On Tue Aug 4 10:18:21 2026 +0530, Anuj Bolewar wrote:
> hackrf_alloc_urbs() frees the URBs it allocated so far when one
> allocation fails, but leaves the entries in dev->urb_list[] and
> dev->urbs_initialized untouched. The caller, hackrf_start_streaming(),
> then calls hackrf_free_urbs() on the error path, which walks
> dev->urbs_initialized entries and calls usb_free_urb() a second time on
> the already-freed URBs, causing a use-after-free (slab-use-after-free
> Write in usb_free_urb()).
> 
> Drop the redundant cleanup loop inside hackrf_alloc_urbs() and let
> hackrf_free_urbs(), which the caller already invokes on error, own the
> cleanup of the successfully allocated URBs.
> 
> Reported-by: [email protected]
> Closes: https://syzkaller.appspot.com/bug?extid=832ce9fa3face1b7d44d
> Fixes: 969ec1f6bd92 ("[media] hackrf: HackRF SDR driver")
> Cc: [email protected]
> Signed-off-by: Anuj Bolewar <[email protected]>
> Signed-off-by: Hans Verkuil <[email protected]>

Patch committed.

Thanks,
Hans Verkuil

 drivers/media/usb/hackrf/hackrf.c | 7 ++-----
 1 file changed, 2 insertions(+), 5 deletions(-)

---

diff --git a/drivers/media/usb/hackrf/hackrf.c 
b/drivers/media/usb/hackrf/hackrf.c
index a15829a60e88..70fd95f3e97d 100644
--- a/drivers/media/usb/hackrf/hackrf.c
+++ b/drivers/media/usb/hackrf/hackrf.c
@@ -665,7 +665,7 @@ static int hackrf_free_urbs(struct hackrf_dev *dev)
 
 static int hackrf_alloc_urbs(struct hackrf_dev *dev, bool rcv)
 {
-       int i, j;
+       int i;
        unsigned int pipe;
        usb_complete_t complete;
 
@@ -681,11 +681,8 @@ static int hackrf_alloc_urbs(struct hackrf_dev *dev, bool 
rcv)
        for (i = 0; i < MAX_BULK_BUFS; i++) {
                dev_dbg(dev->dev, "alloc urb=%d\n", i);
                dev->urb_list[i] = usb_alloc_urb(0, GFP_KERNEL);
-               if (!dev->urb_list[i]) {
-                       for (j = 0; j < i; j++)
-                               usb_free_urb(dev->urb_list[j]);
+               if (!dev->urb_list[i])
                        return -ENOMEM;
-               }
                usb_fill_bulk_urb(dev->urb_list[i],
                                dev->udev,
                                pipe,
_______________________________________________
linuxtv-commits mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to