Re: [PATCH v3] usbip: vudc: Prevent transfer timer rearm during teardown
From: Greg KH
Date: Fri Sep 25 2026 - 01:30:32 EST
On Thu, Sep 24, 2026 at 09:51:44PM +0000, mhun512@xxxxxxxxx wrote:
> Commit d96209626a29 ("usbip: vudc: Fix use after free bug in
> vudc_remove due to race condition") deletes the timer before
> usb_del_gadget_udc() stops the receive thread. v_kick_timer() can rearm
> it even in VUDC_TR_STOPPED, leaving v_timer() to use freed vudc.
>
> Use timer_shutdown_sync() to reject later rearms. Replace the
> inaccurate blanket lock comment with __must_hold(&udc->lock) on
> v_start_timer() and v_kick_timer(); v_init_timer() and v_stop_timer() run
> unlocked.
That is two different things you are doing here, so this should be a
patch series of 2 patches, right?
thanks,
greg k-h