mirror of
https://github.com/torvalds/linux.git
synced 2026-09-11 20:13:02 +02:00
usb-storage: ene_ub6250: fix race between scan work and probe
ene_ub6250_probe() calls usb_stor_probe2(), which starts the usb-storage infrastructure and schedules the delayed scan work. The driver then calls ene_get_card_type(), which sends an ENE command through ene_send_scsi_cmd() and the usb-storage bulk transfer helpers. Both the delayed scan work, through usb_stor_Bulk_max_lun(), and ene_get_card_type() use us->current_urb. The scan work serializes this access with us->dev_mutex, but the ENE card-type probe does not. If the scan work runs while ene_get_card_type() is still using us->current_urb, usb_submit_urb() warns that the URB is already active. Serialize ene_get_card_type() with us->dev_mutex, matching the locking used by the scan path. Reported-by: syzbot+22ea20ef3afb6785b122@syzkaller.appspotmail.com Cc: stable <stable@kernel.org> Closes: https://syzkaller.appspot.com/bug?extid=22ea20ef3afb6785b122 Assisted-by: Qwen:Qwen3.6 Signed-off-by: Liu Qi <liuqi@longcheer.com> Acked-by: Alan Stern <stern@rowland.harvard.edu> Link: https://patch.msgid.link/20260821090416.1247127-1-liuqi@longcheer.com Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
This commit is contained in:
parent
dd0eed9e16
commit
445fc368c6
|
|
@ -2357,7 +2357,9 @@ static int ene_ub6250_probe(struct usb_interface *intf,
|
|||
return result;
|
||||
|
||||
/* probe card type */
|
||||
mutex_lock(&us->dev_mutex);
|
||||
result = ene_get_card_type(us, REG_CARD_STATUS, info->bbuf);
|
||||
mutex_unlock(&us->dev_mutex);
|
||||
if (result != USB_STOR_XFER_GOOD) {
|
||||
usb_stor_disconnect(intf);
|
||||
return USB_STOR_TRANSPORT_ERROR;
|
||||
|
|
|
|||
Loading…
Reference in New Issue
Block a user