Re: [PATCH] usb: core: sysfs: add lock to bos_descriptors_read()
From: Alan Stern
Date: Wed Jul 15 2026 - 12:17:11 EST
On Wed, Jul 15, 2026 at 04:59:05PM +0200, Griffin Kroah-Hartman wrote:
> Add a lock to the function bos_descriptors_read().
>
> This function accesses udev->bos, which could be simultaneously freed in
> usb_reset_and_verify_device(), a function that is commonly called in
> drivers all over the kernel.
>
> Assisted-by: gkh_clanker_t1000
> Signed-off-by: Griffin Kroah-Hartman <griffin@xxxxxxxxx>
> ---
Acked-by: Alan Stern <stern@xxxxxxxxxxxxxxxxxxx>
> drivers/usb/core/sysfs.c | 8 +++++++-
> 1 file changed, 7 insertions(+), 1 deletion(-)
>
> diff --git a/drivers/usb/core/sysfs.c b/drivers/usb/core/sysfs.c
> index a07866f1060c..d22dc78457d7 100644
> --- a/drivers/usb/core/sysfs.c
> +++ b/drivers/usb/core/sysfs.c
> @@ -899,10 +899,15 @@ bos_descriptors_read(struct file *filp, struct kobject *kobj,
> {
> struct device *dev = kobj_to_dev(kobj);
> struct usb_device *udev = to_usb_device(dev);
> - struct usb_host_bos *bos = udev->bos;
> + struct usb_host_bos *bos;
> struct usb_bos_descriptor *desc;
> size_t desclen, n = 0;
> + int rc;
>
> + rc = usb_lock_device_interruptible(udev);
> + if (rc < 0)
> + return -EINTR;
> + bos = udev->bos;
> if (bos) {
> desc = bos->desc;
> desclen = le16_to_cpu(desc->wTotalLength);
> @@ -911,6 +916,7 @@ bos_descriptors_read(struct file *filp, struct kobject *kobj,
> memcpy(buf, (void *) desc + off, n);
> }
> }
> + usb_unlock_device(udev);
> return n;
> }
> static const BIN_ATTR_RO(bos_descriptors, 65535); /* max-size BOS */
>
> ---
> base-commit: a13c140cc289c0b7b3770bce5b3ad42ab35074aa
> change-id: 20260715-usb_core_patches_3-a4ce9f00d92b
>
> Best regards,
> --
> Griffin Kroah-Hartman <griffin@xxxxxxxxx>
>
>