Re: [PATCH v2] usb: gadget: f_mass_storage: fix null pointer dereference in fsg_common_set_num_buffers()
Alan Stern <[email protected]>
| Newsgroups | org.kernel.vger.linux-kernel,org.kernel.vger.linux-usb,org.kernel.vger.stable |
|---|---|
| Message-ID | <[email protected]> |
On Tue, Aug 18, 2026 at 09:29:04AM +0530, Jeffin Philip wrote: > Previously fsg_num_buffers_validate() was removed as it was not > necessary due to Kconfig setting the limits for n from 2 to 256 with > default as 2. However, setting the page content in such a way that > kstrtou8() reflects n value as either 0 or 1 bypasses these > restrictions leading to a null pointer dereference if n is 0. Fix > this by adding a check for n < 2 and returning -EINVAL if n is > either 0 or 1 consistent with Kconfig logic. > > Reported-by: [email protected] > Closes: https://syzkaller.appspot.com/bug?extid=791be35f1fbcc85d06d7 > Fixes: fe5a6c48fd95 ("usb: gadget: storage: get rid of fsg_num_buffers_validate()") > Cc: [email protected] > Signed-off-by: Jeffin Philip <[email protected]> Acked-by: Alan Stern <[email protected]> > --- > Changes in v2: > - Change check from n = 0 to n < 2 consistent with Kconfig logic > --- > drivers/usb/gadget/function/f_mass_storage.c | 3 +++ > 1 file changed, 3 insertions(+) > > diff --git a/drivers/usb/gadget/function/f_mass_storage.c b/drivers/usb/gadget/function/f_mass_storage.c > index a50743caf083..4e743be220cc 100644 > --- a/drivers/usb/gadget/function/f_mass_storage.c > +++ b/drivers/usb/gadget/function/f_mass_storage.c > @@ -2747,6 +2747,9 @@ int fsg_common_set_num_buffers(struct fsg_common *common, unsigned int n) > struct fsg_buffhd *bh, *buffhds; > int i; > > + if (n < 2) > + return -EINVAL; > + > buffhds = kzalloc_objs(*buffhds, n); > if (!buffhds) > return -ENOMEM; > -- > 2.55.0 > >