From: Shuangpeng <shuangpeng.kernel@gmail.com>
To: Greg KH <gregkh@linuxfoundation.org>
Cc: heikki.krogerus@linux.intel.com, linux-usb@vger.kernel.org,
linux-kernel@vger.kernel.org
Subject: Re: [BUG] KASAN: slab-out-of-bounds in select_usb_power_delivery_show
Date: Sun, 14 Jun 2026 15:11:16 -0400 [thread overview]
Message-ID: <B2D6F550-93F0-4957-8DF0-E1D544DA5694@gmail.com> (raw)
In-Reply-To: <2026061454-pep-avenging-9656@gregkh>
> On Jun 14, 2026, at 13:32, Greg KH <gregkh@linuxfoundation.org> wrote:
>
> On Sun, Jun 14, 2026 at 01:28:36PM -0400, Shuangpeng wrote:
>>
>>
>>> On Jun 14, 2026, at 12:37, Greg KH <gregkh@linuxfoundation.org> wrote:
>>>
>>> On Sun, Jun 14, 2026 at 11:22:45AM -0400, Shuangpeng Bai wrote:
>>>> Hi Kernel Maintainers,
>>>>
>>>> I hit the following report while testing current upstream kernel:
>>>>
>>>> KASAN: slab-out-of-bounds in select_usb_power_delivery_show
>>>>
>>>> on commit: e8c2f9fdadee7cbc75134dc463c1e0d856d6e5c7 (May 25 2026)
>>>
>>> What about the latest tree?
>>
>> I retested it on the latest Linus tree:
>>
>> 424280953322cf66314f3ba5e2d1ef345f21c770
>>
>> The same bug still reproduces there.
>>
>>>>
>>>> The reproducer and .config files are here.
>>>> https://gist.github.com/shuangpengbai/79c08ada299b3ae37b7a0af292ca413f
>>>>
>>>> I'm happy to test debug patches or provide additional information.
>>>>
>>>> Reported-by: Shuangpeng Bai <shuangpeng.kernel@gmail.com>
>>>>
>>>> [ 102.318332] BUG: KASAN: slab-out-of-bounds in select_usb_power_delivery_show (drivers/usb/typec/class.c:1642)
>>>> [ 102.319225] Read of size 8 at addr ffff888117d2f2c0 by task cat/8378
>>>> [ 102.319943] Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2 04/01/2014
>>>
>>> Does this happen on real hardware, or just on emulated hardware?
>>
>> I have only reproduced it in QEMU so far, not on real hardware.
>> The repro uses QEMU to emulate the hardware environment needed to load the
>> FUSB302/TCPM driver path. I have not tested whether the same issue happens on
>> physical hardware.
>>
>> Please let me know if any additional information would be helpful.
>
> If you could test on real hardware, that would be best. How do we know
> that qemu is actually correct? :)
Thanks for the clarification, that makes sense.
Unfortunately, I do not have real FUSB302/TCPM hardware available to test this
on, so I cannot confirm whether it happens on physical hardware.
> thanks,
>
> greg k-h
prev parent reply other threads:[~2026-06-14 19:11 UTC|newest]
Thread overview: 5+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-06-14 15:22 Shuangpeng Bai
2026-06-14 16:37 ` Greg KH
2026-06-14 17:28 ` Shuangpeng
2026-06-14 17:32 ` Greg KH
2026-06-14 19:11 ` Shuangpeng [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=B2D6F550-93F0-4957-8DF0-E1D544DA5694@gmail.com \
--to=shuangpeng.kernel@gmail.com \
--cc=gregkh@linuxfoundation.org \
--cc=heikki.krogerus@linux.intel.com \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-usb@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®