mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: Nicola Fiorillo <nicfio@gmail.com>
To: Laurent Pinchart <laurent.pinchart@ideasonboard.com>
Cc: Sakari Ailus <sakari.ailus@linux.intel.com>,
	mchehab@kernel.org, hverkuil@kernel.org,
	ngocthang2710.1999@gmail.com, linux-media@vger.kernel.org,
	linux-kernel@vger.kernel.org, nicfio@gmail.com
Subject: Re: [PATCH v3 1/2] media: v4l2-subdev: Fix NULL pointer dereference in subdev_open()
Date: Thu, 08 Oct 2026 09:06:01 +0200	[thread overview]
Message-ID: <179144316198.13032.1846729931094664641@gmail.com> (raw)
In-Reply-To: <20261008054842.GB683793@killaraus.ideasonboard.com>

Hi Laurent,

Thank you for looking at it.

On 6.12.86: agreed, that line does not belong in the commit message.
The runs that matter are the ones on media next described in the cover
letter, and those are what the commit message should have referred to.

On the fix: agreed as well, it does not fix the problem. subdev_open()
now goes through vdev->v4l2_dev->mdev, which is only valid as long as
the driver keeps the v4l2_device and the media_device alive. vimc does,
through its v4l2_device release callback, but ipu6-isys embeds both in
struct ipu6_isys, allocated with devm_kzalloc(), so they are freed when
the driver is unbound.

I checked this on the IPU6 tablet (media next 9cfc1aca0781 plus the
sensor drivers mentioned in the cover letter, without this series):
with the media device, a video node and a CSI-2 sub-device node of
isys held open, I unbound isys, then issued one ioctl on each node and
closed them. KASAN reports use-after-free in v4l2_ioctl() on the video
node, then on close in v4l2_release(), v4l2_prio_close() and
v4l2_device_release() on the struct ipu6_isys allocated in
isys_probe() and freed by devres at unbind, and more in subdev_close()
and __vb2_queue_free().

Patch 2/2 rests on the same vdev->v4l2_dev assumption, so I am
withdrawing the whole series rather than keeping half of it. The
underlying issue is the lifetime of the objects in the driver, and
that needs a proper fix along the lines of what Hans did for em28xx,
not another check in the file operations.

Thanks,
Nicola

  reply	other threads:[~2026-10-08  7:06 UTC|newest]

Thread overview: 9+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-10-08  4:25 [PATCH v3 0/2] media: v4l2-subdev: Fix NULL dereferences racing with unbind Nicola Fiorillo
2026-10-08  4:25 ` [PATCH v3 1/2] media: v4l2-subdev: Fix NULL pointer dereference in subdev_open() Nicola Fiorillo
2026-10-08  5:48   ` Laurent Pinchart
2026-10-08  7:06     ` Nicola Fiorillo [this message]
2026-10-09  9:48       ` Laurent Pinchart
2026-10-09 10:37         ` Nicola Fiorillo
2026-10-08  4:26 ` [PATCH v3 2/2] media: v4l2-subdev: Fix NULL pointer dereference in the EXT_CTRLS ioctls Nicola Fiorillo
2026-10-08 10:44   ` Sakari Ailus
2026-10-08 13:55     ` Nicola Fiorillo

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=179144316198.13032.1846729931094664641@gmail.com \
    --to=nicfio@gmail.com \
    --cc=hverkuil@kernel.org \
    --cc=laurent.pinchart@ideasonboard.com \
    --cc=linux-kernel@vger.kernel.org \
    --cc=linux-media@vger.kernel.org \
    --cc=mchehab@kernel.org \
    --cc=ngocthang2710.1999@gmail.com \
    --cc=sakari.ailus@linux.intel.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®