summaryrefslogtreecommitdiffstats
path: root/include
diff options
context:
space:
mode:
authorJiazi Liu <jiazi.liu1984@gmail.com>2026-09-15 19:06:37 +0800
committerGreg Kroah-Hartman <gregkh@linuxfoundation.org>2026-10-01 10:22:53 +0200
commit1ff77cbefe5a653ea12874c213ea4bd0d72c1067 (patch)
treef031c139bb4d87c6babf945d1a2ab63ee5f899aa /include
parenta3e981f42557d7bb4cb212462de463e0b6b8875b (diff)
downloadlinux-stable-1ff77cbefe5a653ea12874c213ea4bd0d72c1067.tar.gz
linux-stable-1ff77cbefe5a653ea12874c213ea4bd0d72c1067.zip
usb: dwc3: gadget: fix IRQ storm on invalid event buffer count
When dwc3_check_event_buf() reads a GEVNTCOUNT value exceeding the event buffer length, commit 63ccd26cd1f6 ("usb: dwc3: gadget: check that event count does not exceed event buffer length") returns IRQ_NONE without writing back GEVNTCOUNT. Since the DWC3 interrupt is level-triggered, the uncleared IRQ source keeps the line asserted, causing a tight IRQ storm that accumulates 99,900 unhandled interrupts and triggers spurious.c:184 BUG -> kernel panic. The resulting call stack: __report_bad_irq+0xac/0xc8 note_interrupt+0x340/0x468 handle_irq_event+0xac/0xc0 handle_fasteoi_irq+0x120/0x228 gic_handle_irq+0x68/0x108 ... kernel BUG at kernel/irq/spurious.c:184 To reproduce, write a bogus value exceeding the event buffer length directly to the GEVNTCOUNT register: devmem <DWC3_BASE + 0xc40c> 4 0x1004 Write the bogus count back to GEVNTCOUNT to clear the IRQ source, consistent with the stale event clearing pattern in dwc3_event_buffers_setup(), and schedule error recovery to reinitialize the controller. Fixes: 63ccd26cd1f6 ("usb: dwc3: gadget: check that event count does not exceed event buffer length") Cc: stable <stable@kernel.org> Suggested-by: Thinh Nguyen <Thinh.Nguyen@synopsys.com> Signed-off-by: Jiazi Liu <jiazi.liu1984@gmail.com> Link: https://patch.msgid.link/20260915110637.17658-1-jiazi.liu1984@gmail.com Acked-by: Thinh Nguyen <Thinh.Nguyen@synopsys.com> Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
Diffstat (limited to 'include')
0 files changed, 0 insertions, 0 deletions