]> git.ipfire.org Git - thirdparty/kernel/stable.git/commitdiff
USB: iowarrior: fix use-after-free on disconnect
authorJohan Hovold <johan@kernel.org>
Sat, 23 May 2026 17:05:23 +0000 (19:05 +0200)
committerGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Thu, 25 Jun 2026 14:14:23 +0000 (15:14 +0100)
Submitted write URBs are not stopped on close() and therefore need to be
stopped unconditionally on disconnect() to avoid use-after-free in the
completion handler.

Fixes: b5f8d46867ca ("USB: iowarrior: fix use-after-free after driver unbind")
Fixes: 946b960d13c1 ("USB: add driver for iowarrior devices.")
Reported-by: syzbot+ad2aac2febc3bedf0962@syzkaller.appspotmail.com
Link: https://lore.kernel.org/all/6a0ce39b.170a0220.39a13.0007.GAE@google.com/
Cc: stable <stable@kernel.org>
Signed-off-by: Johan Hovold <johan@kernel.org>
Link: https://patch.msgid.link/20260523170523.1074563-1-johan@kernel.org
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
drivers/usb/misc/iowarrior.c

index 22504c0a28416fbee1700d8ea91caea83aca8073..88c6d1d1da11625474a65a03aba1e977f176bcb0 100644 (file)
@@ -905,13 +905,15 @@ static void iowarrior_disconnect(struct usb_interface *interface)
        /* prevent device read, write and ioctl */
        dev->present = 0;
 
+       /* write urbs are not stopped on close() so kill unconditionally */
+       usb_kill_anchored_urbs(&dev->submitted);
+
        if (dev->opened) {
                /* There is a process that holds a filedescriptor to the device ,
                   so we only shutdown read-/write-ops going on.
                   Deleting the device is postponed until close() was called.
                 */
                usb_kill_urb(dev->int_in_urb);
-               usb_kill_anchored_urbs(&dev->submitted);
                wake_up_interruptible(&dev->read_wait);
                wake_up_interruptible(&dev->write_wait);
                mutex_unlock(&dev->mutex);