Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 562868 - dev-libs/libusb-1.0.19: Segfault on usb disconnect, reconnect
Summary: dev-libs/libusb-1.0.19: Segfault on usb disconnect, reconnect
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Linux
Classification: Unclassified
Component: [OLD] Library (show other bugs)
Hardware: AMD64 Linux
: Normal normal with 1 vote (vote)
Assignee: Gentoo's Team for Core System packages
URL:
Whiteboard:
Keywords: PATCH
Depends on:
Blocks:
 
Reported: 2015-10-12 02:10 UTC by Matthew Stapleton
Modified: 2022-06-17 02:31 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments
libusb-1.0.20_fix_null_ref_on_usb_reconnect.patch (libusb-1.0.20_fix_null_ref_on_usb_reconnect.patch,750 bytes, patch)
2015-10-12 04:57 UTC, Matthew Stapleton
Details | Diff

Note You need to log in before you can comment on or make changes to this bug.
Description Matthew Stapleton 2015-10-12 02:10:45 UTC
When I unplug and replug a usb cable of a ups, nut triggers the following bug in libusb (identified with valgrind):
==2383== Process terminating with default action of signal 11 (SIGSEGV)
==2383==  Access not within mapped region at address 0x0
==2383==    at 0x4C2F341: strcmp (in /usr/lib64/valgrind/vgpreload_memcheck-amd64-linux.so)
==2383==    by 0x561800B: linux_enumerate_device (linux_usbfs.c:1037)
==2383==    by 0x5618CB8: linux_hotplug_enumerate (linux_usbfs.c:1113)
==2383==    by 0x561A192: linux_netlink_read_message (linux_netlink.c:322)
==2383==    by 0x561A724: linux_netlink_hotplug_poll (linux_netlink.c:366)
==2383==    by 0x560D168: libusb_get_device_list (core.c:807)
==2383==    by 0x4E383DF: usb_find_busses (in /lib64/libusb-0.1.so.4.4.4)
==2383==    by 0x120D55: libusb_open (libusb.c:164)
==2383==    by 0x11EE09: upsdrv_updateinfo (usbhid-ups.c:1355)
==2383==    by 0x11D016: main (main.c:708)

Current kernel is 4.1.6-hardened, but it has been happening for a while, I just haven't been able to get the valgrind output until now.

Reproducible: Always

Steps to Reproduce:
1. Start usb ups driver
2. Disconnect the usb cable
3. Reconnect the usb cable



Portage 2.2.7 (hardened/linux/amd64, gcc-4.8.4, unavailable, 4.1.6-hardened x86_64)
=================================================================
System uname: Linux-4.1.6-hardened-x86_64-Intel-R-_Core-TM-_i7-3820_CPU_@_3.60GHz-with-gentoo-2.1
KiB Mem:    65915456 total,    467432 free
KiB Swap:  134213628 total, 132726332 free
Timestamp of tree: Thu, 08 Oct 2015 13:45:01 +0000
ld GNU ld (Gentoo 2.24 p1.4) 2.24
app-shells/bash:          4.2_p53
dev-java/java-config:     1.3.7, 2.1.12-r1
dev-lang/perl:            5.12.2-r6
dev-lang/python:          2.4.4-r14, 2.5.4-r2, 2.6.8, 2.7.5-r3, 3.2.3-r2, 3.3.3
dev-util/cmake:           2.8.10.2-r2
dev-util/pkgconfig:       0.28-r2
sys-apps/baselayout:      2.1-r1
sys-apps/openrc:          0.11.8
sys-apps/sandbox:         2.6-r1
sys-devel/autoconf:       2.13::<unknown repository>, 2.69
sys-devel/automake:       1.4_p6::<unknown repository>, 1.5::<unknown repository>, 1.6.3::<unknown repository>, 1.7.9-r1::<unknown repository>, 1.8.5-r3::<unknown repository>, 1.9.6-r2::<unknown repository>, 1.10.1, 1.11.1, 1.12.6, 1.13.4, 1.14.1, 1.15
sys-devel/binutils:       2.24-r3
sys-devel/gcc:            3.4.6-r2::<unknown repository>, 4.1.2::<unknown repository>, 4.3.6-r1, 4.5.3-r2, 4.6.3, 4.8.4
sys-devel/gcc-config:     1.7.3
sys-devel/libtool:        2.4.6
sys-devel/make:           3.82-r3
sys-kernel/linux-headers: 3.13 (virtual/os-headers)
sys-libs/glibc:           2.20-r2
Repositories: gentoo x-portage
ACCEPT_KEYWORDS="amd64"
ACCEPT_LICENSE="* -@EULA"
CBUILD="x86_64-pc-linux-gnu"
CFLAGS="-O2 -mtune=amdfam10 -fomit-frame-pointer -ftree-vectorize -fpredictive-commoning -fno-tree-vect-loop-version"
CHOST="x86_64-pc-linux-gnu"
CONFIG_PROTECT="/etc /usr/kde/3.5/env /usr/kde/3.5/share/config /usr/kde/3.5/shutdown /usr/share/config /usr/share/gnupg/qualified.txt /usr/share/openvpn/easy-rsa /var/bind"
CONFIG_PROTECT_MASK="/etc/ca-certificates.conf /etc/env.d /etc/fonts/fonts.conf /etc/gconf /etc/gentoo-release /etc/php/apache2-php5/ext-active/ /etc/php/cgi-php5/ext-active/ /etc/php/cli-php5/ext-active/ /etc/revdep-rebuild /etc/sandbox.d /etc/terminfo"
CXXFLAGS="-O2 -mtune=amdfam10 -fomit-frame-pointer -ftree-vectorize -fpredictive-commoning -fno-tree-vect-loop-version"
DISTDIR="/usr/portage/distfiles"
FCFLAGS="-O2 -pipe"
FEATURES="assume-digests binpkg-logs distlocks ebuild-locks fixlafiles merge-sync news parallel-fetch preserve-libs protect-owned sandbox sfperms strict unknown-features-warn unmerge-logs unmerge-orphans userfetch userpriv usersandbox usersync xattr"
FFLAGS="-O2 -pipe"
GENTOO_MIRRORS="http://mirror.internode.on.net/pub/gentoo http://mirror.pacific.net.au/linux/Gentoo http://distfiles.gentoo.org http://www..ibiblio.org/pub/Linux/distributions/gentoo"
LANG="en_AU.utf8"
LDFLAGS="-Wl,-O1 -Wl,--as-needed"
MAKEOPTS="-j1"
PKGDIR="/usr/portage/packages"
PORTAGE_CONFIGROOT="/"
PORTAGE_RSYNC_OPTS="--recursive --links --safe-links --perms --times --omit-dir-times --compress --force --whole-file --delete --stats --human-readable --timeout=180 --exclude=/distfiles --exclude=/local --exclude=/packages"
PORTAGE_TMPDIR="/var/tmp"
PORTDIR="/usr/portage"
PORTDIR_OVERLAY="/usr/local/portage"
SYNC="rsync://rsync/gentoo-portage"
USE="acl acpi alsa amd64 apache2 berkdb bzip2 caps cjk cli cracklib crypt cups cxx dlloader dri fam gdbm hardened iconv ipv6 jpeg justify kdeenablefinal kdehiddenvisibility kerberos logrotate mmx mmxext mng modules multilib ncurses nls nptl openmp pam pax_kernel pcre pie png qt readline seccomp session sse sse2 ssl ssp tcpd threads tiff unicode urandom vhosts xattr xcb xinerama xtpax zlib" ABI_X86="64" ALSA_CARDS="ali5451 als4000 atiixp atiixp-modem bt87x ca0106 cmipci emu10k1x ens1370 ens1371 es1938 es1968 fm801 hda-intel intel8x0 intel8x0m maestro3 trident usb-audio via82xx via82xx-modem ymfpci" APACHE2_MODULES="actions alias auth_basic auth_digest authn_anon authn_dbd authn_dbm authn_default authn_file authz_dbm authz_default authz_groupfile authz_host authz_owner authz_user autoindex cache dav dav_fs dav_lock dbd deflate dir disk_cache env expires ext_filter file_cache filter headers ident imagemap include info log_config logio mem_cache mime mime_magic negotiation proxy proxy_ajp proxy_balancer proxy_connect proxy_http rewrite setenvif so speling status unique_id userdir usertrack vhost_alias cgid" CALLIGRA_FEATURES="kexi words flow plan sheets stage tables krita karbon braindump author" CAMERAS="ptp2" COLLECTD_PLUGINS="df interface irq load memory rrdtool swap syslog" CPU_FLAGS_X86="mmx mmxext sse sse2" ELIBC="glibc" GPSD_PROTOCOLS="ashtech aivdm earthmate evermore fv18 garmin garmintxt gpsclock itrax mtk3301 nmea ntrip navcom oceanserver oldstyle oncore rtcm104v2 rtcm104v3 sirf superstar2 timing tsip tripmate tnt ublox ubx" INPUT_DEVICES="evdev keyboard mouse" KERNEL="linux" LCD_DEVICES="bayrad cfontz cfontz633 glk hd44780 lb216 lcdm001 mtxorb ncurses text" LIBREOFFICE_EXTENSIONS="presenter-console presenter-minimizer" LINGUAS="en en_GB en_US en_AU" OFFICE_IMPLEMENTATION="libreoffice" PYTHON_SINGLE_TARGET="python2_7" PYTHON_TARGETS="python2_7 python3_4" QEMU_SOFTMMU_TARGETS="i386 x86_64" QEMU_USER_TARGETS="i386 x86_64" RUBY_TARGETS="ruby20 ruby21" USERLAND="GNU" VIDEO_CARDS="fbdev vesa" XTABLES_ADDONS="quota2 psd pknock lscan length2 ipv4options ipset ipp2p iface geoip fuzzy condition tee tarpit sysrq steal rawnat logmark ipmark dhcpmac delude chaos account"
Unset:  CC, CPPFLAGS, CTARGET, CXX, EMERGE_DEFAULT_OPTS, INSTALL_MASK, LC_ALL, PORTAGE_BUNZIP2_COMMAND, PORTAGE_COMPRESS, PORTAGE_COMPRESS_FLAGS, PORTAGE_RSYNC_EXTRA_OPTS, USE_PYTHON
Comment 1 Matthew Stapleton 2015-10-12 04:01:58 UTC
Oh that valgrind output is for libusb-1.0.20.  The following is the output for libusb-1.0.19 but appears to refer to the same code contents:
==1595==    at 0x4C2F341: strcmp (in /usr/lib64/valgrind/vgpreload_memcheck-amd64-linux.so)
==1595==    by 0x5617863: linux_enumerate_device (linux_usbfs.c:1027)
==1595==    by 0x5618518: linux_hotplug_enumerate (linux_usbfs.c:1103)
==1595==    by 0x56199D2: linux_netlink_read_message (linux_netlink.c:322)
==1595==    by 0x5619F64: linux_netlink_hotplug_poll (linux_netlink.c:366)
==1595==    by 0x560D148: libusb_get_device_list (core.c:669)
==1595==    by 0x4E383DF: usb_find_busses (in /lib64/libusb-0.1.so.4.4.4)
==1595==    by 0x120D55: libusb_open (libusb.c:164)
==1595==    by 0x11EE09: upsdrv_updateinfo (usbhid-ups.c:1355)
==1595==    by 0x11D016: main (main.c:708)
Comment 2 Matthew Stapleton 2015-10-12 04:57:36 UTC
Created attachment 414404 [details, diff]
libusb-1.0.20_fix_null_ref_on_usb_reconnect.patch

Here is quick patch that seems to resolve the issue by checking if priv->sysfs_dir is null in the linux_get_parent_info function before calling strcmp.  The patch will also apply with libusb-1.0.19.

Will I need to post the patch to the libusb developers as well or is a gentoo libusb developer able to do this?
Comment 3 Matthew Stapleton 2016-01-13 00:50:47 UTC
It looks like this bug only occurs with grsecurity based kernels.  https://github.com/libusb/libusb/pull/129 is the pull request I've made for libusb with associated debugging comments.
Comment 4 Sam James archtester Gentoo Infrastructure gentoo-dev Security 2022-06-17 02:31:47 UTC
(In reply to Matthew Stapleton from comment #3)
> It looks like this bug only occurs with grsecurity based kernels. 
> https://github.com/libusb/libusb/pull/129 is the pull request I've made for
> libusb with associated debugging comments.

Merged a while ago. Thanks!