In the Linux kernel, the following vulnerability has been resolved:
usb: gadget: Fix use-after-free bug by not setting udc->dev.driver
The syzbot fuzzer found a use-after-free bug:
BUG: KASAN: use-after-free in dev_uevent+0x712/0x780 drivers/base/core.c:2320 Read of size 8 at addr ffff88802b934098 by task udevd/3689
CPU: 2 PID: 3689 Comm: udevd Not tainted 5.17.0-rc4-syzkaller-00229-g4f12b742eb2b #0 Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.14.0-2 04/01/2014 Call Trace: <TASK> _dumpstack lib/dumpstack.c:88 [inline] dumpstacklvl+0xcd/0x134 lib/dumpstack.c:106 printaddressdescription.constprop.0.cold+0x8d/0x303 mm/kasan/report.c:255 _kasanreport mm/kasan/report.c:442 [inline] kasanreport.cold+0x83/0xdf mm/kasan/report.c:459 devuevent+0x712/0x780 drivers/base/core.c:2320 ueventshow+0x1b8/0x380 drivers/base/core.c:2391 devattr_show+0x4b/0x90 drivers/base/core.c:2094
Although the bug manifested in the driver core, the real cause was a race with the gadget core. dev_uevent() does:
if (dev->driver)
add_uevent_var(env, "DRIVER=%s", dev->driver->name);
and between the test and the dereference of dev->driver, the gadget core sets dev->driver to NULL.
The race wouldn't occur if the gadget core registered its devices on a real bus, using the standard synchronization techniques of the driver core. However, it's not necessary to make such a large change in order to fix this bug; all we need to do is make sure that udc->dev.driver is always NULL.
In fact, there is no reason for udc->dev.driver ever to be set to anything, let alone to the value it currently gets: the address of the gadget's driver. After all, a gadget driver only knows how to manage a gadget, not how to manage a UDC.
This patch simply removes the statements in the gadget core that touch udc->dev.driver.
[
{
"signature_version": "v1",
"id": "CVE-2022-48838-01c6223d",
"signature_type": "Line",
"target": {
"file": "drivers/usb/gadget/udc/core.c"
},
"digest": {
"line_hashes": [
"61227177221291731177580189121004493848",
"144276535598198676753187764110326126828",
"234293414360168322329453788522026941343",
"97388159165122827676792897850705541883",
"318597179604468091001330211842545411869",
"226648428705913693617593458172454595369",
"204791579673621144741809320606366937064",
"183444539362529300321185352466888178834",
"312555410732839394388624901645913036779",
"189906527202485312648226525170323870443",
"261077656467110910269339816151664646929",
"308763162705057916431658811578047701567"
],
"threshold": 0.9
},
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@4325124dde6726267813c736fee61226f1d38f0b"
},
{
"signature_version": "v1",
"id": "CVE-2022-48838-095b6b0b",
"signature_type": "Function",
"target": {
"file": "drivers/usb/gadget/udc/core.c",
"function": "usb_gadget_remove_driver"
},
"digest": {
"function_hash": "24913189350801412884717128551174460707",
"length": 439.0
},
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@609a7119bffe3ddd7c93f2fa65be8917e02a0b7e"
},
{
"signature_version": "v1",
"id": "CVE-2022-48838-1fddd2e0",
"signature_type": "Function",
"target": {
"file": "drivers/usb/gadget/udc/core.c",
"function": "udc_bind_to_driver"
},
"digest": {
"function_hash": "207480636093287443775877861555490803944",
"length": 816.0
},
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@16b1941eac2bd499f065a6739a40ce0011a3d740"
},
{
"signature_version": "v1",
"id": "CVE-2022-48838-24ac0c8c",
"signature_type": "Function",
"target": {
"file": "drivers/usb/gadget/udc/core.c",
"function": "udc_bind_to_driver"
},
"digest": {
"function_hash": "166042665051792795966603171740435814608",
"length": 795.0
},
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@609a7119bffe3ddd7c93f2fa65be8917e02a0b7e"
},
{
"signature_version": "v1",
"id": "CVE-2022-48838-256def85",
"signature_type": "Function",
"target": {
"file": "drivers/usb/gadget/udc/core.c",
"function": "udc_bind_to_driver"
},
"digest": {
"function_hash": "207480636093287443775877861555490803944",
"length": 816.0
},
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@2015c23610cd0efadaeca4d3a8d1dae9a45aa35a"
},
{
"signature_version": "v1",
"id": "CVE-2022-48838-30d286d6",
"signature_type": "Function",
"target": {
"file": "drivers/usb/gadget/udc/core.c",
"function": "usb_gadget_remove_driver"
},
"digest": {
"function_hash": "166223234064577551979461573460746043691",
"length": 476.0
},
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@2015c23610cd0efadaeca4d3a8d1dae9a45aa35a"
},
{
"signature_version": "v1",
"id": "CVE-2022-48838-33cb04bf",
"signature_type": "Line",
"target": {
"file": "drivers/usb/gadget/udc/core.c"
},
"digest": {
"line_hashes": [
"61227177221291731177580189121004493848",
"144276535598198676753187764110326126828",
"234293414360168322329453788522026941343",
"97388159165122827676792897850705541883",
"318597179604468091001330211842545411869",
"226648428705913693617593458172454595369",
"269252345962251430994346432705904767044",
"26498613583880160042584262946720982939",
"312555410732839394388624901645913036779",
"189906527202485312648226525170323870443",
"261077656467110910269339816151664646929",
"308763162705057916431658811578047701567"
],
"threshold": 0.9
},
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@e2d3a7009e505e120805f449c832942660f3f7f3"
},
{
"signature_version": "v1",
"id": "CVE-2022-48838-38469bcc",
"signature_type": "Function",
"target": {
"file": "drivers/usb/gadget/udc/core.c",
"function": "usb_gadget_remove_driver"
},
"digest": {
"function_hash": "183062239795497336016648605545838087212",
"length": 455.0
},
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@00bdd9bf1ac6d401ad926d3d8df41b9f1399f646"
},
{
"signature_version": "v1",
"id": "CVE-2022-48838-3a509260",
"signature_type": "Line",
"target": {
"file": "drivers/usb/gadget/udc/core.c"
},
"digest": {
"line_hashes": [
"61227177221291731177580189121004493848",
"144276535598198676753187764110326126828",
"234293414360168322329453788522026941343",
"97388159165122827676792897850705541883",
"318597179604468091001330211842545411869",
"226648428705913693617593458172454595369",
"269252345962251430994346432705904767044",
"26498613583880160042584262946720982939",
"312555410732839394388624901645913036779",
"189906527202485312648226525170323870443",
"261077656467110910269339816151664646929",
"308763162705057916431658811578047701567"
],
"threshold": 0.9
},
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@609a7119bffe3ddd7c93f2fa65be8917e02a0b7e"
},
{
"signature_version": "v1",
"id": "CVE-2022-48838-3e0464b5",
"signature_type": "Function",
"target": {
"file": "drivers/usb/gadget/udc/core.c",
"function": "udc_bind_to_driver"
},
"digest": {
"function_hash": "166042665051792795966603171740435814608",
"length": 795.0
},
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@00bdd9bf1ac6d401ad926d3d8df41b9f1399f646"
},
{
"signature_version": "v1",
"id": "CVE-2022-48838-5157fe64",
"signature_type": "Function",
"target": {
"file": "drivers/usb/gadget/udc/core.c",
"function": "usb_gadget_remove_driver"
},
"digest": {
"function_hash": "183062239795497336016648605545838087212",
"length": 455.0
},
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@2282a6eb6d4e118e294e43dcc421e0e0fe4040b5"
},
{
"signature_version": "v1",
"id": "CVE-2022-48838-5664c71c",
"signature_type": "Line",
"target": {
"file": "drivers/usb/gadget/udc/core.c"
},
"digest": {
"line_hashes": [
"61227177221291731177580189121004493848",
"144276535598198676753187764110326126828",
"234293414360168322329453788522026941343",
"292337993485981629263826454614409659818",
"318597179604468091001330211842545411869",
"226648428705913693617593458172454595369",
"269252345962251430994346432705904767044",
"26498613583880160042584262946720982939",
"312555410732839394388624901645913036779",
"189906527202485312648226525170323870443",
"261077656467110910269339816151664646929",
"308763162705057916431658811578047701567"
],
"threshold": 0.9
},
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@00bdd9bf1ac6d401ad926d3d8df41b9f1399f646"
},
{
"signature_version": "v1",
"id": "CVE-2022-48838-572904d0",
"signature_type": "Line",
"target": {
"file": "drivers/usb/gadget/udc/core.c"
},
"digest": {
"line_hashes": [
"61227177221291731177580189121004493848",
"144276535598198676753187764110326126828",
"234293414360168322329453788522026941343",
"292337993485981629263826454614409659818",
"318597179604468091001330211842545411869",
"226648428705913693617593458172454595369",
"269252345962251430994346432705904767044",
"26498613583880160042584262946720982939",
"312555410732839394388624901645913036779",
"189906527202485312648226525170323870443",
"261077656467110910269339816151664646929",
"308763162705057916431658811578047701567"
],
"threshold": 0.9
},
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@27d64436984fb8835a8b7e95993193cc478b162e"
},
{
"signature_version": "v1",
"id": "CVE-2022-48838-57661317",
"signature_type": "Function",
"target": {
"file": "drivers/usb/gadget/udc/core.c",
"function": "udc_bind_to_driver"
},
"digest": {
"function_hash": "207480636093287443775877861555490803944",
"length": 816.0
},
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@27d64436984fb8835a8b7e95993193cc478b162e"
},
{
"signature_version": "v1",
"id": "CVE-2022-48838-7b574527",
"signature_type": "Function",
"target": {
"file": "drivers/usb/gadget/udc/core.c",
"function": "udc_bind_to_driver"
},
"digest": {
"function_hash": "85176436343063614951861987778138550229",
"length": 753.0
},
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@4325124dde6726267813c736fee61226f1d38f0b"
},
{
"signature_version": "v1",
"id": "CVE-2022-48838-801be10e",
"signature_type": "Function",
"target": {
"file": "drivers/usb/gadget/udc/core.c",
"function": "usb_gadget_remove_driver"
},
"digest": {
"function_hash": "166223234064577551979461573460746043691",
"length": 476.0
},
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@27d64436984fb8835a8b7e95993193cc478b162e"
},
{
"signature_version": "v1",
"id": "CVE-2022-48838-a44e517b",
"signature_type": "Line",
"target": {
"file": "drivers/usb/gadget/udc/core.c"
},
"digest": {
"line_hashes": [
"61227177221291731177580189121004493848",
"144276535598198676753187764110326126828",
"234293414360168322329453788522026941343",
"97388159165122827676792897850705541883",
"318597179604468091001330211842545411869",
"226648428705913693617593458172454595369",
"269252345962251430994346432705904767044",
"26498613583880160042584262946720982939",
"312555410732839394388624901645913036779",
"189906527202485312648226525170323870443",
"261077656467110910269339816151664646929",
"308763162705057916431658811578047701567"
],
"threshold": 0.9
},
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@2282a6eb6d4e118e294e43dcc421e0e0fe4040b5"
},
{
"signature_version": "v1",
"id": "CVE-2022-48838-a5c26665",
"signature_type": "Function",
"target": {
"file": "drivers/usb/gadget/udc/core.c",
"function": "usb_gadget_remove_driver"
},
"digest": {
"function_hash": "24913189350801412884717128551174460707",
"length": 439.0
},
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@4325124dde6726267813c736fee61226f1d38f0b"
},
{
"signature_version": "v1",
"id": "CVE-2022-48838-a6e7d696",
"signature_type": "Function",
"target": {
"file": "drivers/usb/gadget/udc/core.c",
"function": "udc_bind_to_driver"
},
"digest": {
"function_hash": "166042665051792795966603171740435814608",
"length": 795.0
},
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@2282a6eb6d4e118e294e43dcc421e0e0fe4040b5"
},
{
"signature_version": "v1",
"id": "CVE-2022-48838-ab91b1bb",
"signature_type": "Function",
"target": {
"file": "drivers/usb/gadget/udc/core.c",
"function": "usb_gadget_remove_driver"
},
"digest": {
"function_hash": "24913189350801412884717128551174460707",
"length": 439.0
},
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@e2d3a7009e505e120805f449c832942660f3f7f3"
},
{
"signature_version": "v1",
"id": "CVE-2022-48838-b3508c35",
"signature_type": "Line",
"target": {
"file": "drivers/usb/gadget/udc/core.c"
},
"digest": {
"line_hashes": [
"61227177221291731177580189121004493848",
"144276535598198676753187764110326126828",
"234293414360168322329453788522026941343",
"292337993485981629263826454614409659818",
"318597179604468091001330211842545411869",
"226648428705913693617593458172454595369",
"269252345962251430994346432705904767044",
"26498613583880160042584262946720982939",
"312555410732839394388624901645913036779",
"189906527202485312648226525170323870443",
"261077656467110910269339816151664646929",
"308763162705057916431658811578047701567"
],
"threshold": 0.9
},
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@16b1941eac2bd499f065a6739a40ce0011a3d740"
},
{
"signature_version": "v1",
"id": "CVE-2022-48838-e9e0c01d",
"signature_type": "Line",
"target": {
"file": "drivers/usb/gadget/udc/core.c"
},
"digest": {
"line_hashes": [
"61227177221291731177580189121004493848",
"144276535598198676753187764110326126828",
"234293414360168322329453788522026941343",
"292337993485981629263826454614409659818",
"318597179604468091001330211842545411869",
"226648428705913693617593458172454595369",
"269252345962251430994346432705904767044",
"26498613583880160042584262946720982939",
"312555410732839394388624901645913036779",
"189906527202485312648226525170323870443",
"261077656467110910269339816151664646929",
"308763162705057916431658811578047701567"
],
"threshold": 0.9
},
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@2015c23610cd0efadaeca4d3a8d1dae9a45aa35a"
},
{
"signature_version": "v1",
"id": "CVE-2022-48838-eecfb60a",
"signature_type": "Function",
"target": {
"file": "drivers/usb/gadget/udc/core.c",
"function": "udc_bind_to_driver"
},
"digest": {
"function_hash": "166042665051792795966603171740435814608",
"length": 795.0
},
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@e2d3a7009e505e120805f449c832942660f3f7f3"
},
{
"signature_version": "v1",
"id": "CVE-2022-48838-feb25be0",
"signature_type": "Function",
"target": {
"file": "drivers/usb/gadget/udc/core.c",
"function": "usb_gadget_remove_driver"
},
"digest": {
"function_hash": "166223234064577551979461573460746043691",
"length": 476.0
},
"deprecated": false,
"source": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git@16b1941eac2bd499f065a6739a40ce0011a3d740"
}
]