Re: [PATCH v3] usb: gadget: udc: Fix use-after-free in gadget_match_driver

Dmitry Antipov <[email protected]>
Newsgroups org.kernel.vger.linux-usb,org.kernel.vger.linux-kernel,org.kernel.vger.stable
Message-ID <[email protected]>
On 6/25/26 10:37 AM, Jimmy Hu wrote:

> The udc structure acts as the management structure for the gadget,
> but their lifecycles are decoupled. A race condition exists where
> usb_del_gadget() frees the udc memory (e.g., via mode-switch work)
> while gadget_match_driver() concurrently accesses the freed udc memory
> (e.g., via configfs), causing a Use-After-Free (UAF) that triggers a
> NULL pointer dereference when the freed memory is zeroed:
> 
> [39430.908615][ T1171] Unable to handle kernel NULL pointer dereference at virtual address 0000000000000000
> [39430.911397][ T1171] pc : __pi_strcmp+0x20/0x140
> [39430.911441][ T1171] lr : gadget_match_driver+0x34/0x60
> ...
> [39430.911890][ T1171]  usb_gadget_register_driver_owner+0x50/0xf8
> [39430.911910][ T1171]  gadget_dev_desc_UDC_store+0xf4/0x140
> [39430.931308][ T1171]  configfs_write_iter+0xec/0x134
> 
> [39430.957058][ T1171] Workqueue: events_freezable __dwc3_set_mode
> [39430.957287][ T1171]  dwc3_gadget_exit+0x34/0x8c
> [39430.957304][ T1171]  __dwc3_set_mode+0xc0/0x664
> 
> Fix this by ensuring the udc structure remains allocated until the
> gadget is released. To achieve this, introduce a new
> usb_gadget_release() routine to the core. When the gadget is added,
> usb_add_gadget() stores the gadget's release routine in the udc
> structure and takes a reference to the udc. When the gadget is
> released, usb_gadget_release() drops the reference to the udc and
> then calls the gadget's release routine.

It seems that the same (or the very similar) race condition still exists,
see https://syzkaller.appspot.com/bug?extid=9cb1ac7fce4944ba9165.

And the following may make sense as well:

diff --git a/drivers/usb/gadget/configfs.c b/drivers/usb/gadget/configfs.c
index 183a25f65ac8..944e46af8b96 100644
--- a/drivers/usb/gadget/configfs.c
+++ b/drivers/usb/gadget/configfs.c
@@ -405,6 +405,7 @@ static void gadget_info_attr_release(struct config_item *item)
         WARN_ON(!list_empty(&gi->string_list));
         WARN_ON(!list_empty(&gi->available_func));
         kfree(gi->composite.gadget_driver.function);
+       driver_unregister(&gi->composite.gadget_driver.driver);
         kfree(gi->composite.gadget_driver.driver.name);
         kfree(gi);
  }

Dmitry
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.