mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: Shuangpeng <shuangpeng.kernel@gmail.com>
To: Greg KH <gregkh@linuxfoundation.org>
Cc: heikki.krogerus@linux.intel.com, linux-usb@vger.kernel.org,
	linux-kernel@vger.kernel.org
Subject: Re: [BUG] KASAN: slab-out-of-bounds in select_usb_power_delivery_show
Date: Sun, 14 Jun 2026 15:11:16 -0400	[thread overview]
Message-ID: <B2D6F550-93F0-4957-8DF0-E1D544DA5694@gmail.com> (raw)
In-Reply-To: <2026061454-pep-avenging-9656@gregkh>



> On Jun 14, 2026, at 13:32, Greg KH <gregkh@linuxfoundation.org> wrote:
> 
> On Sun, Jun 14, 2026 at 01:28:36PM -0400, Shuangpeng wrote:
>> 
>> 
>>> On Jun 14, 2026, at 12:37, Greg KH <gregkh@linuxfoundation.org> wrote:
>>> 
>>> On Sun, Jun 14, 2026 at 11:22:45AM -0400, Shuangpeng Bai wrote:
>>>> Hi Kernel Maintainers,
>>>> 
>>>> I hit the following report while testing current upstream kernel:
>>>> 
>>>> KASAN: slab-out-of-bounds in select_usb_power_delivery_show
>>>> 
>>>> on commit: e8c2f9fdadee7cbc75134dc463c1e0d856d6e5c7 (May 25 2026)
>>> 
>>> What about the latest tree?
>> 
>> I retested it on the latest Linus tree:
>> 
>> 424280953322cf66314f3ba5e2d1ef345f21c770
>> 
>> The same bug still reproduces there.
>> 
>>>> 
>>>> The reproducer and .config files are here.
>>>> https://gist.github.com/shuangpengbai/79c08ada299b3ae37b7a0af292ca413f
>>>> 
>>>> I'm happy to test debug patches or provide additional information.
>>>> 
>>>> Reported-by: Shuangpeng Bai <shuangpeng.kernel@gmail.com>
>>>> 
>>>> [  102.318332] BUG: KASAN: slab-out-of-bounds in select_usb_power_delivery_show (drivers/usb/typec/class.c:1642)
>>>> [  102.319225] Read of size 8 at addr ffff888117d2f2c0 by task cat/8378
>>>> [  102.319943] Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2 04/01/2014
>>> 
>>> Does this happen on real hardware, or just on emulated hardware?
>> 
>> I have only reproduced it in QEMU so far, not on real hardware.
>> The repro uses QEMU to emulate the hardware environment needed to load the
>> FUSB302/TCPM driver path. I have not tested whether the same issue happens on
>> physical hardware.
>> 
>> Please let me know if any additional information would be helpful.
> 
> If you could test on real hardware, that would be best.  How do we know
> that qemu is actually correct?  :)

Thanks for the clarification, that makes sense.

Unfortunately, I do not have real FUSB302/TCPM hardware available to test this
on, so I cannot confirm whether it happens on physical hardware.

> thanks,
> 
> greg k-h



      reply	other threads:[~2026-06-14 19:11 UTC|newest]

Thread overview: 5+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-06-14 15:22 Shuangpeng Bai
2026-06-14 16:37 ` Greg KH
2026-06-14 17:28   ` Shuangpeng
2026-06-14 17:32     ` Greg KH
2026-06-14 19:11       ` Shuangpeng [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=B2D6F550-93F0-4957-8DF0-E1D544DA5694@gmail.com \
    --to=shuangpeng.kernel@gmail.com \
    --cc=gregkh@linuxfoundation.org \
    --cc=heikki.krogerus@linux.intel.com \
    --cc=linux-kernel@vger.kernel.org \
    --cc=linux-usb@vger.kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®