This is a note to let you know that I've just added the patch titled usb: gadget: eem: fix wrong eem header operation to the 5.12-stable tree which can be found at: http://www.kernel.org/git/?p=linux/kernel/git/stable/stable-queue.git;a=summary The filename of the patch is: usb-gadget-eem-fix-wrong-eem-header-operation.patch and it can be found in the queue-5.12 subdirectory. If you, or anyone else, feels it should not be added to the stable tree, please let <stable@xxxxxxxxxxxxxxx> know about it. >From 305f670846a31a261462577dd0b967c4fa796871 Mon Sep 17 00:00:00 2001 From: Linyu Yuan <linyyuan@xxxxxxxxxxxxxx> Date: Wed, 9 Jun 2021 07:35:47 +0800 Subject: usb: gadget: eem: fix wrong eem header operation From: Linyu Yuan <linyyuan@xxxxxxxxxxxxxx> commit 305f670846a31a261462577dd0b967c4fa796871 upstream. when skb_clone() or skb_copy_expand() fail, it should pull skb with lengh indicated by header, or not it will read network data and check it as header. Cc: <stable@xxxxxxxxxxxxxxx> Signed-off-by: Linyu Yuan <linyyuan@xxxxxxxxxxxxxx> Link: https://lore.kernel.org/r/20210608233547.3767-1-linyyuan@xxxxxxxxxxxxxx Signed-off-by: Greg Kroah-Hartman <gregkh@xxxxxxxxxxxxxxxxxxx> --- drivers/usb/gadget/function/f_eem.c | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) --- a/drivers/usb/gadget/function/f_eem.c +++ b/drivers/usb/gadget/function/f_eem.c @@ -495,7 +495,7 @@ static int eem_unwrap(struct gether *por skb2 = skb_clone(skb, GFP_ATOMIC); if (unlikely(!skb2)) { DBG(cdev, "unable to unframe EEM packet\n"); - continue; + goto next; } skb_trim(skb2, len - ETH_FCS_LEN); @@ -505,7 +505,7 @@ static int eem_unwrap(struct gether *por GFP_ATOMIC); if (unlikely(!skb3)) { dev_kfree_skb_any(skb2); - continue; + goto next; } dev_kfree_skb_any(skb2); skb_queue_tail(list, skb3); Patches currently in stable-queue which might be from linyyuan@xxxxxxxxxxxxxx are queue-5.12/usb-gadget-eem-fix-wrong-eem-header-operation.patch