[PATCH 0/2] usb: gadget: f_uac1/f_uac2: fix invalid-free in srate configfs store
Anuj Bolewar via B4 Relay <devnull+bolewara.gmail.com-DgEjT+Ai2ygdnm+yROfE0A@public.gmane.org>
| Newsgroups | gmane.linux.usb.general,gmane.linux.kernel |
|---|---|
| Message-ID | <[email protected]> |
The p_srate/c_srate configfs store helpers in f_uac1 and f_uac2 free the strsep()-advanced split_page pointer instead of the buffer returned by kstrdup(). When a non-numeric token appears in the first position, kstrtou32() fails and kfree() releases a pointer into the middle of the slab object, which KASAN reports as invalid-free. Keep the original kstrdup() pointer and free that instead. This fixes the syzbot reports for f_uac2_opts_p_srate_store, f_uac2_opts_c_srate_store and f_uac1_opts_c_srate_store. Signed-off-by: Anuj Bolewar <[email protected]> --- Anuj Bolewar (2): usb: gadget: f_uac2: fix invalid-free in srate configfs store usb: gadget: f_uac1: fix invalid-free in srate configfs store drivers/usb/gadget/function/f_uac1.c | 5 +++-- drivers/usb/gadget/function/f_uac2.c | 5 +++-- 2 files changed, 6 insertions(+), 4 deletions(-) --- base-commit: 2d2338c93da79b3bfe4b6099a931d9468d539952 change-id: 20260804-f-uac-srate-invalid-free-827cf8840137 Best regards, -- Anuj Bolewar <[email protected]>