summaryrefslogtreecommitdiffstats
path: root/drivers/usb/dwc3
AgeCommit message (Collapse)Author
10 daysusb: dwc3: gadget: fix IRQ storm on invalid event buffer countJiazi Liu
When dwc3_check_event_buf() reads a GEVNTCOUNT value exceeding the event buffer length, commit 63ccd26cd1f6 ("usb: dwc3: gadget: check that event count does not exceed event buffer length") returns IRQ_NONE without writing back GEVNTCOUNT. Since the DWC3 interrupt is level-triggered, the uncleared IRQ source keeps the line asserted, causing a tight IRQ storm that accumulates 99,900 unhandled interrupts and triggers spurious.c:184 BUG -> kernel panic. The resulting call stack: __report_bad_irq+0xac/0xc8 note_interrupt+0x340/0x468 handle_irq_event+0xac/0xc0 handle_fasteoi_irq+0x120/0x228 gic_handle_irq+0x68/0x108 ... kernel BUG at kernel/irq/spurious.c:184 To reproduce, write a bogus value exceeding the event buffer length directly to the GEVNTCOUNT register: devmem <DWC3_BASE + 0xc40c> 4 0x1004 Write the bogus count back to GEVNTCOUNT to clear the IRQ source, consistent with the stale event clearing pattern in dwc3_event_buffers_setup(), and schedule error recovery to reinitialize the controller. Fixes: 63ccd26cd1f6 ("usb: dwc3: gadget: check that event count does not exceed event buffer length") Cc: stable <stable@kernel.org> Suggested-by: Thinh Nguyen <Thinh.Nguyen@synopsys.com> Signed-off-by: Jiazi Liu <jiazi.liu1984@gmail.com> Link: https://patch.msgid.link/20260915110637.17658-1-jiazi.liu1984@gmail.com Acked-by: Thinh Nguyen <Thinh.Nguyen@synopsys.com> Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
10 daysRevert "usb: dwc3: gadget: fix IRQ storm on invalid event buffer count"Greg Kroah-Hartman
This reverts commit a107edec57659c5a1a2f016311b944af58c904c9. It was incorrectly applied, and was 2 versions old. The "correct" one will be added instead afterward... Cc: stable <stable@kernel.org> Cc: Jiazi Liu <jiazi.liu1984@gmail.com> Reported-by: Thinh Nguyen <Thinh.Nguyen@synopsys.com> Fixes: a107edec5765 ("usb: dwc3: gadget: fix IRQ storm on invalid event buffer count") Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
10 daysusb: dwc3: gadget: fix IRQ storm on invalid event buffer countJiazi Liu
When dwc3_check_event_buf() reads a GEVNTCOUNT value exceeding the event buffer length, commit 63ccd26cd1f6 ("usb: dwc3: gadget: check that event count does not exceed event buffer length") returns IRQ_NONE without writing back GEVNTCOUNT. Since the DWC3 interrupt is level-triggered, the uncleared IRQ source keeps the line asserted, causing a tight IRQ storm that accumulates 99,900 unhandled interrupts and triggers spurious.c:184 BUG -> kernel panic. The resulting call stack: __report_bad_irq+0xac/0xc8 note_interrupt+0x340/0x468 handle_irq_event+0xac/0xc0 handle_fasteoi_irq+0x120/0x228 gic_handle_irq+0x68/0x108 ... kernel BUG at kernel/irq/spurious.c:184 To reproduce, write a bogus value exceeding the event buffer length directly to the GEVNTCOUNT register: devmem <DWC3_BASE + 0xc40c> 4 0x1004 Write the bogus count back to GEVNTCOUNT to clear the IRQ source, consistent with the stale event clearing pattern in dwc3_event_buffers_setup(), and schedule error recovery to reinitialize the controller. Fixes: 63ccd26cd1f6 ("usb: dwc3: gadget: check that event count does not exceed event buffer length") Cc: stable <stable@kernel.org> Co-developed-by: Thinh Nguyen <Thinh.Nguyen@synopsys.com> Signed-off-by: Thinh Nguyen <Thinh.Nguyen@synopsys.com> Signed-off-by: Jiazi Liu <jiazi.liu1984@gmail.com> Suggested-by: Thinh Nguyen <Thinh.Nguyen@synopsys.com> Link: https://patch.msgid.link/20260907073756.22329-1-jiazi.liu1984@gmail.com Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
10 daysusb: gadget: f_uac1_legacy: validate bRequest index in generic_{set,get}_cmdgraftedLiu Chao
generic_set_cmd() and generic_get_cmd() use the low nibble of ctrl->bRequest as an index into con->data[]: u8 cmd = (ctrl->bRequest & 0x0F); /* 0 .. 15 */ ... con->data[cmd] = value; /* OOB when cmd >= 5 */ struct usb_audio_control (include/linux/usb/audio.h) declares data as a 5-element array, so indices 5 through 15 write (or read) up to 44 bytes past the end of the array on the heap. A malicious USB host can craft a class-specific SET_CUR / GET_CUR request with an arbitrary bRequest value, triggering the out-of-bounds access from an IRQ completion handler with no further preconditions. Add an ARRAY_SIZE() guard to both functions. Fixes: c47d7b09891a ("USB: audio: add USB audio class definitions") Cc: stable <stable@kernel.org> Reviewed-by: Weibin Liu <liuwb@xiaopeng.com> Signed-off-by: Liu Chao <liuc63@xiaopeng.com> Reviewed-by: Ivy Lopez <skunkolee@gmail.com> Link: https://patch.msgid.link/20260921072551.3708191-1-liuc63@xiaopeng.com Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>