Linux kernel mirror (for testing) git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git
kernel os linux

usb: phy: Initialize struct usb_phy list_head

As part of the registration of a new 'struct usb_phy' with the USB PHY core
via either usb_add_phy(struct usb_phy *x, ...) or usb_add_phy_dev(struct
usb_phy *x) these functions call list_add_tail(&x->head, phy_list) in
order for the new instance x to be stored in phy_list, a static list
kept internally by the core.

After 7d21114dc6a2 ("usb: phy: Introduce one extcon device into usb phy")
when executing either of the registration functions above it is possible
that usb_add_extcon() fails, leading to either function returning before
the call to list_add_tail(), leaving x->head uninitialized.

Then, when a driver tries to undo the failed registration by calling
usb_remove_phy(struct usb_phy *x) there will be an unconditional call to
list_del(&x->head) acting on an uninitialized variable, and thus a
possible NULL pointer dereference.

Fix this by initializing x->head before usb_add_extcon() has a
chance to fail. Note that this was not needed before 7d21114dc6a2 since
list_add_phy() was executed unconditionally and it guaranteed that x->head
was initialized.

Fixes: 7d21114dc6a2 ("usb: phy: Introduce one extcon device into usb phy")
Cc: stable <stable@kernel.org>
Signed-off-by: Diogo Ivo <diogo.ivo@tecnico.ulisboa.pt>
Link: https://patch.msgid.link/20251121-diogo-smaug_typec-v2-1-5c37c1169d57@tecnico.ulisboa.pt
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>

authored by

Diogo Ivo and committed by
Greg Kroah-Hartman
c69ff68b c77a6544

+4
+4
drivers/usb/phy/phy.c
··· 646 646 return -EINVAL; 647 647 } 648 648 649 + INIT_LIST_HEAD(&x->head); 650 + 649 651 usb_charger_init(x); 650 652 ret = usb_add_extcon(x); 651 653 if (ret) ··· 697 695 dev_err(x->dev, "no device provided for PHY\n"); 698 696 return -EINVAL; 699 697 } 698 + 699 + INIT_LIST_HEAD(&x->head); 700 700 701 701 usb_charger_init(x); 702 702 ret = usb_add_extcon(x);