RE: [PATCH RFC v2] usb: atm: cxacru: fix NULL pointer dereference on uninitialized atm_dev

"Wang, Jie" <[email protected]>
Newsgroups dev.linux.lists.syzbot
Message-ID <DS0PR11MB64485F854D12FF987BF26B0A98A52@DS0PR11MB6448.namprd11.prod.outlook.com>
#syz upstream

> -----Original Message-----
> From: syzbot <[email protected]>
> Sent: Tuesday, August 18, 2026 2:32 PM
> To: [email protected]
> Cc: Wang, Jie <[email protected]>; [email protected]
> Subject: [PATCH RFC v2] usb: atm: cxacru: fix NULL pointer dereference on
> uninitialized atm_dev
> 
> The cxacru driver uses the usbatm framework, which defers the ATM device
> registration to a kernel thread (usbatm_do_heavy_init()) but immediately returns
> success from the USB probe. Because the probe returns success, the driver core
> creates sysfs attribute files (like adsl_state and adsl_config), making them
> accessible to userspace before the ATM device is fully initialized.
> 
> If a user writes to these sysfs files before the initialization is complete or if it fails,
> the driver attempts to send a command to the device. If the command fails, the
> error handling path calls atm_err(), which unconditionally dereferences instance-
> >usbatm->atm_dev. Since atm_dev is NULL, this leads to a NULL pointer
> dereference:
> 
> Oops: general protection fault, probably for non-canonical address
> 0xdffffc0000000002: 0000 [#1] SMP KASAN NOPTI
> KASAN: null-ptr-deref in range [0x0000000000000010-0x0000000000000017]
> RIP: 0010:adsl_state_store+0x5cc/0x770 drivers/usb/atm/cxacru.c:359 Call
> Trace:
>  <TASK>
>  kernfs_fop_write_iter+0x3a4/0x540 fs/kernfs/file.c:345  new_sync_write
> fs/read_write.c:595 [inline]
>  vfs_write+0x612/0xba0 fs/read_write.c:687
>  ksys_write+0x150/0x270 fs/read_write.c:739
>  do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]
>  do_syscall_64+0x174/0x580 arch/x86/entry/syscall_64.c:94
> entry_SYSCALL_64_after_hwframe+0x77/0x7f
>  </TASK>
> 
> To fix this, add checks for instance->usbatm->atm_dev == NULL in
> adsl_state_store() and adsl_config_store(). This prevents the functions from
> proceeding and dereferencing the uninitialized atm_dev, consistent with how
> mac_address_show() handles the same race condition.
> 
> Fixes: e605c30977bb ("USB: atm: cxacru: convert to use dev_groups")
> Assisted-by: Gemini:gemini-3.6-flash Gemini:gemini-3.1-pro-preview syzbot
> Reported-by: [email protected]
> Closes: https://syzkaller.appspot.com/bug?extid=9b195c4f412ea5c4e56a
> Link: https://syzkaller.appspot.com/ai_job?id=b6352d63-d03a-4e87-92a4-
> b334c3ebcf97
> To: "Chas Williams" <[email protected]>
> To: <[email protected]>
> To: "Greg Kroah-Hartman" <[email protected]>
> To: <[email protected]>
> To: <[email protected]>
> To: <[email protected]>
> Cc: <[email protected]>
> 
> ---
> v2:
> - Removed changes and description for cxacru_poll_status().
> 
> v1:
> https://lore.kernel.org/all/a2325770-3137-4cc3-8a69-
> [email protected]/T/
> ---
> diff --git a/drivers/usb/atm/cxacru.c b/drivers/usb/atm/cxacru.c index
> 429ac20a8..dee15f7b7 100644
> --- a/drivers/usb/atm/cxacru.c
> +++ b/drivers/usb/atm/cxacru.c
> @@ -347,7 +347,7 @@ static ssize_t adsl_state_store(struct device *dev,
>  		return -EINVAL;
>  	ret = 0;
> 
> -	if (instance == NULL)
> +	if (instance == NULL || instance->usbatm->atm_dev == NULL)
>  		return -ENODEV;
> 
>  	if (mutex_lock_interruptible(&instance->adsl_state_serialize))
> @@ -444,7 +444,7 @@ static ssize_t adsl_config_store(struct device *dev,
>  	if (!capable(CAP_NET_ADMIN))
>  		return -EACCES;
> 
> -	if (instance == NULL)
> +	if (instance == NULL || instance->usbatm->atm_dev == NULL)
>  		return -ENODEV;
> 
>  	pos = 0;
> 
> 
> base-commit: 8d3ae59288f1e7d58d76558a6ee96d533bc5019f
> --
> This is an AI-generated patch subject to moderation.
> Reply with '#syz upstream' to Sign-off the patch as a human author and send it to
> the upstream kernel mailing lists.
> Reply with '#syz reject' to reject it ('#syz unreject' to undo).
> 
> See https://goo.gle/syzbot-ai-patches for information about AI-generated
> patches.
> You can comment on the patch as usual, syzbot will try to address the comments
> and send a new version of the patch if necessary.
> syzbot engineers can be reached at [email protected].
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.