriptors(). The usb_function passed to the latter is embedded in the freed object, so removing the function from a gadget dereferences freed memory. The failing teardown sequence is: configfs unlink usb9pfs_free_func() kfree(usb9pfs) usb_free_all_descriptors(f) dereference the embedded usb_function KASAN reported: BUG: KASAN: slab-use-after-free in usb_free_all_descriptors+0x138/0x190 Read of size 8 at addr ffff888106a73088 by task poc/95 Call Trace: usb_free_all_descriptors+0x138/0x190 config_usb_cfg_unlink+0x1f0/0x2f0 configfs_unlink+0x321/0x6f0 Free the descriptors before freeing their containing object. Fixes: a3be076dc174 ("net/9p/usbg: Add new usb gadget function transport") Cc: stable@vger.kernel.org Signed-off-by: Chengfeng Ye --- net/9p/trans_usbg.c | 3 +-- 1 file changed, 1 insertion(+), 2 deletions(-) diff --git a/net/9p/trans_usbg.c b/net/9p/trans_usbg.c index 419cda13a7b5..8c2f0d8592c8 100644 --- a/net/9p/trans_usbg.c +++ b/net/9p/trans_usbg.c @@ -725,8 +725,6 @@ static void usb9pfs_free_func(struct usb_function *f) struct f_usb9pfs *usb9pfs = func_to_usb9pfs(f); struct f_usb9pfs_opts *opts; - kfree(usb9pfs); - opts = container_of(f->fi, struct f_usb9pfs_opts, func_inst); mutex_lock(&opts->lock); @@ -734,6 +732,7 @@ static void usb9pfs_free_func(struct usb_function *f) mutex_unlock(&opts->lock); usb_free_all_descriptors(f); + kfree(usb9pfs); } static int usb9pfs_set_alt(struct usb_function *f,