Skip to content

Commit 4567f05

Browse files
Lizhi XuUlrich Hecht
authored andcommitted
usbnet: Prevents free active kevent
[ Upstream commit 420c84c330d1688b8c764479e5738bbdbf0a33de ] The root cause of this issue are: 1. When probing the usbnet device, executing usbnet_link_change(dev, 0, 0); put the kevent work in global workqueue. However, the kevent has not yet been scheduled when the usbnet device is unregistered. Therefore, executing free_netdev() results in the "free active object (kevent)" error reported here. 2. Another factor is that when calling usbnet_disconnect()->unregister_netdev(), if the usbnet device is up, ndo_stop() is executed to cancel the kevent. However, because the device is not up, ndo_stop() is not executed. The solution to this problem is to cancel the kevent before executing free_netdev(). Fixes: a69e617e533e ("usbnet: Fix linkwatch use-after-free on disconnect") Reported-by: Sam Sun <samsun1006219@gmail.com> Closes: https://syzkaller.appspot.com/bug?extid=8bfd7bcc98f7300afb84 Signed-off-by: Lizhi Xu <lizhi.xu@windriver.com> Link: https://patch.msgid.link/20251022024007.1831898-1-lizhi.xu@windriver.com Signed-off-by: Jakub Kicinski <kuba@kernel.org> Signed-off-by: Sasha Levin <sashal@kernel.org> Signed-off-by: Ulrich Hecht <uli@kernel.org>
1 parent 22a9385 commit 4567f05

1 file changed

Lines changed: 2 additions & 0 deletions

File tree

drivers/net/usb/usbnet.c

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1626,6 +1626,8 @@ void usbnet_disconnect (struct usb_interface *intf)
16261626
net = dev->net;
16271627
unregister_netdev (net);
16281628

1629+
cancel_work_sync(&dev->kevent);
1630+
16291631
while ((urb = usb_get_from_anchor(&dev->deferred))) {
16301632
dev_kfree_skb(urb->context);
16311633
kfree(urb->sg);

0 commit comments

Comments
 (0)