From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-oi1-f198.google.com (mail-oi1-f198.google.com [209.85.167.198]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 7737F484232 for ; Fri, 21 Aug 2026 11:23:21 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.167.198 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787311405; cv=none; b=FwYzRW9MPjMzZORbEFmQ6OIWOL8sXj9+2+L6YFsAwsxKe28pQLyujT6XZoatW5zPyfIOeFnPTuOVM9oQQYAtySriuaGIchnjC8/m/kiOBTF0sN2NEuEWFj802+gsSK9sRez4AyR9aRe6NIeVDLhH9xrFUlNSbK9757v6f5+PgIo= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1787311405; c=relaxed/simple; bh=aUarH8n35ruBdUYmpIX6qr9MAhLOA0HV6NJUOLGkX4s=; h=MIME-Version:Date:In-Reply-To:Message-ID:Subject:From:To: Content-Type; b=HE+9CETDQhQ08mWPV3Gw1ksVvToBby5ELxItR3eMTvdroOPYWcxOhqJ8vGH3yQKhD5s1P2z8bOVtDJBun4sF4AqQy46wgCCd0GiWj09P2Yf94kr5Kg94o+nHMHVlIggJ0XX29iI7il8GLARboFD4cAfn0CjzjyqOx7perg7RKZE= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=fail (p=none dis=none) header.from=syzkaller.appspotmail.com; spf=pass smtp.mailfrom=M3KW2WVRGUFZ5GODRSRYTGD7.apphosting.bounces.google.com; arc=none smtp.client-ip=209.85.167.198 Authentication-Results: smtp.subspace.kernel.org; dmarc=fail (p=none dis=none) header.from=syzkaller.appspotmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=M3KW2WVRGUFZ5GODRSRYTGD7.apphosting.bounces.google.com Received: by mail-oi1-f198.google.com with SMTP id 5614622812f47-4ab4f652f9bso809765b6e.0 for ; Fri, 21 Aug 2026 04:23:20 -0700 (PDT) X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1787311399; x=1787916199; h=content-type:to:from:subject:message-id:in-reply-to:date :mime-version:x-gm-message-state:from:to:cc:subject:date:message-id :reply-to:content-type; bh=RZNcXlT+Ha2hBviUaFY625kQFIo950805SWRjsWcJ14=; b=koIwVGwQOOvCf2ocWlQl2wrGOcp1TmBKEdOt8WzqD8uhVc3Qziv7P+8NeFkLpx7Dba PECpVIVDWSePO1GSYsJIRuCf/x7cfG86P8GoTGOMroLB9D3ZpDrDsWe7NfhazVYbfPpm 7TI8zdjBb8PgrOyHryyVFt9zSluXVfS/LoNClW2ubnWcL2+hsTeNJjMiMUi6uaWzw0+8 Mn+K5F082cyVNji5CetK05sq7Og3uKTfquYhNQzkcEVpDK0jNpxjGktAb7slPjzE0Jwx jMbVUghBWIPq3O57OKqgniU7iyzOZWlNEzZllrS+KKAa/ZCBosxqi/sfDmfzB7t6Uunx YcLg== X-Gm-Message-State: AOJu0Yx7R6vC39enEHIp2s1kpmzvttP3oJJ4JIR/GA5F3VvmykXg6Y59 XYyFZwiPf19xCYI7V7w2WoANPECUm9/7ptEwoGVKTJXdWXEVxGCFH5ShpQiuLSa9qyYfxOZzktO +V6tFKfXiao2VgkzP7DnnAqwWVxolsxkhDg6JjbaBpt/ZZvxiW/RVIBVyhXg= Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 X-Received: by 2002:a05:6808:c1e1:b0:491:3ade:8ba0 with SMTP id 5614622812f47-4b2ef3ab657mr5137409b6e.16.1787311399621; Fri, 21 Aug 2026 04:23:19 -0700 (PDT) Date: Fri, 21 Aug 2026 04:23:19 -0700 In-Reply-To: <6a88066b.ae6ddae5.3da009.002c.GAE@google.com> X-Google-Appengine-App-Id: s~syzkaller X-Google-Appengine-App-Id-Alias: syzkaller Message-ID: <6a883527.ae6ddae5.3da009.0036.GAE@google.com> Subject: Forwarded: [PATCH] usb: gadget: net2280: fix NULL pointer deref in usb_reinit_338x() From: syzbot To: linux-kernel@vger.kernel.org, syzkaller-bugs@googlegroups.com Content-Type: text/plain; charset="UTF-8" For archival purposes, forwarding an incoming command email to linux-kernel@vger.kernel.org, syzkaller-bugs@googlegroups.com. *** Subject: [PATCH] usb: gadget: net2280: fix NULL pointer deref in usb_reinit_338x() Author: kartikey406@gmail.com #syz test: git://git.kernel.org/pub/scm/linux/kernel/git/arm64/linux.git for-kernelci net2280_probe() only maps dev->llregs when the PLX_PCIE quirk bit is set. usb_reinit() dispatches to usb_reinit_338x() for any device that doesn't have PLX_LEGACY set, assuming such a device must have PLX_PCIE set (and thus llregs mapped). That assumption holds for every entry in the driver's pci_device_id table, but a forced driver bind (e.g. via sysfs bind/driver_override) can invoke probe() with quirks that have neither bit set, leaving llregs NULL and crashing in usb_reinit_338x() on the first readl(). Reject probe() early when quirks has neither PLX_LEGACY nor PLX_PCIE set, instead of proceeding into a reinit path that assumes one of them is always present. Reported-by: syzbot+2ec7fc1793a63864d9d6@syzkaller.appspotmail.com Closes: https://syzkaller.appspot.com/bug?extid=2ec7fc1793a63864d9d6 Signed-off-by: Deepanshu Kartikey --- drivers/usb/gadget/udc/net2280.c | 11 +++++++++++ 1 file changed, 11 insertions(+) diff --git a/drivers/usb/gadget/udc/net2280.c b/drivers/usb/gadget/udc/net2280.c index 7c5f30cfd24d..02d12c2ad58b 100644 --- a/drivers/usb/gadget/udc/net2280.c +++ b/drivers/usb/gadget/udc/net2280.c @@ -3708,6 +3708,17 @@ static int net2280_probe(struct pci_dev *pdev, const struct pci_device_id *id) writel(0, &dev->usb->usbctl); } + /* usb_reinit() dispatches on PLX_LEGACY vs PLX_PCIE and assumes + * every non-legacy chip has llregs mapped (PLX_PCIE branch above). + * A forced/mismatched driver bind can hand us quirks that satisfy + * neither, so refuse to proceed rather than dereference NULL. + */ + if (!(dev->quirks & (PLX_LEGACY | PLX_PCIE))) { + ep_err(dev, "unsupported device (quirks=%#lx)\n", dev->quirks); + retval = -ENODEV; + goto done; + } + usb_reset(dev); usb_reinit(dev); -- 2.43.0