Re: [PATCH v2] driver core: avoid klist_remove() on unattached knode_driver

Greg KH <[email protected]>
Newsgroups dev.linux.lists.driver-core,org.kernel.vger.linux-kernel,org.kernel.vger.linux-usb
Message-ID <2026082048-malformed-finite-4e61@gregkh>
On Thu, Aug 20, 2026 at 02:05:23PM +0800, Nguyen Quang Le Kien wrote:
> usb_driver_claim_interface() sets dev->driver directly and skips
> device_bind_driver() when the interface is not yet registered, so the
> device can reach teardown with dev->driver set but knode_driver never
> added to the driver's klist_devices. __device_release_driver() then
> unconditionally calls klist_remove() on the unattached node, which
> dereferences a NULL klist pointer in klist_put() and crashes.
> 
> Only remove the node if the device is actually bound, mirroring the
> check device_is_bound() already provides for the driver core. This
> matches the existing guard on knode_bus in bus_remove_device().
> 
> Reported-by: [email protected]
> Closes: https://syzkaller.appspot.com/bug?extid=87188222c77c0dbbdb4d
> Signed-off-by: Nguyen Quang Le Kien <[email protected]>
> ---
>  drivers/base/dd.c | 3 ++-
>  1 file changed, 2 insertions(+), 1 deletion(-)

What changed from v1?

And why did you send the same patch as Edward Adam Davis <[email protected]>
just did:
	https://lore.kernel.org/r/[email protected]

What is suddenly causing people to care about syzbot bugs for USB?

thanks,

greg k-h
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.