From 057df423bf4747091cf942af57307627e941e1fb Mon Sep 17 00:00:00 2001 From: David Laight Date: Mon, 8 Jun 2026 10:55:21 +0100 Subject: [PATCH] usb_string_copy: Use kzalloc() to avoid leaking old data If the string is read while being updated (which is why the copy is done in place) and the new string is longer than the old one, then the reader can read memory that isnt part of either string. Use memcpy() to copy the known length string instead of strcpy. Signed-off-by: David Laight Link: https://patch.msgid.link/20260608095523.2606-37-david.laight.linux@gmail.com Signed-off-by: Greg Kroah-Hartman --- drivers/usb/gadget/configfs.c | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/drivers/usb/gadget/configfs.c b/drivers/usb/gadget/configfs.c index 183a25f65ac8..4518dc6bb5af 100644 --- a/drivers/usb/gadget/configfs.c +++ b/drivers/usb/gadget/configfs.c @@ -125,11 +125,11 @@ static int usb_string_copy(const char *s, char **s_copy) if (copy) { str = copy; } else { - str = kmalloc(USB_MAX_STRING_WITH_NULL_LEN, GFP_KERNEL); + str = kzalloc(USB_MAX_STRING_WITH_NULL_LEN, GFP_KERNEL); if (!str) return -ENOMEM; } - strcpy(str, s); + memcpy(str, s, ret + 1); if (str[ret - 1] == '\n') str[ret - 1] = '\0'; *s_copy = str;