Re: [PATCH] usb: hcd: Cancel BH giveback works on removal
From: Michal Pecio
Date: Fri Oct 02 2026 - 17:33:10 EST
On Sun, 23 Aug 2026 12:58:31 +0200, Michal Pecio wrote:
> Turns out, we do actually need to flush them, because workers use the
> 'high_prio_bh' and 'low_prio_bh' members of 'usb_hcd' for a brief time
> after all URBs are completed to track pending completions and possibly
> reschedule themselves, see usb_giveback_urb_bh() implementation.
>
> Flushing would suffice if the works don't reschedule themselves, but
> cancel_work_sync() is more robust against stray completions.
>
> Syzbot may have found the issue due to unlucky hard IRQ timing. It can
> be reproduced by adding udelay(3000) in the work function, disabling RH
> autosuspend to maintain the status URB and unbinding a real HC:
>
> [10818.828029] ehci-pci 0000:00:12.0: USB bus 1 deregistered
> [10818.828077] hcd_release freeing high_prio_bh ffff88814a950978
> [10818.829211] usb_giveback_urb_bh still running on bh ffff88814a950978
>
> Reported-by: syzbot+cade843a1e4af0651f5e@xxxxxxxxxxxxxxxxxxxxxxxxx
> Link: https://lore.kernel.org/linux-usb/6a8a5047.dbb3a75c.13dd47.003e.GAE@xxxxxxxxxx/
> Fixes: 94dfd7edfd5c ("USB: HCD: support giveback of URB in tasklet context")
> Cc: stable@xxxxxxxxxxxxxxx
> Signed-off-by: Michal Pecio <michal.pecio@xxxxxxxxx>
> ---
Hi Greg,
Any interest in this fix? If you think it's too theoretical I can
drop the stable tag, but this code just isn't really correct.
Syzbot has found another case: primary HCD of vhci-hcd is freed
if secondary HCD creation fails (e.g. USB bus number limit). This
(again) races with the giveback work still using the primary HCD
after unlinking its root hub URB.
https://lore.kernel.org/linux-usb/6abb3515.c6a7fab7.e5ea7.0459.GAE@xxxxxxxxxx/
> slab-use-after-free in usb_giveback_urb_bh+0x441/0x560 drivers/usb/core/hcd.c:1692
>
> Freed by task 1:
> hcd_release drivers/usb/core/hcd.c:2690 [inline]
> kref_put include/linux/kref.h:65 [inline]
> usb_put_hcd drivers/usb/core/hcd.c:2704 [inline]
> usb_put_hcd+0x149/0x1f0 drivers/usb/core/hcd.c:2701
> vhci_hcd_probe+0x342/0x4e0 drivers/usb/usbip/vhci_hcd.c:1415
>
> Last potentially related work creation:
> queue_work include/linux/workqueue.h:700 [inline]
> usb_hcd_giveback_urb+0x330/0x4a0 drivers/usb/core/hcd.c:1758
> usb_rh_urb_dequeue drivers/usb/core/hcd.c:845 [inline]
> unlink1+0x418/0x510 drivers/usb/core/hcd.c:1580
Regards,
Michal