* [PATCH] USB: sierra: Fix urb leak in sierra_submit_delayed_urbs()
@ 2026-09-16 16:53 Wentao Liang
2026-09-17 9:00 ` Johan Hovold
0 siblings, 1 reply; 3+ messages in thread
From: Wentao Liang @ 2026-09-16 16:53 UTC (permalink / raw)
To: gregkh; +Cc: johan, linux-kernel, linux-usb, oliver, Wentao Liang, stable
sierra_submit_delayed_urbs() takes a reference to each delayed urb
with usb_get_from_anchor() before submitting it. The submit failure
path releases the reference with usb_free_urb(), but on the success
path the reference is never dropped: the urb is only anchored in the
active list and the USB core unanchors it on completion, leaving the
reference returned by usb_get_from_anchor() dangling so the urb
object is never freed.
Drop the reference with usb_put_urb() after a successful submission,
matching the reference handling in sierra_write() and the sierra_close()
drain loop. Skip the rest of the loop body with continue on the error
path, which already frees the urb.
Fixes: e6929a9020ac ("USB: support for autosuspend in sierra while online")
Cc: stable@vger.kernel.org
Signed-off-by: Wentao Liang <vulab@iscas.ac.cn>
---
drivers/usb/serial/sierra.c | 2 ++
1 file changed, 2 insertions(+)
diff --git a/drivers/usb/serial/sierra.c b/drivers/usb/serial/sierra.c
index 6e443aacae07..c11259a8e66c 100644
--- a/drivers/usb/serial/sierra.c
+++ b/drivers/usb/serial/sierra.c
@@ -977,7 +977,9 @@ static int sierra_submit_delayed_urbs(struct usb_serial_port *port)
spin_lock(&portdata->lock);
portdata->outstanding_urbs--;
spin_unlock(&portdata->lock);
+ continue;
}
+ usb_put_urb(urb);
}
if (ec)
--
2.34.1
^ permalink raw reply [flat|nested] 3+ messages in thread
* Re: [PATCH] USB: sierra: Fix urb leak in sierra_submit_delayed_urbs()
2026-09-16 16:53 [PATCH] USB: sierra: Fix urb leak in sierra_submit_delayed_urbs() Wentao Liang
@ 2026-09-17 9:00 ` Johan Hovold
2026-10-09 12:40 ` Johan Hovold
0 siblings, 1 reply; 3+ messages in thread
From: Johan Hovold @ 2026-09-17 9:00 UTC (permalink / raw)
To: Wentao Liang; +Cc: gregkh, linux-kernel, linux-usb, oliver, stable
On Wed, Sep 16, 2026 at 04:53:52PM +0000, Wentao Liang wrote:
> sierra_submit_delayed_urbs() takes a reference to each delayed urb
> with usb_get_from_anchor() before submitting it. The submit failure
> path releases the reference with usb_free_urb(), but on the success
> path the reference is never dropped: the urb is only anchored in the
> active list and the USB core unanchors it on completion, leaving the
> reference returned by usb_get_from_anchor() dangling so the urb
> object is never freed.
>
> Drop the reference with usb_put_urb() after a successful submission,
> matching the reference handling in sierra_write() and the sierra_close()
> drain loop. Skip the rest of the loop body with continue on the error
> path, which already frees the urb.
>
> Fixes: e6929a9020ac ("USB: support for autosuspend in sierra while online")
> Cc: stable@vger.kernel.org
> Signed-off-by: Wentao Liang <vulab@iscas.ac.cn>
This looks correct, but as Greg already asked you elsewhere, did you
forget to add an Assisted-by tag here as well? How was this issue found
and fixed?
Also, you need to start replying to feedback. According to the list
archives you have haven't replied to any of the four mails commenting on
your patches that I've sent you so far.
Johan
^ permalink raw reply [flat|nested] 3+ messages in thread
* Re: [PATCH] USB: sierra: Fix urb leak in sierra_submit_delayed_urbs()
2026-09-17 9:00 ` Johan Hovold
@ 2026-10-09 12:40 ` Johan Hovold
0 siblings, 0 replies; 3+ messages in thread
From: Johan Hovold @ 2026-10-09 12:40 UTC (permalink / raw)
To: Wentao Liang; +Cc: gregkh, linux-kernel, linux-usb, oliver, stable
On Thu, Sep 17, 2026 at 11:00:54AM +0200, Johan Hovold wrote:
> On Wed, Sep 16, 2026 at 04:53:52PM +0000, Wentao Liang wrote:
> > sierra_submit_delayed_urbs() takes a reference to each delayed urb
> > with usb_get_from_anchor() before submitting it. The submit failure
> > path releases the reference with usb_free_urb(), but on the success
> > path the reference is never dropped: the urb is only anchored in the
> > active list and the USB core unanchors it on completion, leaving the
> > reference returned by usb_get_from_anchor() dangling so the urb
> > object is never freed.
> >
> > Drop the reference with usb_put_urb() after a successful submission,
> > matching the reference handling in sierra_write() and the sierra_close()
> > drain loop. Skip the rest of the loop body with continue on the error
> > path, which already frees the urb.
> >
> > Fixes: e6929a9020ac ("USB: support for autosuspend in sierra while online")
> > Cc: stable@vger.kernel.org
> > Signed-off-by: Wentao Liang <vulab@iscas.ac.cn>
>
> This looks correct, but as Greg already asked you elsewhere, did you
> forget to add an Assisted-by tag here as well? How was this issue found
> and fixed?
>
> Also, you need to start replying to feedback. According to the list
> archives you have haven't replied to any of the four mails commenting on
> your patches that I've sent you so far.
You still haven't replied to anything I've ever sent you so I'm gonna
start treating you like a bot.
I've fixed up the USB serial and cdc-acm leaks you reported and given
you credit for reporting them.
Johan
^ permalink raw reply [flat|nested] 3+ messages in thread
end of thread, other threads:[~2026-10-09 12:41 UTC | newest]
Thread overview: 3+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-09-16 16:53 [PATCH] USB: sierra: Fix urb leak in sierra_submit_delayed_urbs() Wentao Liang
2026-09-17 9:00 ` Johan Hovold
2026-10-09 12:40 ` Johan Hovold
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®