Re: [PATCH v2] usb: gadget: f_mass_storage: fix null pointer dereference in fsg_common_set_num_buffers()

Alan Stern <[email protected]>
Newsgroups org.kernel.vger.linux-usb,org.kernel.vger.linux-kernel,org.kernel.vger.stable
Message-ID <[email protected]>
On Tue, Aug 18, 2026 at 09:29:04AM +0530, Jeffin Philip wrote:
> Previously fsg_num_buffers_validate() was removed as it was not
> necessary due to Kconfig setting the limits for n from 2 to 256 with
> default as 2. However, setting the page content in such a way that
> kstrtou8() reflects n value as either 0 or 1 bypasses these
> restrictions leading to a null pointer dereference if n is 0. Fix
> this by adding a check for n < 2 and returning -EINVAL if n is
> either 0 or 1 consistent with Kconfig logic.
> 
> Reported-by: [email protected]
> Closes: https://syzkaller.appspot.com/bug?extid=791be35f1fbcc85d06d7
> Fixes: fe5a6c48fd95 ("usb: gadget: storage: get rid of fsg_num_buffers_validate()")
> Cc: [email protected]
> Signed-off-by: Jeffin Philip <[email protected]>

Acked-by: Alan Stern <[email protected]>

> ---
> Changes in v2:
>  - Change check from n = 0 to n < 2 consistent with Kconfig logic
> ---
>  drivers/usb/gadget/function/f_mass_storage.c | 3 +++
>  1 file changed, 3 insertions(+)
> 
> diff --git a/drivers/usb/gadget/function/f_mass_storage.c b/drivers/usb/gadget/function/f_mass_storage.c
> index a50743caf083..4e743be220cc 100644
> --- a/drivers/usb/gadget/function/f_mass_storage.c
> +++ b/drivers/usb/gadget/function/f_mass_storage.c
> @@ -2747,6 +2747,9 @@ int fsg_common_set_num_buffers(struct fsg_common *common, unsigned int n)
>  	struct fsg_buffhd *bh, *buffhds;
>  	int i;
>  
> +	if (n < 2)
> +		return -EINVAL;
> +
>  	buffhds = kzalloc_objs(*buffhds, n);
>  	if (!buffhds)
>  		return -ENOMEM;
> -- 
> 2.55.0
> 
>
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.