From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-pj2-f43.google.com (mail-pj2-f43.google.com [74.125.227.171]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 53B4E33DEE6 for ; Sun, 20 Sep 2026 11:39:57 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=74.125.227.171 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789904400; cv=none; b=Z/a1e+mhDVj0HeRcX9gBw2DS8C4ymmUPctKJZ+fv/saIRMQUVWy8JmkwLe2YMG2GKp6Z+66Gsm1cof4d60Ry2BRgErIoyAR5Hplb+Bwyxm8Vq5DYrwkd0usUoDpmgAXreAu3zk6mqu5qHd6irBpcHo2UJq+FZZ5SQm6O3oxfXwk= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789904400; c=relaxed/simple; bh=yz3jCQ+G9ritM+0QYRVsGG5LlnZv6QqLJOt/G6kBde0=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=X8EDoaHz89LZZmUmV/CKo7/zTt+kg+lHjGvILC+XU+LvpAcjYikMcgd1yEClqxyqjPmNbmhGtrdAiRgcqAuNcNE5lV2NXH0cU8jI0ybxWYRKpnJ3EIcB5hQf1PUCoippGmGC9BVEbIuVBYL9Sd8/JR0gnZc6wXlBw/tArLzFKgA= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=nFhgy91O; arc=none smtp.client-ip=74.125.227.171 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="nFhgy91O" Received: by mail-pj2-f43.google.com with SMTP id 98e67ed59e1d1-396ccb1a98fso1934035a91.1 for ; Sun, 20 Sep 2026 04:39:57 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1789904396; x=1790509196; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to:content-type; bh=Hh2u1s7hlbDfnebkD4E7jjtOwra5qng6se9Ex4k64Kc=; b=nFhgy91OnP9/SJWHGI95BZZ6ednf3ejCWLLciwbtgHCXLLixk40RdR4fPicahDfz5J 9ommOuc04liErkGdgWuYFo7csQc6UXvaJNEk7lFeubnYfaBe2Cc/fW+DKhdDj5QweVDp Pp1raelc6fNPPT2Hgwwg98mxnRkQO2jQ38DxUvLlE8vQRDG5JhQFjNHdyvTmyHrAU2FD UUgMzvTQPmj0r9vUS+ZnID+3PmblMxFgMQRah0LSLTJwqXhVMKkXaflBwvzN0aIFcklg siS9Q4fux8GNeeA+TiefeZkPiGJLx7GEo9p7ZUuvSDprwxYnXn/X3EFsU1wmwXaWT6j2 zsVg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1789904396; x=1790509196; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=Hh2u1s7hlbDfnebkD4E7jjtOwra5qng6se9Ex4k64Kc=; b=WvDaBIkUPtQrbTxP6x2nn8vGNIf6qb8R2xw1DjpnZ1omGMxTDVVH5nbKzEJXSl2yPP SC7y5F8G4q5iHFhM71WyT8vxWfdH7qy+UMG098bhj/Wr3DGt69sx7q+ESRlckEs4R2S8 ofs7iePUWzdOv2DPz8QGr6woMIp3ars3TSrr65vi+zHoNuKy5E8RAaADyONCnT24FrZ/ nWKBzrsuq0MNTy8noLjj5+n1iqYjLioSXQPSRVxs6ve4qmJwYDOoDUVmhKDZW49DH8h5 Vi1HaPkABceh2/vSV6AWI28C8J3RFiYXaTotQwSxgrN9xHXcPQROKVhtusEnO/3Eqsd7 SOtQ== X-Forwarded-Encrypted: i=1; AKwUvBxTYEVppJQr6YAsdALaAX2/wVNT1xrOLhbV1nFCUJp9i8hughreljjPMVyRch5kCKb4RVrfoAPp+rsgEmg=@vger.kernel.org X-Gm-Message-State: AFuF++mdFQkCt+WSkCjmcLV4eVXXB5lmUJMHFYxDcdEZNYXhZJrUCCye dzAfxlytteoUpbgt/Qfgql0lfZnkEFEOxyKYaaSA91ms4/5icyebr662 X-Gm-Gg: AYBFou2WJjTYkItyL8bGkJS/yH17wA2QzEBpeley5hi5GJV+BuHByRvh8pow3SLrOal JHe7Kdmnn0ZjbgBKYTnIv3WEo3rkEYJKILIDDuMpplR8TzqnKUotdwiVCR7EzEBRC9ZmLJ7M1Xd uSrxNwLXXGO+eBzoIYCnQVeUCPTNjPsG24IHExCM85g+Ec84UvGpFNYw3D3BLyy744CtMhgwn36 wZWB2X1N2q2GkQDAQuInpOzYFoZZshl5ydkuC3OxA/T+gnGi1Gacd9RZwHSZ9A4PFrt9OyCe3Mq +mrl9yv1rDcAfJoWj4NEx4N8j2bUjBqyBMTCuzqiNQbOVnnA5t1ypIxGf9MZvOsZkLOFvhd57QU ifPszVTkbod7ymKEaesnkeAAE+D3ThcQIJZVDp1yfTomJMniUGRtR15NhpV3mWox7YGxNnloOiO ShXOmPSK9T04jp2ymCkDfEAugqeSO+6yiHl2cvIpfSY4aGRhV+QhUY1xCh7Glri0COV7o2FXufX D0kG+6Fi8zHdBpdsp3BOsLZdA== X-Received: by 2002:a17:90b:390e:b0:39e:2e7c:d43c with SMTP id 98e67ed59e1d1-39e54b66b6cmr11973998a91.7.1789904396266; Sun, 20 Sep 2026 04:39:56 -0700 (PDT) Received: from thangnn-ASUS.. ([2405:4802:1d4a:e90:2022:c2a9:de8:d005]) by smtp.gmail.com with ESMTPSA id 98e67ed59e1d1-39e6c6dd585sm8490548a91.0.2026.09.20.04.39.53 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sun, 20 Sep 2026 04:39:55 -0700 (PDT) From: Nguyen Ngoc Thang To: dmitry.torokhov@gmail.com Cc: floe@butterbrot.org, linux-input@vger.kernel.org, linux-media@vger.kernel.org, linux-kernel@vger.kernel.org, Nguyen Ngoc Thang Subject: [PATCH v1 0/2] Input: sur40 - fix UAF/hang on closing the video node after unplug Date: Sun, 20 Sep 2026 18:39:47 +0700 Message-ID: <20260920113949.12726-1-ngocthang2710.1999@gmail.com> X-Mailer: git-send-email 2.43.0 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit Hi, syzbot reported a slab-use-after-free in vb2_core_queue_release() [1]: closing /dev/v4l-touch* after the SUR40 was unplugged reads freed memory. Cause: sur40_disconnect() kfree()s struct sur40_state, which embeds the video_device, v4l2_device and vb2_queue, even though a video node can still be open. v4l2_release() and vb2_fop_release() then dereference freed memory. Patch 2 fixes this by giving the v4l2_device a release() callback that frees the state, and dropping the disconnect path's reference with v4l2_device_put(), so the last close does the freeing. The probe error paths never expose the node and still free directly. Patch 1 is needed first: once the state outlives disconnect, closing a node that is still streaming hangs forever, because sur40_stop_streaming() waits (vb2_wait_for_all_buffers) for buffers that only the input poll callback completes, and that is gone after unplug. Returning the queued buffers before the wait fixes it. This was masked by the UAF above. Testing: no hardware, so I emulated a SUR40 (045e:0775) with raw-gadget on dummy_hcd in QEMU with KASAN. The reproducer enumerates the device, starts a non-blocking read() on the video node (making the fd the queue owner), disconnects the gadget, then close()s the fd. - before: KASAN: slab-use-after-free in v4l2_release(), allocated in sur40_probe(), freed in sur40_disconnect() (same alloc/free stacks as the syzbot report) - patch 1 only: no KASAN, but close() blocks in vb2_wait_for_all_buffers() [only meaningful with patch 2 applied] - both patches: 5 consecutive enumerate/disconnect/close cycles, no KASAN, no hang. (The dma_map_sg WARNING during read() in the log comes from dummy_hcd having no DMA mask; it is unrelated.) Nguyen Ngoc Thang (2): Input: sur40 - don't wait for buffers nothing will complete Input: sur40 - keep device state alive until the video node is released drivers/input/touchscreen/sur40.c | 21 +++++++++++++++------ 1 file changed, 15 insertions(+), 6 deletions(-) -- 2.43.0