From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-oi1-f199.google.com (mail-oi1-f199.google.com [209.85.167.199]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 42444171B1 for ; Sun, 2 Aug 2026 00:04:19 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.167.199 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785629060; cv=none; b=uulC3SI758EyxGTL8QNmAn3ctBpxXewSQjquPTMow8gmtrtT17JwLkNy4mkGZic+2cwIcBolzIv3gP3y30bhZ/O0Q5u5eGZYm0s5YYYXQUtt4hoMlj38x6wYLunjxZXdMajA1NppT0QDfiUktVaYPmzhR1U1uOHYSNCchCg3qS4= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785629060; c=relaxed/simple; bh=8c0288p9dx9f3hvAjJ3mv9ZY4X/6vsezwbB43LzCwA8=; h=MIME-Version:Date:In-Reply-To:Message-ID:Subject:From:To: Content-Type; b=CdMipQmPYulwKLomenxmfUN4itGSVT8WclysFJC12i81Lw2OCbtIqkbpuGQcA5Kk/bHZ6jlnsdxtkiut6eEieQCTiYbdqV4HCT4WYALh3reAEi33u+r8ESkJWEVcvI1HdPjqtERJvceGZVva+iRCmUPJRk8e72Cmsi38lFtDVuI= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=fail (p=none dis=none) header.from=syzkaller.appspotmail.com; spf=pass smtp.mailfrom=M3KW2WVRGUFZ5GODRSRYTGD7.apphosting.bounces.google.com; arc=none smtp.client-ip=209.85.167.199 Authentication-Results: smtp.subspace.kernel.org; dmarc=fail (p=none dis=none) header.from=syzkaller.appspotmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=M3KW2WVRGUFZ5GODRSRYTGD7.apphosting.bounces.google.com Received: by mail-oi1-f199.google.com with SMTP id 5614622812f47-4a41e3d6fe9so3124176b6e.2 for ; Sat, 01 Aug 2026 17:04:19 -0700 (PDT) X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785629058; x=1786233858; h=content-type:to:from:subject:message-id:in-reply-to:date :mime-version:x-gm-message-state:from:to:cc:subject:date:message-id :reply-to:content-type; bh=Y7X6lsydjjs4B72yOMOvMwmsiMb5hO6UuDNPIEmDU64=; b=p6dWaElLUk0L/qKVFZSjSUPKTHGa+LNQlSnBRxjxNikT9S9l5sjmjSbJPIqcpxQPbB o8OZsX+XhQgWrUD1KP4cgzU6asHAhPbW663ljFPkMXi4E/qNqsoefFea3tqy25O99SwG PE37J2ooX0ChB0U0RPzUULUAPQBHSRFLIfEfwcUpG7BIDehZUJwftZ6A2G/2iZCW4dtL NA2t2EP0relqBRO220XXqfX1fJSMMKkTRjUOtb2ptIPxkU182pgHyX8236T3BbI/qK7W 9o+JEyNiZ4+Mok/8X4WsmYXC7Fy1P0r7/meGaUxPaGnBy1ntAxDowHqI3HDWq5rdGY9V 9Wwg== X-Gm-Message-State: AOJu0YxWAyDzokr75R8knjsTXrdGxcUhPDpgm7inj19P+3TN033E4wpp PHkP1IxNjBx8YdnQHpv+SQ9aXAUSuj7v10TlnhlUFaJMWVwmP2mZs30Eo81d43yVxNu0MNUaHqg 7UCc7sJDeS1EJXvSz1gw3gSwfZHtseK0W+n2c+B8/p37Xt2xq/5fM939fR+Y= Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 X-Received: by 2002:a05:6808:1b8f:b0:497:d1e7:5e90 with SMTP id 5614622812f47-4af5e2927e6mr9354516b6e.18.1785629058248; Sat, 01 Aug 2026 17:04:18 -0700 (PDT) Date: Sat, 01 Aug 2026 17:04:18 -0700 In-Reply-To: <6a6be82a.77639fcc.3d4fd0.0012.GAE@google.com> X-Google-Appengine-App-Id: s~syzkaller X-Google-Appengine-App-Id-Alias: syzkaller Message-ID: <6a6e8982.2d659fcc.1d46f5.01c6.GAE@google.com> Subject: Forwarded: #syz test From: syzbot To: linux-kernel@vger.kernel.org, syzkaller-bugs@googlegroups.com Content-Type: text/plain; charset="UTF-8" For archival purposes, forwarding an incoming command email to linux-kernel@vger.kernel.org, syzkaller-bugs@googlegroups.com. *** Subject: #syz test Author: rwarwatkar@gmail.com >From 89443f65c32564e688448a39ba54cd13a1f8ef67 Mon Sep 17 00:00:00 2001 From: Rituparna Warwatkar Date: Sat, 1 Aug 2026 23:38:07 +0000 Subject: [PATCH] usb: gadget: f_uac2: fix memory leak in sample rate store f_uac2_opts_{p,c}_srate_store() duplicate the input page with kstrdup() and then tokenize it with strsep(&split_page, ","). strsep() advances the pointer it is given, so by the time the parsing loop finishes split_page points at the end of the string (or NULL). The subsequent kfree(split_page) therefore frees the wrong pointer (NULL when the whole buffer was consumed), leaking the buffer allocated by kstrdup(): BUG: memory leak unreferenced object 0xffff888112a01e00 (size 64): kstrdup f_uac2_opts_c_srate_store configfs_write_iter vfs_write ksys_write Keep the original allocation in split_page and hand a separate iterator to strsep(), so the buffer is always freed. While at it, handle a kstrdup() failure instead of dereferencing NULL. Both the p_srate and c_srate attributes use the same macro and are fixed together. Fixes: a7339e4f5788 ("usb: gadget: f_uac2: Support multiple sampling rates") Reported-by: syzbot+ebd045a6645cfb713c95@syzkaller.appspotmail.com Closes: https://syzkaller.appspot.com/bug?extid=ebd045a6645cfb713c95 Signed-off-by: Rituparna Warwatkar --- drivers/usb/gadget/function/f_uac2.c | 8 +++++++- 1 file changed, 7 insertions(+), 1 deletion(-) diff --git a/drivers/usb/gadget/function/f_uac2.c b/drivers/usb/gadget/function/f_uac2.c index 897787d0803..8facf289710 100644 --- a/drivers/usb/gadget/function/f_uac2.c +++ b/drivers/usb/gadget/function/f_uac2.c @@ -2013,6 +2013,7 @@ static ssize_t f_uac2_opts_##name##_store(struct config_item *item, \ { \ struct f_uac2_opts *opts = to_f_uac2_opts(item); \ char *split_page = NULL; \ + char *rest; \ int ret = -EINVAL; \ char *token; \ u32 num; \ @@ -2027,7 +2028,12 @@ static ssize_t f_uac2_opts_##name##_store(struct config_item *item, \ i = 0; \ memset(opts->name##s, 0x00, sizeof(opts->name##s)); \ split_page = kstrdup(page, GFP_KERNEL); \ - while ((token = strsep(&split_page, ",")) != NULL) { \ + if (!split_page) { \ + ret = -ENOMEM; \ + goto end; \ + } \ + rest = split_page; \ + while ((token = strsep(&rest, ",")) != NULL) { \ ret = kstrtou32(token, 0, &num); \ if (ret) \ goto end; \ -- 2.47.3