Re: [PATCH] usb: gadget: midi2: Fix null-pointer dereference in f_midi2_free_ep_reqs

Jeffin Philip <[email protected]>
Newsgroups org.kernel.vger.linux-usb,dev.linux.lists.syzbot,org.kernel.vger.linux-kernel
Message-ID <[email protected]>
On Wed, 29 Jul 2026 11:04:54 +0200,
syzbot wrote:
> 
> From: Aleksandr Nogikh <[email protected]>
> 
> A null-pointer dereference occurs in f_midi2_free_ep_reqs() when attempting
> to clean up an endpoint that was never initialized.
> 
> When configuring the MIDI 2.0 gadget via configfs and setting the block
> direction to SNDRV_UMP_DIR_INPUT, the initialization of the midi1_ep_out
> endpoint is explicitly skipped during the gadget bind phase
> (f_midi2_bind()). As a result, the usb_ep->card field remains NULL.
> 
> Later, when the host sets the alternate setting, f_midi2_set_alt()
> unconditionally stops both the IN and OUT endpoints by calling
> f_midi2_stop_eps(), which in turn calls f_midi2_free_ep_reqs() for both
> endpoints. When f_midi2_free_ep_reqs() is called for the uninitialized
> midi1_ep_out, it attempts to dereference usb_ep->card to determine the
> number of requests to free, leading to a crash.
> 
> Fix this by using usb_ep->num_reqs instead of usb_ep->card->info.num_reqs
> in f_midi2_free_ep_reqs(). usb_ep->num_reqs is correctly set during
> f_midi2_init_ep() and remains 0 if the endpoint was never initialized,
> safely avoiding the loop. For consistency, apply the same change to
> f_midi2_alloc_ep_reqs().
> 
> Oops: general protection fault, probably for non-canonical address
> 0xdffffc00000000ee: 0000 [#1] SMP KASAN NOPTI
> KASAN: null-ptr-deref in range [0x0000000000000770-0x0000000000000777]
> ...
> RIP: 0010:f_midi2_free_ep_reqs drivers/usb/gadget/function/f_midi2.c:1166
> [inline]
> RIP: 0010:f_midi2_stop_eps+0x28e/0x4d0
> drivers/usb/gadget/function/f_midi2.c:1246
> ...
> Call Trace:
>  <TASK>
>  f_midi2_set_alt+0x11c/0xf00 drivers/usb/gadget/function/f_midi2.c:1296
>  composite_setup+0x1ffd/0x3480 drivers/usb/gadget/composite.c:1933
>  configfs_composite_setup+0xbd/0x100 drivers/usb/gadget/configfs.c:1877
> 
> Fixes: 8b645922b223 ("usb: gadget: Add support for USB MIDI 2.0 function driver")
> Assisted-by: Gemini:gemini-3.5-flash Gemini:gemini-3.1-pro-preview syzbot
> Reported-by: [email protected]
> Closes: https://syzkaller.appspot.com/bug?extid=bbb6dad313f4aaa8da6b
> Link: https://syzkaller.appspot.com/ai_job?id=8ce30b1a-8cf7-4e38-bcf7-1f69e6f6313f
> Signed-off-by: Aleksandr Nogikh <[email protected]>

Closes: https://syzkaller.appspot.com/bug?extid=01a17afb30637396955e

Thanks,
Jeffin.
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.