From: Markus Mikonsaari <hidden> Date: 2026-09-09 08:09:51
In the USB/IP protocol, number_of_packets is set to 0xffffffff (-1)
by sender when the transfer is not isochronous.
usbip_pack_pdu() copies this wire value into urb->number_of_packets
unconditionally.
A host controller driver may compute the iso_frame_desc memory requirements
directly from number_of_packets without independently validating it
against the pipe type which produces an undersized allocation.
On dwc_otg, this manifests as a slab-out-of-bounds write in
dwc_otg_hcd_urb_alloc() during a USB/IP attach involving a non-isochronous
transfer.
Correct the number_of_packets to the value the urb was actually
allocated for immediately after usbip_pack_pdu() overwrites it.
Signed-off-by: Markus Mikonsaari <redacted>
---
drivers/usb/usbip/stub_rx.c | 13 +++++++++++++
1 file changed, 13 insertions(+)
On Wed, Sep 09, 2026 at 08:09:48AM +0000, Markus Mikonsaari wrote:
In the USB/IP protocol, number_of_packets is set to 0xffffffff (-1)
by sender when the transfer is not isochronous.
usbip_pack_pdu() copies this wire value into urb->number_of_packets
unconditionally.
A host controller driver may compute the iso_frame_desc memory requirements
directly from number_of_packets without independently validating it
against the pipe type which produces an undersized allocation.
What driver does that?
On dwc_otg, this manifests as a slab-out-of-bounds write in
dwc_otg_hcd_urb_alloc() during a USB/IP attach involving a non-isochronous
transfer.
Correct the number_of_packets to the value the urb was actually
allocated for immediately after usbip_pack_pdu() overwrites it.
Signed-off-by: Markus Mikonsaari <redacted>
How was this found and tested?
And did you forget an Assisted-by: tag?
From: Markus Mikonsaari <hidden> Date: 2026-09-09 10:38:16
Hi,
What driver does that?
The DWC-OTG USB host controller is a part of the Raspberry Pi
fork of the Linux Kernel: https://github.com/nfeske/dwc_otg
Particularly dwc_otg_hcd_urb_alloc does:
size = sizeof(*dwc_otg_urb) +
iso_desc_count * sizeof(struct dwc_otg_hcd_iso_packet_desc);
where iso_desc_count is urb->number_of_packets.
How was this found and tested?
This issue was found and tested on an industrial box pc based on
the rpi zero2w, the EDC-IPC1100. Every USB/IP attach resulted in a
kernel panic on the device.
And did you forget an Assisted-by: tag?
The fix itself is not generated by an LLM, but I did use it to aid me in
setting up the build and tests and commit message tone.
I will add the tag.
What comment? That's not the best way to do this...
Right, sorry about that. I didn't want to pollute the file with explaining the same thing
twice. I will move the comment and the action into it's own fuction.
Thank you for taking the time to help me by reviewing and commenting!
- Markus
From: Markus Mikonsaari <hidden> Date: 2026-09-09 12:06:28
In the USB/IP protocol, number_of_packets is set to 0xffffffff (-1)
by sender when the transfer is not isochronous.
usbip_pack_pdu() copies this value into urb->number_of_packets.
A host controller driver may compute the iso_frame_desc size directly
from number_of_packets without independently validating it against
the pipe type which produces an undersized allocation.
For example on a Raspberry Pi, the dwc_otg driver panics with a
slab-out-of-bounds write in dwc_otg_hcd_urb_alloc() during a
USB/IP attach involving a non-isochronous transfer.
Correct the number_of_packets to the value the urb was actually
allocated for immediately after usbip_pack_pdu() overwrites it.
Assisted-by: LLM
Signed-off-by: Markus Mikonsaari <redacted>
---
v2:
- Moved fix and comment into a static helper
- Shortened summary
- Added Assisted-by tag
drivers/usb/usbip/stub_rx.c | 16 ++++++++++++++++
1 file changed, 16 insertions(+)