Linux kernel mirror (for testing) git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git
kernel os linux
1
fork

Configure Feed

Select the types of activity you want to include in your feed.

usb: gadget: u_ether: Fix NULL pointer deref in eth_get_drvinfo

Commit ec35c1969650 ("usb: gadget: f_ncm: Fix net_device lifecycle with
device_move") reparents the gadget device to /sys/devices/virtual during
unbind, clearing the gadget pointer. If the userspace tool queries on
the surviving interface during this detached window, this leads to a
NULL pointer dereference.

Unable to handle kernel NULL pointer dereference
Call trace:
eth_get_drvinfo+0x50/0x90
ethtool_get_drvinfo+0x5c/0x1f0
__dev_ethtool+0xaec/0x1fe0
dev_ethtool+0x134/0x2e0
dev_ioctl+0x338/0x560

Add a NULL check for dev->gadget in eth_get_drvinfo(). When detached,
skip copying the fw_version and bus_info strings, which is natively
handled by ethtool_get_drvinfo for empty strings.

Suggested-by: Val Packett <val@packett.cool>
Reported-by: Val Packett <val@packett.cool>
Closes: https://lore.kernel.org/linux-usb/10890524-cf83-4a71-b879-93e2b2cc1fcc@packett.cool/
Fixes: ec35c1969650 ("usb: gadget: f_ncm: Fix net_device lifecycle with device_move")
Cc: stable <stable@kernel.org>
Signed-off-by: Kuen-Han Tsai <khtsai@google.com>
Link: https://patch.msgid.link/20260316-eth-null-deref-v1-1-07005f33be85@google.com
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>

authored by

Kuen-Han Tsai and committed by
Greg Kroah-Hartman
e002e92e 2ca9e46f

+4 -2
+4 -2
drivers/usb/gadget/function/u_ether.c
··· 113 113 114 114 strscpy(p->driver, "g_ether", sizeof(p->driver)); 115 115 strscpy(p->version, UETH__VERSION, sizeof(p->version)); 116 - strscpy(p->fw_version, dev->gadget->name, sizeof(p->fw_version)); 117 - strscpy(p->bus_info, dev_name(&dev->gadget->dev), sizeof(p->bus_info)); 116 + if (dev->gadget) { 117 + strscpy(p->fw_version, dev->gadget->name, sizeof(p->fw_version)); 118 + strscpy(p->bus_info, dev_name(&dev->gadget->dev), sizeof(p->bus_info)); 119 + } 118 120 } 119 121 120 122 /* REVISIT can also support: