diff options
| author | Anuj Bolewar <bolewara@gmail.com> | 2026-08-04 10:18:21 +0530 |
|---|---|---|
| committer | Hans Verkuil <hverkuil+cisco@kernel.org> | 2026-09-08 15:10:03 +0200 |
| commit | 6802ad4b6b267dda02209b5811edac7825c8a5f6 (patch) | |
| tree | ccbf205a24d09f87b0aabf9bcd273124d45fa5d1 /drivers/media/usb/hackrf | |
| parent | 8a3435f98175aa611e6cb347738f85d7cd6df792 (diff) | |
| download | linux-next-6802ad4b6b267dda02209b5811edac7825c8a5f6.tar.gz linux-next-6802ad4b6b267dda02209b5811edac7825c8a5f6.zip | |
media: hackrf: fix use-after-free in hackrf_alloc_urbs() error path
hackrf_alloc_urbs() frees the URBs it allocated so far when one
allocation fails, but leaves the entries in dev->urb_list[] and
dev->urbs_initialized untouched. The caller, hackrf_start_streaming(),
then calls hackrf_free_urbs() on the error path, which walks
dev->urbs_initialized entries and calls usb_free_urb() a second time on
the already-freed URBs, causing a use-after-free (slab-use-after-free
Write in usb_free_urb()).
Drop the redundant cleanup loop inside hackrf_alloc_urbs() and let
hackrf_free_urbs(), which the caller already invokes on error, own the
cleanup of the successfully allocated URBs.
Reported-by: syzbot+832ce9fa3face1b7d44d@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=832ce9fa3face1b7d44d
Fixes: 969ec1f6bd92 ("[media] hackrf: HackRF SDR driver")
Cc: stable@vger.kernel.org
Signed-off-by: Anuj Bolewar <bolewara@gmail.com>
Signed-off-by: Hans Verkuil <hverkuil+cisco@kernel.org>
Diffstat (limited to 'drivers/media/usb/hackrf')
| -rw-r--r-- | drivers/media/usb/hackrf/hackrf.c | 7 |
1 files changed, 2 insertions, 5 deletions
diff --git a/drivers/media/usb/hackrf/hackrf.c b/drivers/media/usb/hackrf/hackrf.c index a15829a60e88..70fd95f3e97d 100644 --- a/drivers/media/usb/hackrf/hackrf.c +++ b/drivers/media/usb/hackrf/hackrf.c @@ -665,7 +665,7 @@ static int hackrf_free_urbs(struct hackrf_dev *dev) static int hackrf_alloc_urbs(struct hackrf_dev *dev, bool rcv) { - int i, j; + int i; unsigned int pipe; usb_complete_t complete; @@ -681,11 +681,8 @@ static int hackrf_alloc_urbs(struct hackrf_dev *dev, bool rcv) for (i = 0; i < MAX_BULK_BUFS; i++) { dev_dbg(dev->dev, "alloc urb=%d\n", i); dev->urb_list[i] = usb_alloc_urb(0, GFP_KERNEL); - if (!dev->urb_list[i]) { - for (j = 0; j < i; j++) - usb_free_urb(dev->urb_list[j]); + if (!dev->urb_list[i]) return -ENOMEM; - } usb_fill_bulk_urb(dev->urb_list[i], dev->udev, pipe, |
