mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: Michal Pecio <michal.pecio@gmail.com>
To: Greg Kroah-Hartman <gregkh@linuxfoundation.org>,
	Alan Stern <stern@rowland.harvard.edu>,
	Oliver Neukum <oneukum@suse.com>,
	Ming Lei <ming.lei@canonical.com>
Cc: linux-usb@vger.kernel.org, linux-kernel@vger.kernel.org
Subject: Re: [PATCH] usb: hcd: Cancel BH giveback works on removal
Date: Fri, 2 Oct 2026 23:33:00 +0200	[thread overview]
Message-ID: <20261002233300.705d5a7f.michal.pecio@gmail.com> (raw)
In-Reply-To: <20260823125831.6ea35650.michal.pecio@gmail.com>

On Sun, 23 Aug 2026 12:58:31 +0200, Michal Pecio wrote:
> Turns out, we do actually need to flush them, because workers use the
> 'high_prio_bh' and 'low_prio_bh' members of 'usb_hcd' for a brief time
> after all URBs are completed to track pending completions and possibly
> reschedule themselves, see usb_giveback_urb_bh() implementation.
> 
> Flushing would suffice if the works don't reschedule themselves, but
> cancel_work_sync() is more robust against stray completions.
> 
> Syzbot may have found the issue due to unlucky hard IRQ timing. It can
> be reproduced by adding udelay(3000) in the work function, disabling RH
> autosuspend to maintain the status URB and unbinding a real HC:
> 
> [10818.828029] ehci-pci 0000:00:12.0: USB bus 1 deregistered
> [10818.828077] hcd_release freeing high_prio_bh ffff88814a950978
> [10818.829211] usb_giveback_urb_bh still running on bh ffff88814a950978
> 
> Reported-by: syzbot+cade843a1e4af0651f5e@syzkaller.appspotmail.com
> Link: https://lore.kernel.org/linux-usb/6a8a5047.dbb3a75c.13dd47.003e.GAE@google.com/
> Fixes: 94dfd7edfd5c ("USB: HCD: support giveback of URB in tasklet context")
> Cc: stable@vger.kernel.org
> Signed-off-by: Michal Pecio <michal.pecio@gmail.com>
> ---

Hi Greg,

Any interest in this fix? If you think it's too theoretical I can
drop the stable tag, but this code just isn't really correct.

Syzbot has found another case: primary HCD of vhci-hcd is freed
if secondary HCD creation fails (e.g. USB bus number limit). This
(again) races with the giveback work still using the primary HCD
after unlinking its root hub URB.

https://lore.kernel.org/linux-usb/6abb3515.c6a7fab7.e5ea7.0459.GAE@google.com/

> slab-use-after-free in usb_giveback_urb_bh+0x441/0x560 drivers/usb/core/hcd.c:1692
>
> Freed by task 1:
> hcd_release drivers/usb/core/hcd.c:2690 [inline]
> kref_put include/linux/kref.h:65 [inline]
> usb_put_hcd drivers/usb/core/hcd.c:2704 [inline]
> usb_put_hcd+0x149/0x1f0 drivers/usb/core/hcd.c:2701
> vhci_hcd_probe+0x342/0x4e0 drivers/usb/usbip/vhci_hcd.c:1415
>
> Last potentially related work creation:
> queue_work include/linux/workqueue.h:700 [inline]
> usb_hcd_giveback_urb+0x330/0x4a0 drivers/usb/core/hcd.c:1758
> usb_rh_urb_dequeue drivers/usb/core/hcd.c:845 [inline]
> unlink1+0x418/0x510 drivers/usb/core/hcd.c:1580

Regards,
Michal

      parent reply	other threads:[~2026-10-02 21:33 UTC|newest]

Thread overview: 4+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-08-23 10:58 Michal Pecio
2026-08-23 14:31 ` Alan Stern
2026-08-23 17:26   ` Michal Pecio
2026-10-02 21:33 ` Michal Pecio [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20261002233300.705d5a7f.michal.pecio@gmail.com \
    --to=michal.pecio@gmail.com \
    --cc=gregkh@linuxfoundation.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=linux-usb@vger.kernel.org \
    --cc=ming.lei@canonical.com \
    --cc=oneukum@suse.com \
    --cc=stern@rowland.harvard.edu \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®