[BUG] drivers/usb: NULL pointer dereference in stub_recv_cmd_submit()
From: co
Date: Fri Sep 11 2026 - 22:07:31 EST
This is a bug report, not a patch submission. See
https://bugs.sh/reporting.html
We found a bug reachable in:
path drivers/usb/usbip
crash NULL pointer dereference in stub_recv_cmd_submit()
commit 2f1baf1fc892 ("Merge tag 'trace-v7.2-rc7' of git://git.kernel.org/pub/scm/linux/kernel/git/trace/linux-trace")
Config, environment, the sanitizer report and a C reproducer follow.
== Notes ===============================================================
If you fix this bug, this tag credits the report and lets us
close it on our side:
Reported-by: co+66c3f58096d0bde8@xxxxxxx
Everything in this mail is validated by the reproducer below.
We also hold an unreviewed LLM-generated analysis and candidate
patch. The same reproducer panics the unpatched kernel and runs
clean with that patch applied. Use it as a starting point, or ignore
it and write your own:
patch.diff https://bugs.sh/b/66c3f58096d0bde8/patch.diff
report.md https://bugs.sh/b/66c3f58096d0bde8/report.md
A guide to taking it from here to a sendable patch, including the
trailers to add: https://bugs.sh/patch.html
Happy to test patches. Complaints and suggestions about our work
are welcome at:
cedalion@xxxxxxx
== Environment =========================================================
Reproduced on 2f1baf1fc892 ("Merge tag 'trace-v7.2-rc7' of git://git.kernel.org/pub/scm/linux/kernel/git/trace/linux-trace")
VM setup https://bugs.sh/b/66c3f58096d0bde8/run.sh
config https://bugs.sh/b/66c3f58096d0bde8/config.gz
poc https://bugs.sh/b/66c3f58096d0bde8/repro.c
== Sanitizer Report ====================================================
Oops: general protection fault, probably for non-canonical address 0xdffffc0000000000: 0000 [#1] SMP KASAN NOPTI
KASAN: null-ptr-deref in range [0x0000000000000000-0x0000000000000007]
CPU: 0 UID: 0 PID: 83 Comm: kworker/u8:5 Not tainted 7.2.0 #1 PREEMPT(full)
Workqueue: usbip_event event_handler
RIP: 0010:stub_device_cleanup_urbs (drivers/usb/usbip/stub_main.c:356)
Call Trace:
stub_shutdown_connection (drivers/usb/usbip/stub_dev.c:191)
event_handler (drivers/usb/usbip/usbip_event.c:79)
process_one_work (kernel/workqueue.c:3322)
worker_thread (kernel/workqueue.c:3405 kernel/workqueue.c:3486)
kthread (kernel/kthread.c:436)
ret_from_fork (arch/x86/kernel/process.c:158)
ret_from_fork_asm (arch/x86/entry/entry_64.S:245)
Kernel panic - not syncing: Fatal exception
---
The report format is based on syzbot bug report.
This report is generated by a bot. It may contain errors.
See https://github.com/n132/cedalion for more information.
For any issue with this report, reach out to cedalion@xxxxxxx
If the report is already addressed, let us know by replying with:
#co fix: <commit hash>
If the report is a duplicate of another one, reply with:
#co dup: <lore link>
If you want to undo deduplication, reply with:
#co undup