Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.kernel > #1555612
| From | Greg Kroah-Hartman <gregkh@linuxfoundation.org> |
|---|---|
| Newsgroups | linux.kernel |
| Subject | [PATCH 4.4 019/101] usb: xhci: fix possible wild pointer |
| Date | 2017-01-10 16:30 +0100 |
| Message-ID | <sY6x3-32R-13@gated-at.bofh.it> (permalink) |
| References | <sY4OB-1Tf-3@gated-at.bofh.it> |
| Organization | linux.* mail to news gateway |
4.4-stable review patch. If anyone has any objections, please let me know.
------------------
From: Lu Baolu <baolu.lu@linux.intel.com>
commit 2b985467371a58ae44d76c7ba12b0951fee6ed98 upstream.
handle_cmd_completion() frees a command structure which might be still
referenced by xhci->current_cmd.
This might cause problem when xhci->current_cmd is accessed after that.
A real-life case could be like this. The host takes a very long time to
respond to a command, and the command timer is fired at the same time
when the command completion event arrives. The command completion
handler frees xhci->current_cmd before the timer function can grab
xhci->lock. Afterward, timer function grabs the lock and go ahead with
checking and setting members of xhci->current_cmd.
Signed-off-by: Lu Baolu <baolu.lu@linux.intel.com>
Signed-off-by: Mathias Nyman <mathias.nyman@linux.intel.com>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
drivers/usb/host/xhci-ring.c | 16 +++++++++++-----
1 file changed, 11 insertions(+), 5 deletions(-)
--- a/drivers/usb/host/xhci-ring.c
+++ b/drivers/usb/host/xhci-ring.c
@@ -1268,14 +1268,18 @@ void xhci_handle_command_timeout(unsigne
bool second_timeout = false;
xhci = (struct xhci_hcd *) data;
- /* mark this command to be cancelled */
spin_lock_irqsave(&xhci->lock, flags);
- if (xhci->current_cmd) {
- if (xhci->current_cmd->status == COMP_CMD_ABORT)
- second_timeout = true;
- xhci->current_cmd->status = COMP_CMD_ABORT;
+
+ if (!xhci->current_cmd) {
+ spin_unlock_irqrestore(&xhci->lock, flags);
+ return;
}
+ /* mark this command to be cancelled */
+ if (xhci->current_cmd->status == COMP_CMD_ABORT)
+ second_timeout = true;
+ xhci->current_cmd->status = COMP_CMD_ABORT;
+
/* Make sure command ring is running before aborting it */
hw_ring_state = xhci_read_64(xhci, &xhci->op_regs->cmd_ring);
if ((xhci->cmd_ring_state & CMD_RING_STATE_RUNNING) &&
@@ -1424,6 +1428,8 @@ static void handle_cmd_completion(struct
xhci->current_cmd = list_entry(cmd->cmd_list.next,
struct xhci_command, cmd_list);
mod_timer(&xhci->cmd_timer, jiffies + XHCI_CMD_DEFAULT_TIMEOUT);
+ } else if (xhci->current_cmd == cmd) {
+ xhci->current_cmd = NULL;
}
event_handled:
Back to linux.kernel | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread
[PATCH 4.4 000/101] 4.4.42-stable review Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-01-10 16:20 +0100 [PATCH 4.4 004/101] ARM: davinci: da850: dont add emac clock to lookup table twice Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-01-10 16:20 +0100 [PATCH 4.4 059/101] mei: bus: fix mei_cldev_enable KDoc Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-01-10 16:20 +0100 [PATCH 4.4 026/101] usb: xhci: hold lock over xhci_abort_cmd_ring() Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-01-10 16:20 +0100 [PATCH 4.4 051/101] usb: musb: Fix trying to free already-free IRQ 4 Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-01-10 16:20 +0100 [PATCH 4.4 055/101] USB: serial: kl5kusb105: abort on open exception path Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-01-10 16:20 +0100 [PATCH 4.4 043/101] USB: serial: mos7720: fix NULL-deref at open Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-01-10 16:20 +0100 [PATCH 4.4 020/101] xhci: workaround for hosts missing CAS bit Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-01-10 16:20 +0100 [PATCH 4.4 056/101] ARM: dts: r8a7794: Correct hsusb parent clock Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-01-10 16:20 +0100 [PATCH 4.4 005/101] mac80211: initialize fast-xmit info later Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-01-10 16:20 +0100 [PATCH 4.4 003/101] ALSA: usb-audio: Fix irq/process data synchronization Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-01-10 16:20 +0100 [PATCH 4.4 013/101] USB: gadgetfs: fix use-after-free bug Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-01-10 16:30 +0100 [PATCH 4.4 014/101] USB: gadgetfs: fix checks of wTotalLength in config descriptors Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-01-10 16:30 +0100 [PATCH 4.4 019/101] usb: xhci: fix possible wild pointer Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-01-10 16:30 +0100 [PATCH 4.4 001/101] ALSA: hda - Fix up GPIO for ASUS ROG Ranger Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-01-10 16:30 +0100 [PATCH 4.4 018/101] usb: dwc3: core: avoid Overflow events Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-01-10 16:30 +0100 [PATCH 4.4 011/101] usb: gadgetfs: restrict upper bound on device configuration size Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-01-10 16:30 +0100 [PATCH 4.4 015/101] USB: fix problems with duplicate endpoint addresses Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2017-01-10 16:30 +0100 Re: [PATCH 4.4 000/101] 4.4.42-stable review Shuah Khan <shuah.kh@samsung.com> - 2017-01-10 18:40 +0100 Re: [PATCH 4.4 000/101] 4.4.42-stable review Guenter Roeck <linux@roeck-us.net> - 2017-01-10 23:30 +0100
csiph-web