From patchwork Sat Dec 3 13:31:55 2022 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Vincent Mailhol X-Patchwork-Id: 29276 Return-Path: Delivered-To: ouuuleilei@gmail.com Received: by 2002:adf:f944:0:0:0:0:0 with SMTP id q4csp1366835wrr; Sat, 3 Dec 2022 05:34:57 -0800 (PST) X-Google-Smtp-Source: AA0mqf55ssWXvoHHiw68EMPkFW9Myhw2WvB96AASz1hFfSDHoyAuwNog0YkH5MXKGSBMHrGRCds0 X-Received: by 2002:a63:525e:0:b0:477:bca8:1cd9 with SMTP id s30-20020a63525e000000b00477bca81cd9mr42324237pgl.581.1670074497065; Sat, 03 Dec 2022 05:34:57 -0800 (PST) ARC-Seal: i=1; a=rsa-sha256; t=1670074497; cv=none; d=google.com; s=arc-20160816; b=uKr67gcjSoXUexNR+8qEavHsOiGqK7FAyu7S4aMYVhXDCulYyWr01IxDPG6dnL8CKa ZWEMDwcU/yC9UIOigKud5NTatqCJfwrqcqqabr5hdA6mqgOZ5A9/J9UOGA0KfUzq6Shz b8HcbwmmJgqvewxX1t38kY8Mlou3GV6hE9Cn5SUCcYEw6W98sF1iJQXFck+HBngh8wbB 4zOODqxEaw8hf/cv+arNziAU2cSRl0Q1zadJNv4bbpRhiKpso3yqAubbOQIZttbB6bBc a1sN492uiyI50/s3wpoS49n7X9D5N8oEhkyxIjb1vdLDxDUS3u1JuxjsA+O0p7DcYLis 75CA== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:content-transfer-encoding:mime-version :references:in-reply-to:message-id:date:subject:cc:to:from:sender :dkim-signature; bh=dOfYV6CW+avnaQrtamVGsJG2bps7tCEFlf1CMaOsNsw=; b=C01mVg6ymipyg1YNAPzcMiIsYpWKrFCsc26KIgctiHz7o0lEKZk8fTddgBW/liBMpz ZUCXytRJH9rmMhvKAb4feCH+yFJw8FVM/GoXe7VqXsnJS0MEoOj9jP1/uxDquKA1Nsr1 yIEv3UdQY07qw0DUfDAnba7bjIFPVe+SGiYRZ8HLXNis7K02TYyMLbHKatyMcrz6OzBl GfthdHCXtetlAHcJFefDpGjD0VSL3Ri1kLwStasxO9SGLrzwDpwNobfbZ4pnF4Eo49fG P9x/KJX9a5mLYInU/iR8vlt1tzU7LHyXpnaw+a/PC4KacFxKhuI7ov8J8JmzvFyurEVZ Qrhw== ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@gmail.com header.s=20210112 header.b=oR3qU0yG; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org Received: from out1.vger.email (out1.vger.email. [2620:137:e000::1:20]) by mx.google.com with ESMTP id p39-20020a056a000a2700b0056cb4662b9csi10857200pfh.16.2022.12.03.05.34.44; Sat, 03 Dec 2022 05:34:57 -0800 (PST) Received-SPF: pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) client-ip=2620:137:e000::1:20; Authentication-Results: mx.google.com; dkim=pass header.i=@gmail.com header.s=20210112 header.b=oR3qU0yG; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S229853AbiLCNda (ORCPT + 99 others); Sat, 3 Dec 2022 08:33:30 -0500 Received: from lindbergh.monkeyblade.net ([23.128.96.19]:54466 "EHLO lindbergh.monkeyblade.net" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S229820AbiLCNdG (ORCPT ); Sat, 3 Dec 2022 08:33:06 -0500 Received: from mail-pg1-x52e.google.com (mail-pg1-x52e.google.com [IPv6:2607:f8b0:4864:20::52e]) by lindbergh.monkeyblade.net (Postfix) with ESMTPS id 55FBA17880; Sat, 3 Dec 2022 05:32:46 -0800 (PST) Received: by mail-pg1-x52e.google.com with SMTP id h193so6605285pgc.10; Sat, 03 Dec 2022 05:32:46 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20210112; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:sender:from:to:cc:subject:date :message-id:reply-to; bh=dOfYV6CW+avnaQrtamVGsJG2bps7tCEFlf1CMaOsNsw=; b=oR3qU0yGIU6iOVxIuVEsaLNO1sG7NxQvlVqOJ80orEIdFjBHtPWRt6o4v19aDO7z6N 1dhba3k9yINO1pkZIQ0NiR+H32RiclgG3wohPdPhJzgd8d18WAnsOqIDo/Y+EwAsKfvX FmC1co2ixcRv9pPMVaA9BnghXnetjra3pLc3powVIXsXnkO4TshoPLjrZgtkcUYWYrZP evduuq2dw704I8aR87KM7UoKzlXt80CXgrmOUAMrXAN/Sw65D1m761T+HkR4pO874yrk nXuVpgrAUqUVnqpvw88qNcHpETQB5yoRX0mW+Xs5UgfrE2eRCOX+EjU3IZ2UXUkPG7Ez FvRQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20210112; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:sender:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to; bh=dOfYV6CW+avnaQrtamVGsJG2bps7tCEFlf1CMaOsNsw=; b=ryq7PeECd42kSnTifxKgG4mhg4HpCHp0WIGIcm6LzECFUK6oT2rRkaX0J45PFfGCG7 XK75f3wFwYNRtkEgYDx9Hpb5F/llJU6rApE2CO8bWD/5tP4uD1Oj94TNvZl/n1kmPH3K JowlrEUqv2VFTyWVVLcyooBu7YLmwTqpXszhkBMzxXVkitUpyR9AB11Q+bK11FD9C/JR 7vjJ1o+aqSV12uhTfvLy6P9weI8Jan/nVdlCDBdtN+YqqBjlZu8DAC5W1WgRUwcJXEDl jNcj2wwoItIU0902vqens/xJSR4vubVkYYZVuyRYGIJxVhUA7XgXeCg8eBAyjdC5+Fq3 bf4g== X-Gm-Message-State: ANoB5pmOA4HnSd+R5r4cFpOJnpUHkNETi7ll3ayeOS0/kMS16LZO9Ag+ IRTBSEpRUhgb4UdqnkC63GY= X-Received: by 2002:a63:f40f:0:b0:478:1c89:5c9a with SMTP id g15-20020a63f40f000000b004781c895c9amr25227135pgi.384.1670074365730; Sat, 03 Dec 2022 05:32:45 -0800 (PST) Received: from localhost.localdomain (124x33x176x97.ap124.ftth.ucom.ne.jp. [124.33.176.97]) by smtp.gmail.com with ESMTPSA id q12-20020a170902dacc00b00185402cfedesm7414472plx.246.2022.12.03.05.32.39 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sat, 03 Dec 2022 05:32:45 -0800 (PST) Sender: Vincent Mailhol From: Vincent Mailhol To: Marc Kleine-Budde , linux-can@vger.kernel.org Cc: Wolfgang Grandegger , "David S . Miller" , Eric Dumazet , Jakub Kicinski , Paolo Abeni , Frank Jungclaus , socketcan@esd.eu, Yasushi SHOJI , =?utf-8?q?Stefan_M=C3=A4tje?= , Hangyu Hua , Oliver Hartkopp , Peter Fink , Jeroen Hofstee , =?utf-8?q?Christoph_M=C3=B6hring?= , John Whittington , Vasanth Sadhasivan , Jimmy Assarsson , Anssi Hannula , Pavel Skripkin , Stephane Grosjean , Wolfram Sang , "Gustavo A . R . Silva" , Julia Lawall , Dongliang Mu , Sebastian Haas , Maximilian Schneider , Daniel Berglund , Olivier Sobrie , =?utf-8?b?UmVtaWdpdXN6IEtvxYLFgsSFdGFq?= , Jakob Unterwurzacher , Martin Elshuber , Philipp Tomsich , Bernd Krumboeck , netdev@vger.kernel.org, linux-kernel@vger.kernel.org, Alan Stern , linux-usb@vger.kernel.org, Vincent Mailhol Subject: [PATCH 4/8] can: kvaser_usb: kvaser_usb_disconnect(): fix NULL pointer dereference Date: Sat, 3 Dec 2022 22:31:55 +0900 Message-Id: <20221203133159.94414-5-mailhol.vincent@wanadoo.fr> X-Mailer: git-send-email 2.37.4 In-Reply-To: <20221203133159.94414-1-mailhol.vincent@wanadoo.fr> References: <20221203133159.94414-1-mailhol.vincent@wanadoo.fr> MIME-Version: 1.0 X-Spam-Status: No, score=-1.7 required=5.0 tests=BAYES_00,DKIM_SIGNED, DKIM_VALID,DKIM_VALID_EF,FREEMAIL_FORGED_FROMDOMAIN,FREEMAIL_FROM, HEADER_FROM_DIFFERENT_DOMAINS,RCVD_IN_DNSWL_NONE,SPF_HELO_NONE, SPF_PASS autolearn=no autolearn_force=no version=3.4.6 X-Spam-Checker-Version: SpamAssassin 3.4.6 (2021-04-09) on lindbergh.monkeyblade.net Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org X-getmail-retrieved-from-mailbox: =?utf-8?q?INBOX?= X-GMAIL-THRID: =?utf-8?q?1751200036174848281?= X-GMAIL-MSGID: =?utf-8?q?1751200036174848281?= kvaser_usb sets the usb_interface to NULL before waiting for the completion of outstanding urbs. This can result in NULL pointer dereference, c.f. [1] and [2]. Remove the call to usb_set_intfdata(intf, NULL). The core will take care of setting it to NULL after kvaser_usb_disconnect() at [3]. [1] commit 27ef17849779 ("usb: add usb_set_intfdata() documentation") Link: https://git.kernel.org/gregkh/usb/c/27ef17849779 [2] thread about usb_set_intfdata() on linux-usb mailing. Link: https://lore.kernel.org/linux-usb/Y4OD70GD4KnoRk0k@rowland.harvard.edu/ [3] function usb_unbind_interface() from drivers/usb/core/driver.c Link: https://elixir.bootlin.com/linux/v6.0/source/drivers/usb/core/driver.c#L497 Fixes: 080f40a6fa28 ("can: kvaser_usb: Add support for Kvaser CAN/USB devices") Signed-off-by: Vincent Mailhol --- @stable team: the function was moved from kvaser_usb.c to kvaser_usb_core.c in: 7259124eac7d1 ("can: kvaser_usb: Split driver into kvaser_usb_core.c and kvaser_usb_leaf.c") --- drivers/net/can/usb/kvaser_usb/kvaser_usb_core.c | 2 -- 1 file changed, 2 deletions(-) diff --git a/drivers/net/can/usb/kvaser_usb/kvaser_usb_core.c b/drivers/net/can/usb/kvaser_usb/kvaser_usb_core.c index 3a2bfaad1406..dad916b3288e 100644 --- a/drivers/net/can/usb/kvaser_usb/kvaser_usb_core.c +++ b/drivers/net/can/usb/kvaser_usb/kvaser_usb_core.c @@ -981,8 +981,6 @@ static void kvaser_usb_disconnect(struct usb_interface *intf) { struct kvaser_usb *dev = usb_get_intfdata(intf); - usb_set_intfdata(intf, NULL); - if (!dev) return;