Linux kernel mirror (for testing) git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git
kernel os linux

can: usb_8dev: usb_8dev_read_bulk_callback(): fix URB memory leak

Fix similar memory leak as in commit 7352e1d5932a ("can: gs_usb:
gs_usb_receive_bulk_callback(): fix URB memory leak").

In usb_8dev_open() -> usb_8dev_start(), the URBs for USB-in transfers are
allocated, added to the priv->rx_submitted anchor and submitted. In the
complete callback usb_8dev_read_bulk_callback(), the URBs are processed and
resubmitted. In usb_8dev_close() -> unlink_all_urbs() the URBs are freed by
calling usb_kill_anchored_urbs(&priv->rx_submitted).

However, this does not take into account that the USB framework unanchors
the URB before the complete function is called. This means that once an
in-URB has been completed, it is no longer anchored and is ultimately not
released in usb_kill_anchored_urbs().

Fix the memory leak by anchoring the URB in the
usb_8dev_read_bulk_callback() to the priv->rx_submitted anchor.

Fixes: 0024d8ad1639 ("can: usb_8dev: Add support for USB2CAN interface from 8 devices")
Cc: stable@vger.kernel.org
Link: https://patch.msgid.link/20260116-can_usb-fix-memory-leak-v2-5-4b8cb2915571@pengutronix.de
Signed-off-by: Marc Kleine-Budde <mkl@pengutronix.de>

+7 -1
+7 -1
drivers/net/can/usb/usb_8dev.c
··· 541 541 urb->transfer_buffer, RX_BUFFER_SIZE, 542 542 usb_8dev_read_bulk_callback, priv); 543 543 544 + usb_anchor_urb(urb, &priv->rx_submitted); 545 + 544 546 retval = usb_submit_urb(urb, GFP_ATOMIC); 547 + if (!retval) 548 + return; 549 + 550 + usb_unanchor_urb(urb); 545 551 546 552 if (retval == -ENODEV) 547 553 netif_device_detach(netdev); 548 - else if (retval) 554 + else 549 555 netdev_err(netdev, 550 556 "failed resubmitting read bulk urb: %d\n", retval); 551 557 }