summaryrefslogtreecommitdiff
path: root/drivers
diff options
context:
space:
mode:
authorAnuj Bolewar <bolewara@gmail.com>2026-08-04 10:18:21 +0530
committerHans Verkuil <hverkuil+cisco@kernel.org>2026-09-08 15:10:03 +0200
commit6802ad4b6b267dda02209b5811edac7825c8a5f6 (patch)
treeccbf205a24d09f87b0aabf9bcd273124d45fa5d1 /drivers
parent8a3435f98175aa611e6cb347738f85d7cd6df792 (diff)
downloadlinux-next-6802ad4b6b267dda02209b5811edac7825c8a5f6.tar.gz
linux-next-6802ad4b6b267dda02209b5811edac7825c8a5f6.zip
media: hackrf: fix use-after-free in hackrf_alloc_urbs() error path
hackrf_alloc_urbs() frees the URBs it allocated so far when one allocation fails, but leaves the entries in dev->urb_list[] and dev->urbs_initialized untouched. The caller, hackrf_start_streaming(), then calls hackrf_free_urbs() on the error path, which walks dev->urbs_initialized entries and calls usb_free_urb() a second time on the already-freed URBs, causing a use-after-free (slab-use-after-free Write in usb_free_urb()). Drop the redundant cleanup loop inside hackrf_alloc_urbs() and let hackrf_free_urbs(), which the caller already invokes on error, own the cleanup of the successfully allocated URBs. Reported-by: syzbot+832ce9fa3face1b7d44d@syzkaller.appspotmail.com Closes: https://syzkaller.appspot.com/bug?extid=832ce9fa3face1b7d44d Fixes: 969ec1f6bd92 ("[media] hackrf: HackRF SDR driver") Cc: stable@vger.kernel.org Signed-off-by: Anuj Bolewar <bolewara@gmail.com> Signed-off-by: Hans Verkuil <hverkuil+cisco@kernel.org>
Diffstat (limited to 'drivers')
-rw-r--r--drivers/media/usb/hackrf/hackrf.c7
1 files changed, 2 insertions, 5 deletions
diff --git a/drivers/media/usb/hackrf/hackrf.c b/drivers/media/usb/hackrf/hackrf.c
index a15829a60e88..70fd95f3e97d 100644
--- a/drivers/media/usb/hackrf/hackrf.c
+++ b/drivers/media/usb/hackrf/hackrf.c
@@ -665,7 +665,7 @@ static int hackrf_free_urbs(struct hackrf_dev *dev)
static int hackrf_alloc_urbs(struct hackrf_dev *dev, bool rcv)
{
- int i, j;
+ int i;
unsigned int pipe;
usb_complete_t complete;
@@ -681,11 +681,8 @@ static int hackrf_alloc_urbs(struct hackrf_dev *dev, bool rcv)
for (i = 0; i < MAX_BULK_BUFS; i++) {
dev_dbg(dev->dev, "alloc urb=%d\n", i);
dev->urb_list[i] = usb_alloc_urb(0, GFP_KERNEL);
- if (!dev->urb_list[i]) {
- for (j = 0; j < i; j++)
- usb_free_urb(dev->urb_list[j]);
+ if (!dev->urb_list[i])
return -ENOMEM;
- }
usb_fill_bulk_urb(dev->urb_list[i],
dev->udev,
pipe,