Re: [BUG] ci_hdrc_add_device -- KASAN slab-out-of-bounds reading a FOREIGN device's platform_data
From: Greg Kroah-Hartman
Date: Fri Aug 28 2026 - 02:12:40 EST
On Fri, Aug 28, 2026 at 08:01:19AM +0200, Greg Kroah-Hartman wrote:
> On Thu, Aug 27, 2026 at 10:34:56PM -0700, Farhad Alemi wrote:
> > Hello,
> >
> > As part of the kernel research at ASU's SEFCOM
> > lab, we hit the crash below. Crash reports can be found here:
> >
> > https://github.com/farhad-alemi/public_bug_reports/tree/main/150-usb-chipidea-foreign-platform_data-oob/
> >
> > BUG: KASAN: slab-out-of-bounds in ci_hdrc_add_device+0xb76/0xd10
> > Read of size 4 at addr ffff88810e9061c8 by task repro/9505
> > Call Trace:
> > ci_hdrc_add_device+0xb76/0xd10
> > ci_hdrc_usb2_probe+0x22d/0x370
> > platform_probe+0xf9/0x190
> > really_probe+0x267/0xaf0
> > __driver_probe_device+0x1e2/0x350
> > device_driver_attach+0xe0/0x1d0
> > bind_store+0x1d0/0x220
> > kernfs_fop_write_iter+0x3af/0x540
> > vfs_write+0x61d/0xb90
> > ksys_write+0x150/0x270
> >
> > Our reproducer.c is available upon request.
> >
> > Happy to test a patch if that would help.
>
> Please send such a patch.
>
> But again, stop messing around with root-only sysfs files without
> understanding that you get to keep the broken pieces of the kernel if
> you touch them :)
To be honest, all of these "reports" look like you set a fuzzer loose on
the kernel, while running as root, and are surprised that things broke.
You should be more surprised that you actually only got a few crash
traces and that your whole system wasn't randomly corrupted and
permanently destroyed :)
Perhaps you might want to look into the "guardrails" that other more
mature tools like syzbot has in place to not go and do things that are
"obviously wrong" and add that to your llm "harness"?
good luck with the research.
greg k-h