From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-wm1-f46.google.com (mail-wm1-f46.google.com [209.85.128.46]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id E75FF377009 for ; Wed, 27 May 2026 08:37:30 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.128.46 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1779871052; cv=none; b=Ued07aspQY+mP27AGOdxUD9tNpE4M4aVqFSXM+dXIfCzIY6J6Nyd38ZbXbyroXcpZzLl5Qb1M/+RizffPB+VlYD93d3py7QYNuD/KGFVZHKh3xFaTqRztZxfbykFW+ESx+BcppEb+MDILi3u4dCKzqh1Jq6K+rZMtwL8ywkLMNY= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1779871052; c=relaxed/simple; bh=KqmcM5wjpzIIpE7M9ZJHP3JYmC0sdYhOOdrFBUm6YhE=; h=Message-ID:Date:MIME-Version:Subject:To:Cc:References:From: In-Reply-To:Content-Type; b=W/UusS1mzhkZ8NghZ2a/KabM1KwtbNGGI0JGsf6UH/V69K4qLn09T7ZtaiOTSSQq8U+DHSXtlsQvCcWt5mrLgHjzJ0i4oXWR65yn9nP8AaidtVRVG/4JfCOV3rTeHUryIBDLqKQ1gb9gT3D3M6vXALZdhsqzoUhbGL7v7k2LymU= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=buYKQNrc; arc=none smtp.client-ip=209.85.128.46 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="buYKQNrc" Received: by mail-wm1-f46.google.com with SMTP id 5b1f17b1804b1-49040362e4aso58587535e9.0 for ; Wed, 27 May 2026 01:37:30 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1779871049; x=1780475849; darn=vger.kernel.org; h=content-transfer-encoding:in-reply-to:from:content-language :references:cc:to:subject:user-agent:mime-version:date:message-id :from:to:cc:subject:date:message-id:reply-to; bh=dd63B64j/8tYt7JtZPFcGeZ7Eicxm9sULbtAClwSATc=; b=buYKQNrcX1Jf8lnDxw/fm2hmChhKjvpkbm1nRtLAe9x2ya6OqEgR4F4TD6lDtqDP2l F3zourjfBDw0BXcsLTePrLn0+cMPLPNUmO7FjWVrSGHJnE5tFlpAZhY7z9n8ks7aC3Cs IHp6OB/7E4zYEVWoELHDV5/Kg54QK72yyPfKyfQOK9wN5TDBZNkcOErAtFXKtlfXYPvs ajb/DeI4pZqhrMjJHZ8HCwHpwDiOAbTFT++1kdRRJJsxKdJToQ7NON325Pgi7jo23Ww8 m7Vnli6WiVvKt7eSrqH7svbXBJVXZ92QjJqjyR35dSkQXZQZsNDjHove4NZWHmM/fJ6E ztgQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1779871049; x=1780475849; h=content-transfer-encoding:in-reply-to:from:content-language :references:cc:to:subject:user-agent:mime-version:date:message-id :x-gm-gg:x-gm-message-state:from:to:cc:subject:date:message-id :reply-to; bh=dd63B64j/8tYt7JtZPFcGeZ7Eicxm9sULbtAClwSATc=; b=rm66oHDlk3mkCosKfKhaDc7NzabuusHdKx0lnDOO6uqiB+nuyaz+gE0tY6Bz9SNYDe KhC92f4sAU+M5Bm4CsEGCKW9el51/fDyuZRo2HhPPKPNFrNmmbcLM5bsyqptXNfmKnSp v39PDN4zChx7TMc+nsQEuD4GqhtumLC8fpg2ViL5HdTMZi6oyQ8o99wJxozCkITe5voM aBxz03Ro3KAc38d4kbYJ1IfJEwDhvILY6fu6ByxZLsRay8HBUXe0+JiqMWS9odEq4jUL MOPskscwFo3ypRXgjbLk8mVfLsbV7BR5j+gPxN4eYeC0oKFfCh90wHB0CsKSnLTkgCqP V9sg== X-Forwarded-Encrypted: i=1; AFNElJ9UBRC7LBO5pA9vQSYkeihiWz1b/YQ+Y+WYHt66mAU029gred5xnYb8upuROh6m9BT0aaYHn8bGVMf0YAY=@vger.kernel.org X-Gm-Message-State: AOJu0YwE2iATBjBfPr5J9iXSHeg9fWk+meRqcs0TEr+GI96LGTiPqevr D7gYWIbu5gRtOEm4/vXBq1s3YQCla6dghJZO5CLt+tEbhnz7SmCpXAPG X-Gm-Gg: Acq92OG7uc6Br9bvskgcKg5fYrZ0oxXBkphbuGrBhUYZpcR7/ukG9q7cvH2IDZHrc43 gMW5OI0C2bzgzgn+Nl/oSAxbinJTgqbEbRvBKEICh1aBCDi1KncWDfedx78sNxHmxT8mGeMF+UF rRmXQpxk8TMFUoxM50ZFf+233owZB1Hiqez1LBVb3RSGwXOuAUFFU6w7CRilsJqV7p8iTPki1pD VniMr6GmZbD/nC7ZKU/v8GHGXUY2dCSzovcOKdLi+dvSMHVzgWoRKVAQlm3bG9P/GswUC3vdXLC QNWYySpwubLoBvOAXeuA/DtD/rfjSG091xPPMmE5GHxjhAYT+b2b4eCqXndGXr/2u6EbdcktEg/ XY3T6s3JqM+gxifM1o/a+UPrLRGo0rXOuA1VBd4zPB3DpWGSo4SqKTqFb+y9VggIRkpFXK2Z+8o BDLDeEVEyejiD6LqxpZtGEH0VhxjM3gKX4fPY= X-Received: by 2002:a05:600c:1992:b0:48a:9428:5522 with SMTP id 5b1f17b1804b1-490426bc7dcmr362225525e9.16.1779871049109; Wed, 27 May 2026 01:37:29 -0700 (PDT) Received: from [192.168.1.10] ([95.43.220.235]) by smtp.googlemail.com with ESMTPSA id 5b1f17b1804b1-4904526c926sm682068395e9.1.2026.05.27.01.37.28 (version=TLS1_3 cipher=TLS_AES_128_GCM_SHA256 bits=128/128); Wed, 27 May 2026 01:37:28 -0700 (PDT) Message-ID: Date: Wed, 27 May 2026 11:37:27 +0300 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 User-Agent: Mozilla Thunderbird Subject: Re: [REGRESSION] usb: gadget: u_ether NULL deref in eth_stop after gether_detach_gadget To: Greg Kroah-Hartman Cc: khtsai@google.com, sashal@kernel.org, Merlijn Wajer , linux-usb@vger.kernel.org, linux-kernel@vger.kernel.org References: <89e19e6e-7ee7-4bb0-abd6-60971b7fd601@gmail.com> <2026052726-vagrancy-lilac-bf72@gregkh> Content-Language: en-GB From: Ivaylo Dimitrov In-Reply-To: <2026052726-vagrancy-lilac-bf72@gregkh> Content-Type: text/plain; charset=UTF-8; format=flowed Content-Transfer-Encoding: 8bit On 27.05.26 г. 11:03 ч., Greg Kroah-Hartman wrote: > On Tue, May 26, 2026 at 08:56:15AM +0300, Ivaylo Dimitrov wrote: >> on linux 6.18.31 I am seeing a NULL pointer dereference during RNDIS gadget >> teardown. > > Does this also happen on the latest 7.1-rc release? > I didn't test this on current -rc (this is a mobile phone and not particularly easy to run latest Linux on), however this looks more like an object lifetime contract issue than something specific to 6.18.y. Also, the suspected patch was backported to 6.18.y together with e002e92e88e12457373ed096b18716d97e7bbb20 ("usb: gadget: u_ether: Fix NULL pointer deref in eth_get_drvinfo"), which fixes a similar issue, so I strongly suspect the issue exists in current -rc as well. >> I suspect the reason is commit: >> >> usb: gadget: f_ncm: Fix net_device lifecycle with device_move > > Do you have a proposed fix for this issue? > Not really, as checking whether dev->gadget is NULL before calling DBG() looks more like a workaround than a proper fix to me. I also don't know the subsystem well enough to judge whether switching to netdev_dbg() instead of DBG() would be appropriate here, or whether that would defeat the purpose of the existing debug messages (or cause confusion by mixing gadget and netdev based logging). I could use some maintainer advice on what they think the proper fix should look like, and then I'll try to put together a fix. Thanks, Ivo