[PATCH 0/3] media: dvb-usb: fix null-ptr-deref in {cxusb,dib0700,dw2102}_disconnect
From: Michael Chapman
Date: Thu Jul 16 2026 - 01:10:18 EST
The following bug was observed when connecting a cxusb device:
usb 1-4: new high-speed USB device number 10 using xhci_hcd
usb 1-4: New USB device found, idVendor=0fe9, idProduct=db10, bcdDevice= 1.00
usb 1-4: New USB device strings: Mfr=0, Product=0, SerialNumber=0
dvb-usb: found a 'DViCO FusionHDTV DVB-T USB (TH7579)' in cold state, will try to load a firmware
dvb-usb: downloading firmware from file 'dvb-usb-bluebird-01.fw'
usbcore: registered new interface driver dvb_usb_cxusb
usb 1-4: USB disconnect, device number 10
BUG: unable to handle page fault for address: 0000000000002c68
#PF: supervisor read access in kernel mode
#PF: error_code(0x0000) - not-present page
PGD 0 P4D 0
Oops: Oops: 0000 [#1] SMP PTI
CPU: 2 UID: 0 PID: 1557026 Comm: kworker/2:0 Tainted: G I 7.0.14-201.fc44.x86_64 #1 PREEMPT(lazy)
Tainted: [I]=FIRMWARE_WORKAROUND
Hardware name: Gigabyte Technology Co., Ltd. To be filled by O.E.M./Z170-HD3-CF, BIOS F6 02/23/2016
Workqueue: usb_hub_wq hub_event
RIP: 0010:cxusb_disconnect+0x19/0x90 [dvb_usb_cxusb]
Code: 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 90 f3 0f 1e fa 0f 1f 44 00 00 55 53 48 89 fb 48 83 ec 08 48 8b bf c8 00 00 00 <48> 8b af 68 2c 00 00 48 81 bf 68 03 00 00 a0 e5 99 c1 74 55 48 8b
RSP: 0018:ffffd1950c1e7b58 EFLAGS: 00010292
RAX: ffffffffc17a9130 RBX: ffff8b7e31300c00 RCX: 0000000000000000
RDX: 0000000000000000 RSI: ffff8b7e31300c00 RDI: 0000000000000000
RBP: ffff8b7d10dc30b0 R08: 00000000fffffff3 R09: ffff8b7f79b13908
R10: 000000000002fe85 R11: ffff8b7d003de810 R12: 0000000000000000
R13: ffffffffc19884d0 R14: 0000000000000090 R15: ffff8b7e31300c50
FS: 0000000000000000(0000) GS:ffff8b80a9d9b000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 0000000000002c68 CR3: 000000005b42e004 CR4: 00000000003726f0
Call Trace:
<TASK>
usb_unbind_interface+0xa2/0x300
? device_remove+0x25/0x60
device_release_driver_internal+0x19e/0x200
bus_remove_device+0xfe/0x200
? device_remove_attrs+0xb3/0x100
device_del+0x179/0x410
usb_disable_device+0xe9/0x2b0
usb_disconnect+0xef/0x320
hub_port_connect+0x7a/0x990
? port_event+0x2a7/0x900
hub_port_connect_change+0x95/0x310
hub_event+0x177/0x570
process_one_work+0x19e/0x3a0
worker_thread+0x1a6/0x310
? __pfx_worker_thread+0x10/0x10
kthread+0xe4/0x120
? __pfx_kthread+0x10/0x10
ret_from_fork+0x1a1/0x270
? __pfx_kthread+0x10/0x10
ret_from_fork_asm+0x1a/0x30
</TASK>
Modules linked in: dvb_usb_cxusb dib0070 dvb_usb xfs overlay joydev uhid rfcomm snd_seq_dummy snd_hrtimer cfg80211 nft_fib_inet nft_fib_ipv4 nft_fib_ipv6 nft_fib nft_reject_inet nf_reject_ipv4 nf_reject_ipv6 nft_reject nft_ct nft_chain_nat nf_nat nf_conntrack nf_defrag_ipv6 nf_defrag_ipv4 nf_tables nfnetlink bnep sunrpc dvb_pll mt352 cx88_dvb cx88_vp3054_i2c dm_crypt videobuf2_dvb dvb_core cx8802 cx8800 intel_rapl_msr intel_rapl_common cx88xx intel_tcc_cooling x86_pkg_temp_thermal intel_powerclamp coretemp binfmt_misc videobuf2_dma_sg tveeprom kvm_intel kvm irqbypass btusb uvcvideo uvc videobuf2_vmalloc videobuf2_memops mei_pxp videobuf2_v4l2 videobuf2_common snd_usb_audio rapl snd_usbmidi_lib snd_hwdep snd_ump snd_rawmidi snd_seq videodev snd_seq_device snd_pcm btmtk btrtl btbcm snd_timer ee1004 btintel ppdev bluetooth mc parport_pc rfkill iTCO_wdt intel_cstate intel_pmc_bxt r8169 mei_hdcp parport mei_me intel_uncore intel_pmc_core pmt_telemetry pmt_discovery pmt_class intel_wmi_thunderbolt
intel_pmc_ssram_telemetry snd intel_vsec soundcore intel_pch_thermal mei realtek i2c_i801 pcspkr i2c_smbus acpi_pad tun uas usb_storage raid1 ghash_clmulni_intel intel_oc_wdt i915 i2c_algo_bit drm_buddy video wmi ttm drm_display_helper cec fuse scsi_dh_alua i2c_dev scsi_dh_rdac scsi_dh_emc
CR2: 0000000000002c68
---[ end trace 0000000000000000 ]---
The device drops off the USB bus after the firmware has been loaded.
cxusb_disconnect assumes the USB interface's private data has been set,
but this is the case only when the device has been initialized in warm
state.
dib0700 and dw2102 appear to have the same bug, so the same fix was
applied to all three drivers.
Michael Chapman (3):
media: dvb-usb: cxusb: fix null-ptr-deref in cxusb_disconnect
media: dvb-usb: dib0700: fix null-ptr-deref in dib0700_disconnect
media: dvb-usb: dw2102: fix null-ptr-deref in dw2102_disconnect
drivers/media/usb/dvb-usb/cxusb.c | 9 ++++++++-
drivers/media/usb/dvb-usb/dib0700_core.c | 9 ++++++++-
drivers/media/usb/dvb-usb/dw2102.c | 9 ++++++++-
3 files changed, 24 insertions(+), 3 deletions(-)
--
2.55.0