| From 76e2e15bc72878a584518f76cfb290ecd00f2b16 Mon Sep 17 00:00:00 2001 |
| From: Tom Rix <trix@redhat.com> |
| Date: Wed, 8 Jul 2020 06:12:43 -0700 |
| Subject: [PATCH] USB: c67x00: fix use after free in c67x00_giveback_urb |
| |
| commit 211f08347355cba1f769bbf3355816a12b3ddd55 upstream. |
| |
| clang static analysis flags this error |
| |
| c67x00-sched.c:489:55: warning: Use of memory after it is freed [unix.Malloc] |
| usb_hcd_giveback_urb(c67x00_hcd_to_hcd(c67x00), urb, urbp->status); |
| ^~~~~~~~~~~~ |
| Problem happens in this block of code |
| |
| c67x00_release_urb(c67x00, urb); |
| usb_hcd_unlink_urb_from_ep(c67x00_hcd_to_hcd(c67x00), urb); |
| spin_unlock(&c67x00->lock); |
| usb_hcd_giveback_urb(c67x00_hcd_to_hcd(c67x00), urb, urbp->status); |
| |
| In the call to c67x00_release_urb has this freeing of urbp |
| |
| urbp = urb->hcpriv; |
| urb->hcpriv = NULL; |
| list_del(&urbp->hep_node); |
| kfree(urbp); |
| |
| And so urbp is freed before usb_hcd_giveback_urb uses it as its 3rd |
| parameter. |
| |
| Since all is required is the status, pass the status directly as is |
| done in c64x00_urb_dequeue |
| |
| Fixes: e9b29ffc519b ("USB: add Cypress c67x00 OTG controller HCD driver") |
| Signed-off-by: Tom Rix <trix@redhat.com> |
| Cc: stable <stable@vger.kernel.org> |
| Link: https://lore.kernel.org/r/20200708131243.24336-1-trix@redhat.com |
| Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org> |
| Signed-off-by: Paul Gortmaker <paul.gortmaker@windriver.com> |
| |
| diff --git a/drivers/usb/c67x00/c67x00-sched.c b/drivers/usb/c67x00/c67x00-sched.c |
| index 633c52de3bb3..9865750bc31e 100644 |
| --- a/drivers/usb/c67x00/c67x00-sched.c |
| +++ b/drivers/usb/c67x00/c67x00-sched.c |
| @@ -486,7 +486,7 @@ c67x00_giveback_urb(struct c67x00_hcd *c67x00, struct urb *urb, int status) |
| c67x00_release_urb(c67x00, urb); |
| usb_hcd_unlink_urb_from_ep(c67x00_hcd_to_hcd(c67x00), urb); |
| spin_unlock(&c67x00->lock); |
| - usb_hcd_giveback_urb(c67x00_hcd_to_hcd(c67x00), urb, urbp->status); |
| + usb_hcd_giveback_urb(c67x00_hcd_to_hcd(c67x00), urb, status); |
| spin_lock(&c67x00->lock); |
| } |
| |
| -- |
| 2.27.0 |
| |