mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
* [BUG] usb: gadgetfs: KASAN null-ptr-deref and intermittent UAF in ep_aio_cancel()
@ 2026-06-30 23:08 김민서
  2026-07-01  2:13 ` Alan Stern
  0 siblings, 1 reply; 45+ messages in thread
From: 김민서 @ 2026-06-30 23:08 UTC (permalink / raw)
  To: Greg Kroah-Hartman; +Cc: linux-usb, linux-kernel, syzkaller

Hello,

I am reporting a USB gadgetfs AIO cancellation bug reproduced on upstream
v7.2-rc1, commit dc59e4fea9d83f03bad6bddf3fa2e52491777482, with KASAN
enabled. In my test environment, the reproducer repeatedly triggers a
KASAN null-ptr-deref/general protection fault in ep_aio_cancel(). I also
observed an intermittent slab-use-after-free at the same dereference site.

Target file:
  drivers/usb/gadget/legacy/inode.c
Subsystem: USB gadgetfs
Git tree: https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git
Git head: dc59e4fea9d83f03bad6bddf3fa2e52491777482
Kernel release: v7.2-rc1

Observed crash:

  KASAN: null-ptr-deref in range [0x0000000000000008-0x000000000000000f]
  RIP: ep_aio_cancel+0x47/0xf0 drivers/usb/gadget/legacy/inode.c:455

Additional intermittent UAF observation:

  BUG: KASAN: slab-use-after-free in ep_aio_cancel+0x25/0x90
  drivers/usb/gadget/legacy/inode.c:455

Relevant stack:

  ep_aio_cancel
  __do_sys_io_cancel
  __se_sys_io_cancel
  __x64_sys_io_cancel
  do_syscall_64
  entry_SYSCALL_64_after_hwframe

Root cause analysis:

The crash appears to involve a race between gadgetfs AIO completion and
AIO cancellation.

In drivers/usb/gadget/legacy/inode.c, ep_aio_cancel() does:

  struct kiocb_priv *priv = iocb->private;
  ...
  epdata = priv->epdata;

At the same time, ep_aio_complete() can clear fields in the same private
object and then free it on the completion path before setting
iocb->private to NULL:

  priv->req = NULL;
  priv->epdata = NULL;
  ...
  kfree(req->buf);
  kfree(priv->to_free);
  kfree(priv);
  iocb->private = NULL;

My current understanding is that completion and cancellation are not
effectively serialized around this lifetime transition.

If cancellation observes NULL after iocb->private has been cleared,
ep_aio_cancel() dereferences priv->epdata through a NULL priv pointer and
reports the null-ptr-deref.

If cancellation observes the old non-NULL priv pointer after completion
has freed it, or if completion frees priv after cancellation loads it but
before cancellation reads priv->epdata, the same dereference can surface
as a slab-use-after-free.

Reproducer:

C reproducer:
  https://raw.githubusercontent.com/neck392/linux-kernel-bug-reports/main/gadgetfs_ep_aio_cancel_minimal_20260630/reproducers/repro_ndr_decoylock.c

Additional C reproducer used for the intermittent UAF observation:
  https://raw.githubusercontent.com/neck392/linux-kernel-bug-reports/main/gadgetfs_ep_aio_cancel_minimal_20260630/reproducers/repro_uaf_decoylock_107000_96000.c

Symbolized KASAN report:
  https://raw.githubusercontent.com/neck392/linux-kernel-bug-reports/main/gadgetfs_ep_aio_cancel_minimal_20260630/reports/clean_report_ndr_inline.txt

Additional symbolized UAF report:
  https://raw.githubusercontent.com/neck392/linux-kernel-bug-reports/main/gadgetfs_ep_aio_cancel_minimal_20260630/reports/clean_report_uaf_outline.txt

Kernel config:
  https://raw.githubusercontent.com/neck392/linux-kernel-bug-reports/main/gadgetfs_ep_aio_cancel_minimal_20260630/configs/kernel.config.v7.2-rc1-kasan-inline

Additional KASAN_OUTLINE config used for the intermittent UAF observation:
  https://raw.githubusercontent.com/neck392/linux-kernel-bug-reports/main/gadgetfs_ep_aio_cancel_minimal_20260630/configs/kernel.config.v7.2-rc1-kasan-outline

Build:

  gcc -O2 -Wall -Wextra -pthread -o repro_ndr_decoylock repro_ndr_decoylock.c
  gcc -O2 -Wall -Wextra -pthread -o repro_uaf_decoylock_107000_96000
repro_uaf_decoylock_107000_96000.c

Key config options:

  CONFIG_USB_GADGETFS=y
  CONFIG_USB_DUMMY_HCD=y
  CONFIG_AIO=y
  CONFIG_KASAN=y
  CONFIG_KASAN_GENERIC=y

Runtime conditions:

  x86_64 QEMU/KVM
  dummy_hcd + gadgetfs; physical USB hardware is not required
  kasan_multi_shot=1
  slub_debug=FZPU

The reproducer uses root only for the privileged environment setup
(dummy_hcd-backed gadgetfs setup, mounting gadgetfs, writing the initial
gadget descriptors/configuration through the control endpoint, and
preparing the endpoint file permissions). It then drops to uid/gid 1000
before opening/using the endpoint file(s) and triggering the AIO
completion/cancellation race. The faulting task in the null-ptr-deref
report is uid 1000.

Brief KASAN excerpt:

  Oops: general protection fault, probably for non-canonical address
  0xdffffc0000000001
  KASAN: null-ptr-deref in range [0x0000000000000008-0x000000000000000f]
  CPU: 2 UID: 1000 PID: 358 Comm: gdecoylock Not tainted 7.2.0-rc1
  RIP: 0010:ep_aio_cancel+0x47/0xf0 drivers/usb/gadget/legacy/inode.c:455

  Call Trace:
    __do_sys_io_cancel
    __se_sys_io_cancel
    __x64_sys_io_cancel
    do_syscall_64
    entry_SYSCALL_64_after_hwframe

If you fix this issue, please add the following tag to the commit:

  Reported-by: Minseo Kim <neck3922@gmail.com>

If you need anything else, please let me know.

Best regards,
Minseo Kim

^ permalink raw reply	[flat|nested] 45+ messages in thread

end of thread, other threads:[~2026-09-18 14:17 UTC | newest]

Thread overview: 45+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-06-30 23:08 [BUG] usb: gadgetfs: KASAN null-ptr-deref and intermittent UAF in ep_aio_cancel() 김민서
2026-07-01  2:13 ` Alan Stern
2026-07-02  8:08   ` 김민서
2026-07-02 14:22     ` Alan Stern
2026-07-06  1:18       ` 김민서
2026-07-07 17:31         ` Alan Stern
2026-07-13 18:47           ` Minseo Kim
2026-07-14  3:23             ` Alan Stern
2026-07-19 20:59               ` Minseo Kim
2026-07-21  2:18                 ` Alan Stern
2026-07-29 15:31                   ` Alan Stern
2026-07-30 15:55                     ` Minseo Kim
2026-07-31 18:59                       ` Alan Stern
2026-08-02  6:08                         ` Minseo Kim
2026-08-02 16:07                           ` Alan Stern
2026-08-04 23:12                             ` Minseo Kim
2026-08-05 16:17                               ` Alan Stern
2026-08-09 22:19                                 ` Andrey Konovalov
2026-08-14 16:17                                 ` Alan Stern
2026-08-17 19:49                                   ` Minseo Kim
2026-08-18  2:57                                     ` Alan Stern
2026-08-20  9:40                                       ` Minseo Kim
2026-08-20 14:08                                         ` Alan Stern
2026-08-22 20:26                                           ` Minseo Kim
2026-08-23  1:10                                             ` Alan Stern
2026-08-28 20:30                                               ` neck3922
2026-08-29 16:08                                                 ` Alan Stern
2026-08-31 13:30                                                   ` Minseo Kim
2026-09-01  2:47                                                     ` Alan Stern
2026-09-04 14:00                                                       ` Minseo Kim
2026-09-04 20:09                                                         ` Alan Stern
2026-09-07 13:00                                                           ` Minseo Kim
2026-09-08 19:02                                                             ` Alan Stern
2026-09-10 14:00                                                               ` Minseo Kim
2026-09-10 15:50                                                                 ` Alan Stern
2026-09-11 14:00                                                                   ` Minseo Kim
2026-09-11 19:22                                                                     ` Alan Stern
2026-09-14 14:00                                                                       ` Minseo Kim
2026-09-14 16:00                                                                         ` Alan Stern
2026-09-16 14:00                                                                           ` Minseo Kim
2026-09-16 19:39                                                                             ` Alan Stern
2026-09-17 14:02                                                                               ` Minseo Kim
2026-09-17 15:38                                                                                 ` Alan Stern
2026-09-18 13:30                                                                                   ` Minseo Kim
2026-09-18 14:17                                                                                     ` Alan Stern

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®