Re: [PATCH] usb: core: Strengthen error handling in hub_hub_status()

From: Alan Stern

Date: Tue Jul 14 2026 - 12:34:20 EST


On Tue, Jul 14, 2026 at 11:04:33AM +0200, Griffin Kroah-Hartman wrote:
> Add additional error handling after the call to get_hub_status() in
> hub_hub_status().
>
> get_hub_status() uses usb_control_msg() which does not verify that the
> message is the correct length, substituting it for
> usb_control_msg_recv() would also solve this issue but increase memory
> allocations.
>
> Instead, error handling is copied from the method used in
> hub_ext_port_status(), which shares the same flow of logic as
> hub_hub_status().
>
> Assisted-by: gkh_clanker_t1000
> Signed-off-by: Griffin Kroah-Hartman <griffin@xxxxxxxxx>
> ---
> drivers/usb/core/hub.c | 4 +++-
> 1 file changed, 3 insertions(+), 1 deletion(-)
>
> diff --git a/drivers/usb/core/hub.c b/drivers/usb/core/hub.c
> index 5262e11c12cd..0d2166b8923a 100644
> --- a/drivers/usb/core/hub.c
> +++ b/drivers/usb/core/hub.c
> @@ -991,10 +991,12 @@ static int hub_hub_status(struct usb_hub *hub,
>
> mutex_lock(&hub->status_mutex);
> ret = get_hub_status(hub->hdev, &hub->status->hub);
> - if (ret < 0) {
> + if (ret < sizeof(hub->status->hub)) {
> if (ret != -ENODEV)
> dev_err(hub->intfdev,
> "%s failed (err = %d)\n", __func__, ret);
> + if (ret >= 0)
> + ret = -EIO;

It would be better to put these two lines above the preceding test.
That way it won't print confusing things like "hub_hub_status failed
(err = 2)".

Alan Stern

> } else {
> *status = le16_to_cpu(hub->status->hub.wHubStatus);
> *change = le16_to_cpu(hub->status->hub.wHubChange);
>
> ---
> base-commit: a13c140cc289c0b7b3770bce5b3ad42ab35074aa
> change-id: 20260714-usb_core_patches_2-a3eb9d1b7b9e
>
> Best regards,
> --
> Griffin Kroah-Hartman <griffin@xxxxxxxxx>