No description
  • C 98.2%
  • Assembly 1%
  • Makefile 0.3%
  • Shell 0.2%
  • Python 0.1%
Find a file
Repository files (latest commit first)
Filename Latest commit message Latest commit date
Lizhi Xu 285d4b953f usbnet: Prevents free active kevent
[ Upstream commit 420c84c330d1688b8c764479e5738bbdbf0a33de ]

The root cause of this issue are:
1. When probing the usbnet device, executing usbnet_link_change(dev, 0, 0);
put the kevent work in global workqueue. However, the kevent has not yet
been scheduled when the usbnet device is unregistered. Therefore, executing
free_netdev() results in the "free active object (kevent)" error reported
here.

2. Another factor is that when calling usbnet_disconnect()->unregister_netdev(),
if the usbnet device is up, ndo_stop() is executed to cancel the kevent.
However, because the device is not up, ndo_stop() is not executed.

The solution to this problem is to cancel the kevent before executing
free_netdev().

Fixes: a69e617e533e ("usbnet: Fix linkwatch use-after-free on disconnect")
Reported-by: Sam Sun <samsun1006219@gmail.com>
Closes: https://syzkaller.appspot.com/bug?extid=8bfd7bcc98f7300afb84
Signed-off-by: Lizhi Xu <lizhi.xu@windriver.com>
Link: https://patch.msgid.link/20251022024007.1831898-1-lizhi.xu@windriver.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2025-12-03 12:45:05 +01:00
arch x86/bugs: Fix reporting of LFENCE retpoline 2025-12-03 12:45:04 +01:00
block block: use int to store blk_stack_limits() return value 2025-10-29 13:59:46 +01:00
certs
crypto crypto: essiv - Check ssize for decryption and in-place encryption 2025-10-29 13:59:52 +01:00
Documentation arm64: errata: Apply workarounds for Neoverse-V3AE 2025-10-29 14:00:00 +01:00
drivers usbnet: Prevents free active kevent 2025-12-03 12:45:05 +01:00
fs btrfs: use smp_mb__after_atomic() when forcing COW in create_pending_snapshot() 2025-12-03 12:45:04 +01:00
include net/sched: sch_qfq: Fix null-deref in agg_dequeue 2025-12-03 12:45:04 +01:00
init bpfilter: match bit size of bpfilter_umh to that of the kernel 2025-07-17 18:24:51 +02:00
ipc
kernel padata: Reset next CPU when reorder sequence wraps around 2025-10-29 14:00:01 +01:00
lib lib/genalloc: fix device leak in of_gen_pool_get() 2025-10-29 13:59:53 +01:00
LICENSES
mm mm: hugetlb: avoid soft lockup when mprotect to large memory area 2025-10-29 13:59:50 +01:00
net net/sched: sch_qfq: Fix null-deref in agg_dequeue 2025-12-03 12:45:04 +01:00
samples samples: mei: Fix building on musl libc 2025-08-28 16:21:19 +02:00
scripts randstruct: gcc-plugin: Fix attribute addition 2025-09-09 18:44:01 +02:00
security KEYS: trusted_tpm1: Compare HMAC values in constant time 2025-10-29 14:00:01 +01:00
sound ASoC: qdsp6: q6asm: do not sleep while atomic 2025-12-03 12:45:05 +01:00
tools rseq/selftests: Use weak symbol reference, not definition, to link with glibc 2025-10-29 13:59:54 +01:00
usr kbuild: hdrcheck: fix cross build with clang 2025-07-17 18:24:51 +02:00
virt
.clang-format
.cocciconfig
.get_maintainer.ignore
.gitattributes
.gitignore
.mailmap
COPYING
CREDITS
Kbuild
Kconfig
MAINTAINERS platform: Add Surface platform directory 2025-06-27 11:02:56 +01:00
Makefile Linux 5.4.301 2025-10-29 14:00:02 +01:00
README

Linux kernel
============

There are several guides for kernel developers and users. These guides can
be rendered in a number of formats, like HTML and PDF. Please read
Documentation/admin-guide/README.rst first.

In order to build the documentation, use ``make htmldocs`` or
``make pdfdocs``.  The formatted documentation can also be read online at:

    https://www.kernel.org/doc/html/latest/

There are various text files in the Documentation/ subdirectory,
several of them using the Restructured Text markup notation.

Please read the Documentation/process/changes.rst file, as it contains the
requirements for building and running the kernel, and information about
the problems which may result by upgrading your kernel.