Re: [PATCH 2/2] usb: gadget: raw_gadget: fix memory leak on connect event failure

From: Andrey Konovalov

Date: Wed Sep 30 2026 - 14:40:27 EST


On Sat, Aug 22, 2026 at 6:34 AM hanzhijian <hanzhijian1991@xxxxxxxxx> wrote:
>
> gadget_bind() allocates an ep0 request and stores it in dev->req. If
> raw_queue_event() fails to queue the connect event, the function
> returns without releasing the request, leaking it.
>
> Release the request before returning in that case.
>
> Reported-by: syzbot+d83b3c49738aea97c0e5@xxxxxxxxxxxxxxxxxxxxxxxxx
> Link: https://syzkaller.appspot.com/bug?extid=d83b3c49738aea97c0e5
> Signed-off-by: hanzhijian <hanzhijian1991@xxxxxxxxx>
> ---
> drivers/usb/gadget/legacy/raw_gadget.c | 2 ++
> 1 file changed, 2 insertions(+)
>
> diff --git a/drivers/usb/gadget/legacy/raw_gadget.c b/drivers/usb/gadget/legacy/raw_gadget.c
> index 4febf8dac..33d70b552 100644
> --- a/drivers/usb/gadget/legacy/raw_gadget.c
> +++ b/drivers/usb/gadget/legacy/raw_gadget.c
> @@ -316,6 +316,8 @@ static int gadget_bind(struct usb_gadget *gadget,
> ret = raw_queue_event(dev, USB_RAW_EVENT_CONNECT, 0, NULL);
> if (ret < 0) {
> dev_err(&gadget->dev, "failed to queue connect event\n");
> + usb_ep_free_request(gadget->ep0, dev->req);
> + dev->req = NULL;
> set_gadget_data(gadget, NULL);
> return ret;
> }
> --
> 2.43.0
>

Maybe this is a valid fix (though it's not obvious: dev->req should
get freed in dev_free() even in case of an error here), but it is
unrelated to the referenced syzbot issue (cause by bind-unbind-bind
sequence). LLM?