From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-pj1-f53.google.com (mail-pj1-f53.google.com [209.85.216.53]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 850DE386426 for ; Thu, 30 Jul 2026 10:38:02 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.216.53 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785407885; cv=none; b=mD9x2o0W8BczoLSHUGdCNEkvlFQtCkv/iMkeZBh6b+w9hjxXtHd4cxRhookRh8iglJQk4N9EJQfWonkPfGeubtZUKEXhKuKTjSrZANMwf/MnJQ6AGqfpkkzftnH+NnlnYvTkCZLysDz4Ce8ZUSzsAv4t6fpvmqY2aZ6z0cA/NKM= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785407885; c=relaxed/simple; bh=C+XIta/PnXbHgq5uX591/FuJJN/cSTbjopEz3wI5Rjw=; h=From:To:Cc:Subject:Date:Message-Id:MIME-Version; b=QNdMIN+Mp4sQTguG0aalFSOdAs+oaYkAOY89W97GLssSw45HYy0idJuPq2cmKk+VYcnFU3irMhmFlmG4o4mVjdkfMlvQ6lV25FebtFQepZ+OgR9WReYwredAaqg/FUCeLRKRqSSb1Mg2oaRQAZAbk1UOGAd7CA9UHswHH+zBuzk= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=GuEej2uf; arc=none smtp.client-ip=209.85.216.53 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="GuEej2uf" Received: by mail-pj1-f53.google.com with SMTP id 98e67ed59e1d1-38e3617ba36so2172451a91.3 for ; Thu, 30 Jul 2026 03:38:02 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1785407882; x=1786012682; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to:content-type; bh=MXK6Swv7vBgoQF3j9El0Te9ljuWn43Xnd3oqzZNewrA=; b=GuEej2ufTOCr3VT7I36z7Xw/1SlQmdYnq/zESN/IwicZwZQr78m9ebX9anFPsliB9u FXJxdbhhqW6w45mlIvDnA4aXcFkvdgVHfoCM7W0L1aFRa4n28UrHVzCvOf5Vjb7SEelI OYolHF7JMfEye9mnUOSlNbqVBng5Z65va2hHTE3pgRAYcQzG9BD5MfXLKjvhqtH7dEO1 uuojPDmku2ItmkR8HMOi9oQARL21t4RPvHJ8IoBOSKADgGswyS50+1AbHomjLCuClHRB Q4MMAx2IPCfctahgHrUw+dSGQytNDwrD2BopNKQtPqrtpvXrPurKRzi4/BEpOetI47// jhYg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785407882; x=1786012682; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=MXK6Swv7vBgoQF3j9El0Te9ljuWn43Xnd3oqzZNewrA=; b=RbwqKbn0+1j6EWAKUHKeliE2IrmdKLbXBrG8F5ZhWspMc+6iQXz/lG42ceOumUdUPv zgl4mkKNDXfHyGr5KWxE4ltTOP48wy2hGXFJJD87gQFWH2oMeMV8IwwQ/cSl3/spbQ6k ZQF0U5w2nuK0l68QAJbnsjYZ1IKCaNnGdB3eZQuxkEi09uaS7DWlu44dxMBei3iCAPmv Bxh8c9n4ITcFMAxpK9AWcdIE8etFLBLYlfO4FyhBoEZGV884+r4v8+S8S/bP61pCa0m+ 6+IU9jicKJuumD09lDjtuDAkxs37D+hDXaFnnbKTrWI4zezjwkTVlhow2d32/07crobu eahA== X-Forwarded-Encrypted: i=1; AHgh+RrsCJ+4f9EeHMJ+3NbqX3PMCllPihgw6MQAz1nowu7cad9LlbcNOya/vwaqqsPHm14NFRp8uzr9TBC7kvU=@vger.kernel.org X-Gm-Message-State: AOJu0Yyl9XXMb5k5dGwbqq12jrTQPb2yQ+EmgFjCBXkvHNDDbEMrPYW4 kRY8GBVtf3JdpV5fnS9b1zbulYCpwIP5X+33/UKCjXYGvYKAHFMtWd0t X-Gm-Gg: AR+sD10rxHOy6hvjDVvzp4PKSMcpsvJjm+cs/LoV4ynn4lAjcIFbdBaQR9oGLgOvR79 D5944zAIc55pxa4J/Nja/jmvYY0RGyOgRupzpnkQEGNdagtoGD1i0nZMkXe5sCT/nZ5pVz1fXM0 9EnB+XzwTRqoSRVwggMrHtNl96Rpf/AKdocsjRtqhFmuJTyi3uJkZMFMF6Cy4ZoLYbrgaIOwlBB f/VGisWOnzWh6DjZ3dApvQKsGtHc1huGqNDjpQZw/4RQwunUv0JNdXhr3QhW23jUR77d2JMwjia b8idyIrL1l4YmxG9AekmNzdm+wfhlHPPVEF7DjtKuBOman1DmEZYp+hceivKWWJNe//K2xKETj1 SutkYZFZLkNu00/jT+uUpxOCUNgfKCuommDiKf5Hf/p4NJ80BGyax9vVNX1n90Mj65cqf2yPBOi wzSEoW8OrK796+OPCk2cEhlqUOY7LoNejmaHREDIr/qip8aGwqQFnokhpt3IpX+EzcATOkSvFmt dMQYKRgY6CNZeGl X-Received: by 2002:a17:90b:6c4:b0:380:a568:cc4e with SMTP id 98e67ed59e1d1-38f9bd632b4mr1766643a91.9.1785407881826; Thu, 30 Jul 2026 03:38:01 -0700 (PDT) Received: from SGN-LDSENG.tasernet.com ([2405:4800:5cc3:11a:1ac0:4dff:fe8b:4a69]) by smtp.gmail.com with ESMTPSA id 98e67ed59e1d1-38f9b42d176sm837532a91.4.2026.07.30.03.37.58 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Thu, 30 Jul 2026 03:38:01 -0700 (PDT) From: Cong Nguyen To: Sakari Ailus , Bingbu Cao Cc: Greg Kroah-Hartman , Mauro Carvalho Chehab , Hans Verkuil , linux-media@vger.kernel.org, linux-staging@lists.linux.dev, linux-kernel@vger.kernel.org Subject: [PATCH] media: staging/ipu7: fix async notifier UAF on probe error path Date: Thu, 30 Jul 2026 17:37:54 +0700 Message-Id: <20260730103754.1480367-1-congnt264@gmail.com> X-Mailer: git-send-email 2.25.1 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit isys_register_devices() registers the V4L2 async notifier via isys_notifier_init(). If a subsequent probe step such as isys_fw_log_init() fails, isys_probe() jumps to the out_cleanup label which only calls isys_unregister_devices(). That helper tears down the video devices, subdevices, V4L2 device and media device, but never unregisters or cleans up the async notifier. As a result the notifier stays chained in the global notifier_list while the enclosing struct ipu7_isys is freed by devres, leading to list corruption and a use-after-free the next time the list is walked. The remove path already does the right thing by calling isys_notifier_cleanup() before isys_unregister_devices(). Mirror that on the probe error path so the notifier is unregistered and cleaned up before the device is torn down. Fixes: a516d36bdc3d ("media: staging/ipu7: add IPU7 input system device driver") Cc: stable@vger.kernel.org Signed-off-by: Cong Nguyen --- drivers/staging/media/ipu7/ipu7-isys.c | 1 + 1 file changed, 1 insertion(+) diff --git a/drivers/staging/media/ipu7/ipu7-isys.c b/drivers/staging/media/ipu7/ipu7-isys.c index cb2f49f3e0fa..bf262c01a2b8 100644 --- a/drivers/staging/media/ipu7/ipu7-isys.c +++ b/drivers/staging/media/ipu7/ipu7-isys.c @@ -773,6 +773,7 @@ static int isys_probe(struct auxiliary_device *auxdev, return 0; out_cleanup: + isys_notifier_cleanup(isys); isys_unregister_devices(isys); out_cleanup_fw: ipu7_fw_isys_release(isys); -- 2.25.1