[BUG] WARNING: refcount bug in em28xx_uninit_usb_xfer
From: Farhad Alemi
Date: Fri Sep 11 2026 - 16:14:54 EST
Hello,
We are reporting the following crash (reproducer attached):
Linux version 7.3.0-rc2 50d05c7c76c96b90462f24debacca971d2e86713
Build Config: UpstreamAppArmorKASAN (KASAN + UBSAN, panic_on_warn=1)
[ 47.694214][ T9838] refcount_t: underflow; use-after-free.
[ 47.694228][ T9838] WARNING: lib/refcount.c:28 at
refcount_warn_saturate+0xb2/0x110, CPU#1: repro/9838
[ 47.698307][ T9837] em28xx 3-1:1.0: failed to clear USB bulk
endpoint stall/halt condition (error=-32)
[ 47.704251][ T9838] Modules linked in:
[ 47.704265][ T9837] em28xx 3-1:1.0: failed to clear USB bulk
endpoint stall/halt condition (error=-32)
[ 47.706171][ T9838] CPU: 1 UID: 0 PID: 9838 Comm: repro Not tainted
7.3.0-rc2-00099-g50d05c7c76c9 #1 PREEMPT(full)
[ 47.707259][ T9837] em28xx 3-1:1.0: failed to clear USB bulk
endpoint stall/halt condition (error=-32)
[ 47.708241][ T9838] Hardware name: QEMU Standard PC (Q35 + ICH9,
2009), BIOS 1.17.0-debian-1.17.0-1ubuntu1 04/01/2014
[ 47.709292][ T9838] RIP: 0010:refcount_warn_saturate+0xb2/0x110
[ 47.709877][ T9838] Code: 44 00 9b 0b 67 48 0f b9 3a eb 4a e8 a8 75
01 fd 48 8d 3d 41 00 9b 0b 67 48 0f b9 3a eb 37 e8 95 75 01 fd 48 8d
3d 3e 00 9b 0b <67> 48 0f b9 3a eb 24 e8 82 75 01 fd 48 8d 3d 3b 00 9b
0b 67 48 0f
[ 47.711239][ T9837] em28xx 3-1:1.0: failed to clear USB bulk
endpoint stall/halt condition (error=-32)
[ 47.712631][ T9838] RSP: 0018:ffffc90006747878 EFLAGS: 00010293
[ 47.713221][ T9838] RAX: ffffffff84c626eb RBX: 0000000000000003
RCX: ffff88802758a640
[ 47.713978][ T9838] RDX: 0000000000000000 RSI: ffffffff8f347580
RDI: ffffffff90612730
[ 47.714691][ T9838] RBP: 0000000000000002 R08: ffff88802758a640
R09: 0000000000000005
[ 47.715400][ T9838] R10: 0000000000000004 R11: 0000000000000000
R12: ffff888109299e88
[ 47.716228][ T9838] R13: ffff88802933d000 R14: ffff88802933d000
R15: 0000000000000008
[ 47.716848][ T9837] em28xx 3-1:1.0: failed to clear USB bulk
endpoint stall/halt condition (error=-32)
[ 47.717851][ T9838] FS: 00007fdfcd7da6c0(0000)
GS:ffff8881da588000(0000) knlGS:0000000000000000
[ 47.718670][ T9838] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
[ 47.719280][ T9838] CR2: 00007fdfcdfdafe0 CR3: 000000001f3b6000
CR4: 0000000000752ef0
[ 47.721985][ T9838] PKRU: 55555554
[ 47.722334][ T9838] Call Trace:
[ 47.723521][ T9838] <TASK>
[ 47.723823][ T9838] em28xx_uninit_usb_xfer+0x157/0x320
[ 47.725229][ T9838] em28xx_init_usb_xfer+0x454/0x4a0
[ 47.725357][ T9837] em28xx 3-1:1.0: failed to clear USB bulk
endpoint stall/halt condition (error=-32)
[ 47.726698][ T9838] em28xx_start_analog_streaming+0xf19/0x1960
[ 47.727285][ T9838] ? __pfx_em28xx_urb_data_copy+0x10/0x10
[ 47.727840][ T9838] ? __pfx_em28xx_start_analog_streaming+0x10/0x10
[ 47.728457][ T9838] ? __lock_acquire+0x74c/0x2db0
[ 47.728939][ T9838] ? __video_do_ioctl+0x473/0xca0
[ 47.730362][ T9838] ? __pfx___mutex_lock+0x10/0x10
[ 47.730852][ T9838] ? __pfx_em28xx_start_analog_streaming+0x10/0x10
[ 47.731444][ T9838] vb2_start_streaming+0x128/0x460
[ 47.731920][ T9838] vb2_core_streamon+0x2e0/0x4f0
[ 47.732376][ T9838] __video_do_ioctl+0xadb/0xca0
[ 47.732855][ T9838] ? __pfx___video_do_ioctl+0x10/0x10
[ 47.733374][ T9838] video_usercopy+0x876/0x1450
[ 47.733843][ T9838] ? __pfx___video_do_ioctl+0x10/0x10
[ 47.734350][ T9838] ? __pfx_video_usercopy+0x10/0x10
[ 47.734831][ T9838] ? __fget_files+0x2a/0x420
[ 47.735260][ T9838] ? __fget_files+0x2a/0x420
[ 47.735806][ T9838] ? __fget_files+0x3a0/0x420
[ 47.736261][ T9838] v4l2_ioctl+0x18d/0x1e0
[ 47.736682][ T9838] ? __pfx_v4l2_ioctl+0x10/0x10
[ 47.737149][ T9838] __se_sys_ioctl+0xfc/0x170
[ 47.737597][ T9838] do_syscall_64+0x155/0x510
[ 47.738053][ T9838] ? trace_irq_disable+0x3b/0x140
[ 47.738523][ T9838] ? entry_SYSCALL_64_after_hwframe+0x77/0x7f
[ 47.739079][ T9838] ? clear_bhb_loop+0x30/0x80
[ 47.739549][ T9838] entry_SYSCALL_64_after_hwframe+0x77/0x7f
[ 47.740095][ T9838] RIP: 0033:0x42d07d
[ 47.740463][ T9838] Code: 04 25 28 00 00 00 48 89 45 c8 31 c0 48 8d
45 10 c7 45 b0 10 00 00 00 48 89 45 b8 48 8d 45 d0 48 89 45 c0 b8 10
00 00 00 0f 05 <89> c2 3d 00 f0 ff ff 77 1a 48 8b 45 c8 64 48 2b 04 25
28 00 00 00
[ 47.742283][ T9838] RSP: 002b:00007fdfcd7da0c0 EFLAGS: 00000246
ORIG_RAX: 0000000000000010
[ 47.743037][ T9838] RAX: ffffffffffffffda RBX: 00007fdfcd7da6c0
RCX: 000000000042d07d
[ 47.743086][ T9837] em28xx 3-1:1.0: failed to clear USB bulk
endpoint stall/halt condition (error=-32)
[ 47.744673][ T9838] RDX: 00007fdfcd7da13c RSI: 0000000040045612
RDI: 0000000000000005
[ 47.745423][ T9838] RBP: 00007fdfcd7da110 R08: 0000000000000000
R09: 0000000000000001
[ 47.746234][ T9838] R10: 0000000000000008 R11: 0000000000000246
R12: 00007fdfcd7da6c0
[ 47.746982][ T9838] R13: 00007ffc73885280 R14: 00007fdfcd7dace4
R15: 00007ffc73885377
[ 47.747257][ T9837] em28xx 3-1:1.0: failed to clear USB bulk
endpoint stall/halt condition (error=-32)
[ 47.748529][ T9838] </TASK>
[ 47.748851][ T9838] Kernel panic - not syncing: kernel: panic_on_warn set ...
[ 47.749555][ T9838] CPU: 1 UID: 0 PID: 9838 Comm: repro Not tainted
7.3.0-rc2-00099-g50d05c7c76c9 #1 PREEMPT(full)
[ 47.750531][ T9838] Hardware name: QEMU Standard PC (Q35 + ICH9,
2009), BIOS 1.17.0-debian-1.17.0-1ubuntu1 04/01/2014
[ 47.751514][ T9838] Call Trace:
[ 47.751841][ T9838] <TASK>
[ 47.752128][ T9838] vpanic+0x56d/0xa60
[ 47.752518][ T9838] ? __pfx__printk+0x10/0x10
[ 47.752968][ T9838] ? __pfx_vpanic+0x10/0x10
[ 47.753405][ T9838] ? is_bpf_text_address+0x292/0x2b0
[ 47.753927][ T9838] ? is_bpf_text_address+0x26/0x2b0
[ 47.754405][ T9838] panic+0xc5/0xd0
[ 47.754755][ T9838] ? __pfx_panic+0x10/0x10
[ 47.755169][ T9838] __warn+0x315/0x4c0
[ 47.755624][ T9838] ? refcount_warn_saturate+0xb2/0x110
[ 47.756151][ T9838] ? refcount_warn_saturate+0xb2/0x110
[ 47.756693][ T9838] __report_bug+0x273/0x580
[ 47.757147][ T9838] ? refcount_warn_saturate+0xb2/0x110
[ 47.757673][ T9838] ? __pfx___report_bug+0x10/0x10
[ 47.758165][ T9838] report_bug_entry+0x19b/0x290
[ 47.758613][ T9838] ? refcount_warn_saturate+0xb2/0x110
[ 47.759111][ T9838] ? refcount_warn_saturate+0xb7/0x110
[ 47.759621][ T9838] handle_bug+0xce/0x200
[ 47.760049][ T9838] exc_invalid_op+0x1a/0x50
[ 47.760488][ T9838] asm_exc_invalid_op+0x1a/0x20
[ 47.760957][ T9838] RIP: 0010:refcount_warn_saturate+0xb2/0x110
[ 47.761537][ T9838] Code: 44 00 9b 0b 67 48 0f b9 3a eb 4a e8 a8 75
01 fd 48 8d 3d 41 00 9b 0b 67 48 0f b9 3a eb 37 e8 95 75 01 fd 48 8d
3d 3e 00 9b 0b <67> 48 0f b9 3a eb 24 e8 82 75 01 fd 48 8d 3d 3b 00 9b
0b 67 48 0f
[ 47.763279][ T9838] RSP: 0018:ffffc90006747878 EFLAGS: 00010293
[ 47.763830][ T9838] RAX: ffffffff84c626eb RBX: 0000000000000003
RCX: ffff88802758a640
[ 47.764542][ T9838] RDX: 0000000000000000 RSI: ffffffff8f347580
RDI: ffffffff90612730
[ 47.765302][ T9838] RBP: 0000000000000002 R08: ffff88802758a640
R09: 0000000000000005
[ 47.766110][ T9838] R10: 0000000000000004 R11: 0000000000000000
R12: ffff888109299e88
[ 47.766862][ T9838] R13: ffff88802933d000 R14: ffff88802933d000
R15: 0000000000000008
[ 47.767572][ T9838] ? refcount_warn_saturate+0xab/0x110
[ 47.768111][ T9838] ? refcount_warn_saturate+0xab/0x110
[ 47.768636][ T9838] em28xx_uninit_usb_xfer+0x157/0x320
[ 47.769173][ T9838] em28xx_init_usb_xfer+0x454/0x4a0
[ 47.769677][ T9838] em28xx_start_analog_streaming+0xf19/0x1960
[ 47.770248][ T9838] ? __pfx_em28xx_urb_data_copy+0x10/0x10
[ 47.770772][ T9838] ? __pfx_em28xx_start_analog_streaming+0x10/0x10
[ 47.771364][ T9838] ? __lock_acquire+0x74c/0x2db0
[ 47.771820][ T9838] ? __video_do_ioctl+0x473/0xca0
[ 47.772278][ T9838] ? __pfx___mutex_lock+0x10/0x10
[ 47.772760][ T9838] ? __pfx_em28xx_start_analog_streaming+0x10/0x10
[ 47.773384][ T9838] vb2_start_streaming+0x128/0x460
[ 47.773880][ T9838] vb2_core_streamon+0x2e0/0x4f0
[ 47.774347][ T9838] __video_do_ioctl+0xadb/0xca0
[ 47.774797][ T9838] ? __pfx___video_do_ioctl+0x10/0x10
[ 47.775287][ T9838] video_usercopy+0x876/0x1450
[ 47.775822][ T9838] ? __pfx___video_do_ioctl+0x10/0x10
[ 47.776334][ T9838] ? __pfx_video_usercopy+0x10/0x10
[ 47.776838][ T9838] ? __fget_files+0x2a/0x420
[ 47.777284][ T9838] ? __fget_files+0x2a/0x420
[ 47.777731][ T9838] ? __fget_files+0x3a0/0x420
[ 47.778184][ T9838] v4l2_ioctl+0x18d/0x1e0
[ 47.778611][ T9838] ? __pfx_v4l2_ioctl+0x10/0x10
[ 47.779095][ T9838] __se_sys_ioctl+0xfc/0x170
[ 47.779559][ T9838] do_syscall_64+0x155/0x510
[ 47.780009][ T9838] ? trace_irq_disable+0x3b/0x140
[ 47.780495][ T9838] ? entry_SYSCALL_64_after_hwframe+0x77/0x7f
[ 47.781076][ T9838] ? clear_bhb_loop+0x30/0x80
[ 47.781531][ T9838] entry_SYSCALL_64_after_hwframe+0x77/0x7f
[ 47.782101][ T9838] RIP: 0033:0x42d07d
[ 47.782459][ T9838] Code: 04 25 28 00 00 00 48 89 45 c8 31 c0 48 8d
45 10 c7 45 b0 10 00 00 00 48 89 45 b8 48 8d 45 d0 48 89 45 c0 b8 10
00 00 00 0f 05 <89> c2 3d 00 f0 ff ff 77 1a 48 8b 45 c8 64 48 2b 04 25
28 00 00 00
[ 47.784211][ T9838] RSP: 002b:00007fdfcd7da0c0 EFLAGS: 00000246
ORIG_RAX: 0000000000000010
[ 47.785003][ T9838] RAX: ffffffffffffffda RBX: 00007fdfcd7da6c0
RCX: 000000000042d07d
[ 47.785810][ T9838] RDX: 00007fdfcd7da13c RSI: 0000000040045612
RDI: 0000000000000005
[ 47.786553][ T9838] RBP: 00007fdfcd7da110 R08: 0000000000000000
R09: 0000000000000001
[ 47.787283][ T9838] R10: 0000000000000008 R11: 0000000000000246
R12: 00007fdfcd7da6c0
[ 47.787991][ T9838] R13: 00007ffc73885280 R14: 00007fdfcd7dace4
R15: 00007ffc73885377
[ 47.788725][ T9838] </TASK>
[ 47.789338][ T9838] Kernel Offset: disabled
[ 47.789890][ T9838] Rebooting in 86400 seconds..
Regards,
Attachment:
reproducer.c
Description: Binary data