[PATCH] nfc: port100: cancel a stale out URB before sending a command

From: Nguyen Ngoc Thang

Date: Sat Sep 26 2026 - 10:50:02 EST


port100_send_frame_async() reuses dev->out_urb for every command. It
assumes that once the device has ACKed and answered a command, the out
URB of that command has completed. A device can answer without ever
consuming the OUT transfer, leaving the URB queued. The next command
then resubmits an active URB and trips the "URB submitted while active"
warning in usb_submit_urb(), e.g. from port100_probe() when it sends
SET_COMMAND_TYPE right after GET_COMMAND_TYPE.

Kill the out URB before submitting it again, as port100_send_ack()
already does.

Reported-by: syzbot+89f5f8143d8e62af2b61@xxxxxxxxxxxxxxxxxxxxxxxxx
Closes: https://syzkaller.appspot.com/bug?extid=89f5f8143d8e62af2b61
Fixes: 0347a6ab300a ("NFC: port100: Commands mechanism implementation")
Cc: stable@xxxxxxxxxxxxxxx
Signed-off-by: Nguyen Ngoc Thang <ngocthang2710.1999@xxxxxxxxx>
---
drivers/nfc/port100.c | 3 +++
1 file changed, 3 insertions(+)

diff --git a/drivers/nfc/port100.c b/drivers/nfc/port100.c
index b613f5e2fd57..5fad6444fe3a 100644
--- a/drivers/nfc/port100.c
+++ b/drivers/nfc/port100.c
@@ -780,6 +780,9 @@ static int port100_send_frame_async(struct port100 *dev,
print_hex_dump_debug("PORT100 TX: ", DUMP_PREFIX_NONE, 16, 1,
out->data, out->len, false);

+ /* The device may answer without consuming the previous frame. */
+ usb_kill_urb(dev->out_urb);
+
rc = usb_submit_urb(dev->out_urb, GFP_KERNEL);
if (rc)
goto exit;
--
2.43.0