Thread (6 messages) 6 messages, 2 authors, 2026-09-04

KASAN: slab-use-after-free Read in roccat_open

flat view

From: Jeffin Philip <hidden>
Date: 2026-08-27 09:23:16
Also in: linux-usb, lkml
Subsystem: hid core layer, roccat drivers, the rest · Maintainers: Jiri Kosina, Benjamin Tissoires, Stefan Achatz, Linus Torvalds

#syz test: upstream 903c1cf6dff9
diff --git a/drivers/hid/hid-roccat.c b/drivers/hid/hid-roccat.c
index 4f15eb951039..505844890ed3 100644
--- a/drivers/hid/hid-roccat.c
+++ b/drivers/hid/hid-roccat.c
@@ -236,6 +236,7 @@ static int roccat_release(struct inode *inode, struct file *file)
                        hid_hw_close(device->hid);
                } else {
                        roccat_free_device(device);
+                       devices[minor] = NULL;
                }
        }
diff --git a/drivers/hid/hid-roccat.c b/drivers/hid/hid-roccat.c
index 505844890ed3..220666bdd13d 100644
--- a/drivers/hid/hid-roccat.c
+++ b/drivers/hid/hid-roccat.c
@@ -370,8 +370,11 @@ void roccat_disconnect(int minor)
 
        mutex_lock(&devices_lock);
        device = devices[minor];
+       if (!device) {
+               mutex_unlock(&devices_lock);
+               return;
+       }
        mutex_unlock(&devices_lock);
-
        device->exist = 0; /* TODO exist maybe not needed */
 
        device_destroy(device->dev->class, MKDEV(roccat_major, minor));
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help