Re: [BUG] media: dvb-usb-v2: gl861: WARNING in usb_submit_urb due to bogus control direction

Alan Stern <[email protected]>
Newsgroups org.kernel.vger.linux-media,org.kernel.vger.linux-kernel,org.kernel.vger.linux-usb
Message-ID <[email protected]>
On Mon, Aug 10, 2026 at 04:21:20PM +0800, ZW Tang wrote:
> Hi,
> 
> I am reporting a WARNING triggered by a syzkaller reproducer in the
> GL861 DVB USB driver.
> 
> Although a similar bug has been reported before, I can still trigger
> this warning on Linux 7.2-rc3 with the attached syzkaller reproducer.
> 
> The warning is emitted from usb_submit_urb() because the USB control
> transfer direction appears inconsistent:
> 
> usb 3-1: BOGUS control dir, pipe 80000280 doesn't match bRequestType c0
> WARNING: CPU: 0 PID: 4359 at drivers/usb/core/urb.c:412
> usb_submit_urb+0x117a/0x18d0 drivers/usb/core/urb.c:410
> 
> This looks like a driver-side control-message construction or
> validation issue in the GL861 DVB USB driver, rather than a USB core
> problem. The reproducer creates a dummy GL861 USB device, opens the
> corresponding I2C device, and issues an I2C_SMBUS ioctl. The execution
> path reaches gl861_i2c_master_xfer(), then gl861_ctrl_msg(), and
> finally usb_control_msg()/usb_submit_urb().
> 
> In the observed crash, the driver submits a vendor IN control request
> with bRequestType 0xc0, but USB core reports that the control pipe
> direction does not match the request direction/length. This may be
> related to insufficient validation of zero-length or malformed
> I2C/SMBus read requests before calling gl861_ctrl_msg().

Many USB implementations of I2C cannot handle IN transfers of length 0.  
Some of the USB I2C drivers have been fixed to set a flag saying that IN 
transfers of length 0 should not be accepted.  The same thing could be 
done for this driver.

Alan Stern
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.