usb: gadget: qdss: Add NULL check against channel with usb_qdss_free_req()

USB requests are being freed from 2 context from Linux QDSS driver:
1. usb_qdss_close()
2. explicitly calling usb_free_request() on receiving USB_QDSS_DISCONNECT

usb_qdss_close() is setting drvdata->usbch to NULL. Hence it ends up
passing usbch as NULL while calling usb_free_request() when handling
USB_QDSS_DISCONNECT. Fix this NULL pointer dereference issue by explicitly
checking USB channel against NULL with usb_qdss_free_req().

Change-Id: Ia55a30b09ab1f94db15947b984fd232a33da7788
Signed-off-by: Mayank Rana <mrana@codeaurora.org>
This commit is contained in:
Mayank Rana 2020-10-30 13:03:20 -07:00 • committed by Gerrit - the friendly Code Review server
commit 8b51dad4aa

View file

@ -256,12 +256,13 @@ void usb_qdss_free_req(struct usb_qdss_ch *ch)
unsigned long flags;
spin_lock_irqsave(&channel_lock, flags);
qdss = ch->priv_usb;
if (!qdss) {
if (ch == NULL || ch->priv_usb == NULL) {
spin_unlock_irqrestore(&channel_lock, flags);
pr_err("%s: qdss ctx is NULL\n", __func__);
pr_err("%s: qdss channel or qdss ctx is NULL\n", __func__);
return;
}
qdss = ch->priv_usb;
spin_unlock_irqrestore(&channel_lock, flags);
spin_lock_irqsave(&qdss->lock, flags);