From: Danilo Krummrich <dakr@kernel.org>
To: gregkh@linuxfoundation.org, rafael.j.wysocki@intel.com,
dakr@kernel.org, johan@kernel.org
Cc: linux-usb@vger.kernel.org, driver-core@lists.linux.dev,
linux-kernel@vger.kernel.org, stable@kernel.org
Subject: [PATCH] usb: core: don't set drvdata to NULL in usb_unbind_interface()
Date: Fri, 2 Oct 2026 16:52:49 +0200 [thread overview]
Message-ID: <20261002145455.3392703-1-dakr@kernel.org> (raw)
usb_unbind_interface() serves as the remove() callback of struct
usb_driver and calls usb_set_intfdata(intf, NULL) to clear the bus
device private data pointer.
However, the driver core code already sets the bus device private data
pointer to NULL in device_unbind_cleanup() *after* devres_release_all(),
which makes the call redundant.
In addition, it can create unexpected NULL pointer dereference scenarios
when drivers use managed APIs.
int probe(struct usb_interface *intf,
const struct usb_device_id *id)
{
struct data *data;
int ret;
data = devm_kzalloc(&intf->dev, sizeof(*data), GFP_KERNEL);
if (!data)
return -ENOMEM;
ret = devm_device_add_group(&intf->dev, &foo_attr_group);
if (ret)
return ret;
...
}
ssize_t foo_value_show(struct device *dev, struct device_attribute *attr,
char *buf)
{
struct usb_interface *intf = to_usb_interface(dev);
struct data *data = usb_get_intfdata(intf);
/* Potential NULL pointer dereference */
return sysfs_emit(buf, "%u\n", data->value);
}
Nothing prevents usb_unbind_interface() to race with foo_value_show()
and set usb_set_intfdata(intf, NULL).
Besides that, the Rust driver core code manages a driver's bus device
private data and destroys it in device_unbind_cleanup().
If usb_unbind_interface() sets the pointer to NULL prematurely, the Rust
driver core code sees NULL, and hence skips the destructor of the bus
device private data, which leaks all its resources.
Thus, drop usb_set_intfdata(intf, NULL) from usb_unbind_interface() and
move it to usb_driver_release_interface(), which manually calls the
remove() callback of struct usb_driver, and hence can't rely on the
driver core.
Cc: stable@kernel.org
Fixes: a995fe1a3aa7 ("rust: driver: drop device private data post unbind")
Signed-off-by: Danilo Krummrich <dakr@kernel.org>
---
drivers/usb/core/driver.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/drivers/usb/core/driver.c b/drivers/usb/core/driver.c
index 7f33fe5ba03b..412174270fbf 100644
--- a/drivers/usb/core/driver.c
+++ b/drivers/usb/core/driver.c
@@ -497,7 +497,6 @@ static int usb_unbind_interface(struct device *dev)
} else {
intf->needs_altsetting0 = 1;
}
- usb_set_intfdata(intf, NULL);
intf->condition = USB_INTERFACE_UNBOUND;
intf->needs_remote_wakeup = 0;
@@ -644,6 +643,7 @@ void usb_driver_release_interface(struct usb_driver *driver,
} else {
device_lock(dev);
usb_unbind_interface(dev);
+ dev_set_drvdata(dev, NULL);
dev->driver = NULL;
device_unlock(dev);
}
base-commit: ce1e0223d8ad4211275c82a17ed6d43ab81e13d9
--
2.56.0
next reply other threads:[~2026-10-02 14:59 UTC|newest]
Thread overview: 2+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-10-02 14:52 Danilo Krummrich [this message]
2026-10-02 18:28 ` Alan Stern
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20261002145455.3392703-1-dakr@kernel.org \
--to=dakr@kernel.org \
--cc=driver-core@lists.linux.dev \
--cc=gregkh@linuxfoundation.org \
--cc=johan@kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-usb@vger.kernel.org \
--cc=rafael.j.wysocki@intel.com \
--cc=stable@kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®