Commit 34d17c88 authored by Chris Wulff's avatar Chris Wulff Committed by Ye Bin
Browse files

usb: gadget: core: Check for unset descriptor

mainline inclusion
from mainline-v6.11-rc3
commit 973a57891608a98e894db2887f278777f564de18
category: bugfix
bugzilla: https://gitee.com/src-openeuler/kernel/issues/IAOXZ1
CVE: CVE-2024-44960

Reference: https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?id=973a57891608a98e894db2887f278777f564de18



--------------------------------

Make sure the descriptor has been set before looking at maxpacket.
This fixes a null pointer panic in this case.

This may happen if the gadget doesn't properly set up the endpoint
for the current speed, or the gadget descriptors are malformed and
the descriptor for the speed/endpoint are not found.

No current gadget driver is known to have this problem, but this
may cause a hard-to-find bug during development of new gadgets.

Fixes: 54f83b8c ("USB: gadget: Reject endpoints with 0 maxpacket value")
Cc: stable@vger.kernel.org
Signed-off-by: default avatarChris Wulff <crwulff@gmail.com>
Link: https://lore.kernel.org/r/20240725010419.314430-2-crwulff@gmail.com


Signed-off-by: default avatarGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Signed-off-by: default avatarYe Bin <yebin10@huawei.com>
parent 95444973
Loading
Loading
Loading
Loading
+4 −6
Original line number Diff line number Diff line
@@ -99,12 +99,10 @@ int usb_ep_enable(struct usb_ep *ep)
		goto out;

	/* UDC drivers can't handle endpoints with maxpacket size 0 */
	if (usb_endpoint_maxp(ep->desc) == 0) {
		/*
		 * We should log an error message here, but we can't call
		 * dev_err() because there's no way to find the gadget
		 * given only ep.
		 */
	if (!ep->desc || usb_endpoint_maxp(ep->desc) == 0) {
		WARN_ONCE(1, "%s: ep%d (%s) has %s\n", __func__, ep->address, ep->name,
			  (!ep->desc) ? "NULL descriptor" : "maxpacket 0");

		ret = -EINVAL;
		goto out;
	}