From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mgamail.intel.com (mgamail.intel.com [192.198.163.10]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id B96DD36E48F; Mon, 2 Mar 2026 12:40:24 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=192.198.163.10 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1772455227; cv=none; b=IDz2vG116IJDorQT2UkXs4EdaU0GEguknx2lUnhp84nPYetOCyz1VWROF2ITMG6tOUbSQ5P9s8lxSeYhcOxdeC2DVDERb2aHkECvVPnAM+aguJaXkYnSW/wHVuxTQbXHlKw68zFYCP/ryIqzqNABQHqyjR2A+xjK+UUIcaeccXc= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1772455227; c=relaxed/simple; bh=rpzFy+7EAE2esAzP0RPdL71DMr4OTHuvCae1aeeRJGU=; h=Date:From:To:Cc:Subject:Message-ID:References:MIME-Version: Content-Type:Content-Disposition:In-Reply-To; b=mGaEzuVCt5jSVpwE0eON7ZGS0hagu+rKLq5KPjKUwMT6YQ0qvTpI2t3PxRp5MOKrkpZqIC6+nsQdzjF52OHGviAutrFPK8c8KQI6wP21wgGtFA1tai8/AdXVxH65x6zPf6v9O52shBuXfTV4OyS9Qr6mFJwwT+DIYmNqLa2DxZo= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.intel.com; spf=pass smtp.mailfrom=linux.intel.com; dkim=pass (2048-bit key) header.d=intel.com header.i=@intel.com header.b=S1CSX99g; arc=none smtp.client-ip=192.198.163.10 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=linux.intel.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=linux.intel.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=intel.com header.i=@intel.com header.b="S1CSX99g" DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=intel.com; i=@intel.com; q=dns/txt; s=Intel; t=1772455225; x=1803991225; h=date:from:to:cc:subject:message-id:references: mime-version:in-reply-to; bh=rpzFy+7EAE2esAzP0RPdL71DMr4OTHuvCae1aeeRJGU=; b=S1CSX99gtZTuXrsFJc5pOnECB2B9zTEI9jT/vxt/j1kDxm8M/zU0YgkX SkwHLrvQ23TAv/rV2aRcAqDnOSK2u8zJFyN2Xl/jZIn+byX/S+d0ebZUK fTwZYQx3qZRZoZK4s6+/nmjdcPHPjSwQapsSbEtulfy4libsrjCiUylkf Vsum929bGAy+IR952ituqKhTRJLNyxyrvU6t24uLH68bPu7h2bcj+/Wg3 q4TFxEgrYFeUTxUsNBTRaCqM70rcxq816WZ/tlvganjQQ0w3BE6g4B4kG ACnylJyx+PPdAPycuGbV1Os5d3jeNS5b2jXVYQEcr6/gy4vaE3No7gNt3 Q==; X-CSE-ConnectionGUID: modLsulHTCiLnE1Vygup6A== X-CSE-MsgGUID: ltaMJFHHRJaI/Jap1lhl6Q== X-IronPort-AV: E=McAfee;i="6800,10657,11716"; a="84810250" X-IronPort-AV: E=Sophos;i="6.21,320,1763452800"; d="scan'208";a="84810250" Received: from fmviesa006.fm.intel.com ([10.60.135.146]) by fmvoesa104.fm.intel.com with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 02 Mar 2026 04:40:24 -0800 X-CSE-ConnectionGUID: iBKvTTLERxGUNdL1umrsdw== X-CSE-MsgGUID: hW9uVTOJRbW9QZNkWNrMsQ== X-ExtLoop1: 1 X-IronPort-AV: E=Sophos;i="6.21,320,1763452800"; d="scan'208";a="214861458" Received: from abityuts-desk.ger.corp.intel.com (HELO kekkonen.fi.intel.com) ([10.245.244.89]) by fmviesa006-auth.fm.intel.com with ESMTP/TLS/ECDHE-RSA-AES256-GCM-SHA384; 02 Mar 2026 04:40:22 -0800 Received: from kekkonen.localdomain (localhost [IPv6:::1]) by kekkonen.fi.intel.com (Postfix) with SMTP id 799241212D6; Mon, 02 Mar 2026 14:40:49 +0200 (EET) Date: Mon, 2 Mar 2026 14:40:49 +0200 Organization: Intel Finland Oy - BIC 0357606-4 - c/o Alberga Business Park, 6 krs, Bertel Jungin Aukio 5, 02600 Espoo From: Sakari Ailus To: Ethan Tidmore Cc: Bingbu Cao , Mauro Carvalho Chehab , Tianshu Qiu , Hans Verkuil , linux-media@vger.kernel.org, linux-kernel@vger.kernel.org Subject: Re: [PATCH] media: intel/ipu6: fix error pointer dereference Message-ID: References: <20260217003420.47280-1-ethantidmore06@gmail.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <20260217003420.47280-1-ethantidmore06@gmail.com> Hi Ethan, Thanks for the patch. On Mon, Feb 16, 2026 at 06:34:20PM -0600, Ethan Tidmore wrote: > After confirming that isp->psys is an error pointer goto is called and > imminently goes to this code snippet below: > > out_ipu6_bus_del_devices: > if (isp->psys) { > ipu6_cpd_free_pkg_dir(isp->psys); > ipu6_buttress_unmap_fw_image(isp->psys, &isp->psys->fw_sgt); > } > > Since isp->psys is confirmed to be an error pointer not NULL, the > condition is true and the error pointer is dereferenced. So isp->psys > should be set to NULL before going to out_ipu6_bus_del_devices. > > Fixes: 25fedc021985a ("media: intel/ipu6: add Intel IPU6 PCI device driver") Add: Cc: stable@vger.kernel.org > Signed-off-by: Ethan Tidmore > --- > drivers/media/pci/intel/ipu6/ipu6.c | 1 + > 1 file changed, 1 insertion(+) > > diff --git a/drivers/media/pci/intel/ipu6/ipu6.c b/drivers/media/pci/intel/ipu6/ipu6.c > index 24238f8311a6..6e6b7d2a68ff 100644 > --- a/drivers/media/pci/intel/ipu6/ipu6.c > +++ b/drivers/media/pci/intel/ipu6/ipu6.c > @@ -619,6 +619,7 @@ static int ipu6_pci_probe(struct pci_dev *pdev, const struct pci_device_id *id) > psys_base, &psys_ipdata); > if (IS_ERR(isp->psys)) { > ret = PTR_ERR(isp->psys); > + isp->psys = NULL; There are a number of checks for IS_ERR_OR_NULL() in error handling; instead of setting psys to NULL here I'd add the same test to the condition after out_ipu6_bus_del_devices:. > goto out_ipu6_bus_del_devices; > } > -- Kind regards, Sakari Ailus