From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-qt1-f169.google.com (mail-qt1-f169.google.com [209.85.160.169]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 4D1D01F7575 for ; Sun, 7 Jun 2026 19:38:10 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.160.169 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1780861091; cv=none; b=gQ0+BQrBGAj2qBuxxOLrN7U+f0w6vs/i3Uu+LbvfrJ2dd0TZLq/z2sRZlO4fDUiU6W/DU3drpufQqR2Yq+8+7a82SgU8wjwz4eoouZaU9bBdZg/O+j58LLMiuj0yID5PVBJBuLLauoB/5vJzWTijHI5EwFpDvTawjWYQXgmsW7E= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1780861091; c=relaxed/simple; bh=e49s5ZMygjJkhqkslb7Q+PN9IBI062nSm7lCNZ65+Ws=; h=Content-Type:Mime-Version:Subject:From:In-Reply-To:Date:Cc: Message-Id:References:To; b=spXk9Fnxoo29wnfvO94jJp2hz9nOdl4NsYGsdFOU/DV7cnddhO5OJhgoKdRKUaiaxoWMJRart7mVwq3giQOET8EQnXZ6BMS7IUmqZt+STfrizy68ptSm2BekCORTO+fR+lQaXiu45GQB8WKN+LmUDgeDFQI9+xClq+JhqDfdnUU= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=fujXnUcL; arc=none smtp.client-ip=209.85.160.169 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="fujXnUcL" Received: by mail-qt1-f169.google.com with SMTP id d75a77b69052e-5176fc0cc72so39263901cf.1 for ; Sun, 07 Jun 2026 12:38:10 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1780861089; x=1781465889; darn=vger.kernel.org; h=to:references:message-id:content-transfer-encoding:cc:date :in-reply-to:from:subject:mime-version:from:to:cc:subject:date :message-id:reply-to; bh=aM9MQJQ9ai9IZOwEAek2Fv0YrNG4OoVA13Fihg9Q4rA=; b=fujXnUcLTakJ9SzAkA2Jvuns8Fv6rNKRCC0vrQso5gabNRpt8t+0mC1IGncOtM0Yfq Y6EnMnwtMKkq9T0WHlyVRBPM5sxNCCs1s2IoydWNMPFPLxPOZ899NHY1k8Tltup2PYdi KBNdKSaYTg/iJ/1SaapX6xcKhi74HqqVb7uKDbTyK8UvJ6O5dYkuImOY5l6lCajHNRnI rabhraeORTbSoXdfm/uNZoL9X1PPIWynTxbExSzUWoznNTixt1hfhlxztFsTIp0nV+pK rcB3bgJfGZ16kHMefoICK4BmOZ4rH+Yp2nViATJE4pNq40egvkqp65jzL1ktZbsujvDu gLhA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1780861089; x=1781465889; h=to:references:message-id:content-transfer-encoding:cc:date :in-reply-to:from:subject:mime-version:x-gm-gg:x-gm-message-state :from:to:cc:subject:date:message-id:reply-to; bh=aM9MQJQ9ai9IZOwEAek2Fv0YrNG4OoVA13Fihg9Q4rA=; b=DkKaelQIPbPdvv6w2+s3hULw0FBudrw6U+yM2o+PS9Y1JQ9iDT2h/MeEjUwNzpwPzg ovSr57ib44K6Q2htlApqbJP0lBAjhV5sohf7EQ5jbgeeCv2cmSsNCkMq9juoWPGKOT0H MJtrbIGmR0rS9u7bdOkmt0mJbxTdwhsVwaQefk/8ThOoBJSaNSJj9S++Pv6g70TkDyDe Tmm1NW5vc4vahO0jmsDV8oyu5EQPCh+X33OhXcLUFMbpRAks+NaYOB4gL+j90BGCd8Qa y1bsZLCuSzHlF8mKVCwESxzPfLEhwhq1Rx05upT9l0S+D90X397Qup08Xbou/eHQ8taR BqNQ== X-Forwarded-Encrypted: i=1; AFNElJ/uNDz06o0QtAs8Jqf3cKLzqkfTF+7S3yp3hlEEjUrAm33LlXMlmKkCybMQvtziKqijLYus2P4hzUSs2+E=@vger.kernel.org X-Gm-Message-State: AOJu0YzR/j4Hh8I0ziRpUh0YQ4ntebDBVNzn/io6zD8SkQ4ZpSM/Xezi MwaaWx0ytT7bo1HA4e43CgUbCtIeCm7F0K4j0TwcCJp5z3sR9uv9/5TXLpxFXQ+H X-Gm-Gg: Acq92OGFl0tU11ua0HDIOXsRdSvcSx4k9ajvxCgcMxruZY+/FeCOKWYWBfQ0Dz8H/Oz XgIUmk/8i8zmargBY1to0zedAPKAi09HeqhrHq7xs+wTUq9R0kTwhi6ARYRd7Yc2BkC+7qVN24/ 47XUhDtzbbM5OrH/+lfSCZcCLO6ElmAlyPaBK3Pu1kS8g5pVD4oCzEi/dLcYr9JAM+O23uhda4T +z1PsLBLAPUA5wnNryjsfs7GLsHNT6dmhIamBHtBmlHFR3Kk1N7Ixr0umQ/NbB10pmhDEVBuBXg VFRR8qhuw0S1E4w9WmF1+sevc+uqYDB1IduVIWA1cYpYudHc7/yM0QQCEXHPZHfYOPuxs01YvqW FdMKEDPEtmuSN9HWGgkluKWqD1pMCZiYbHyQuz18Ufg3amUxJ0S6g3jeL3GHXx0YHEtUSJd/JL8 Ig/5C0ubazTycQ3xK5ouBp76gTJtZ17nvfUTDA3F9pjZ7nHBvKsLlBcpDcwz6A7KOA1wC5k2KlT rs= X-Received: by 2002:ac8:594e:0:b0:517:8d24:64d8 with SMTP id d75a77b69052e-517a12d2d76mr136169521cf.13.1780861089320; Sun, 07 Jun 2026 12:38:09 -0700 (PDT) Received: from smtpclient.apple ([2601:985:4601:5df0:5506:f6a8:9fb3:53d7]) by smtp.gmail.com with ESMTPSA id d75a77b69052e-51775d9efa1sm129725711cf.20.2026.06.07.12.38.08 (version=TLS1_2 cipher=ECDHE-ECDSA-AES128-GCM-SHA256 bits=128/128); Sun, 07 Jun 2026 12:38:09 -0700 (PDT) Content-Type: text/plain; charset=utf-8 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: Mime-Version: 1.0 (Mac OS X Mail 16.0 \(3864.600.51.1.1\)) Subject: Re: [BUG] KASAN: slab-use-after-free in dev_driver_string from chaoskey_release From: Shuangpeng In-Reply-To: <257eb882-44dc-4e25-82f9-9cf9b455936d@rowland.harvard.edu> Date: Sun, 7 Jun 2026 15:37:37 -0400 Cc: keithp@keithp.com, gregkh@linuxfoundation.org, linux-usb@vger.kernel.org, linux-kernel@vger.kernel.org Content-Transfer-Encoding: quoted-printable Message-Id: References: <20EC9664-054E-438B-B411-2145D347F97B@gmail.com> <257eb882-44dc-4e25-82f9-9cf9b455936d@rowland.harvard.edu> To: Alan Stern X-Mailer: Apple Mail (2.3864.600.51.1.1) > On Jun 6, 2026, at 22:29, Alan Stern = wrote: >=20 > On Sat, Jun 06, 2026 at 09:31:30PM -0400, Shuangpeng wrote: >> Hi Kernel Maintainers, >>=20 >> I hit the following KASAN report while testing current upstream = kernel: >>=20 >> KASAN: slab-use-after-free in dev_driver_string from chaoskey_release >>=20 >> on commit: e8c2f9fdadee7cbc75134dc463c1e0d856d6e5c7 (May 25 2026) >>=20 >> The reproducer and .config files are here. >> = https://gist.github.com/shuangpengbai/167620d391d9634107bfe4d784fcf52b >>=20 >> I=E2=80=99m happy to test debug patches or provide additional = information. >>=20 >> Reported-by: Shuangpeng Bai >>=20 >>=20 >> [ 2019.816807][T10106] = =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D >> [ 2019.819081][T10106] BUG: KASAN: slab-use-after-free in = dev_driver_string (drivers/base/core.c:2406) >> [ 2019.820996][T10106] Read of size 8 at addr ffff888168e8a0b8 by = task chaoskey_raw_re/10106 >> [ 2019.822432][T10106] >> [ 2019.822899][T10106] Hardware name: QEMU Ubuntu 24.04 PC v2 (i440FX = + PIIX, arch_caps fix, 1996), BIOS 1.16.3-debian-1.16.3-2 04/01/2014 >> [ 2019.822904][T10106] Call Trace: >> [ 2019.822910][T10106] >> [ 2019.822915][T10106] dump_stack_lvl (lib/dump_stack.c:94 = lib/dump_stack.c:120) >> [ 2019.822932][T10106] print_report (mm/kasan/report.c:378 = mm/kasan/report.c:482) >> [ 2019.822984][T10106] kasan_report (mm/kasan/report.c:595) >> [ 2019.823015][T10106] dev_driver_string (drivers/base/core.c:2406) >> [ 2019.823021][T10106] __dynamic_dev_dbg (lib/dynamic_debug.c:906) >> [ 2019.823282][T10106] chaoskey_release = (drivers/usb/misc/chaoskey.c:323) >=20 > The simple explanation is that the chaoskey_release() routine contains=20= > debugging statements that reference an interface for the USB device = even=20 > after that data structure may have been deallocated. Since they are=20= > merely debugging statements, the simplest solution to the problem is = to=20 > get rid of them. >=20 > That's what the patch below does. You can try it out and see if it=20 > works. I tried this patch and the bug is no longer triggered on my side. Thanks for your fix! >=20 > Alan Stern >=20 >=20 >=20 > Index: usb-devel/drivers/usb/misc/chaoskey.c > =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D= =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D > --- usb-devel.orig/drivers/usb/misc/chaoskey.c > +++ usb-devel/drivers/usb/misc/chaoskey.c > @@ -294,15 +294,10 @@ static int chaoskey_release(struct inode >=20 > interface =3D dev->interface; >=20 > - usb_dbg(interface, "release"); > - > mutex_lock(&chaoskey_list_lock); > mutex_lock(&dev->lock); >=20 > - usb_dbg(interface, "open count at release is %d", dev->open); > - > if (dev->open <=3D 0) { > - usb_dbg(interface, "invalid open count (%d)", dev->open); > rv =3D -ENODEV; > goto bail; > } > @@ -320,7 +315,6 @@ bail: > mutex_unlock(&dev->lock); > destruction: > mutex_unlock(&chaoskey_list_lock); > - usb_dbg(interface, "release success"); > return rv; > }