From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mx0b-0031df01.pphosted.com (mx0b-0031df01.pphosted.com [205.220.180.131]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 4BC983803C5 for ; Tue, 3 Mar 2026 04:12:06 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=205.220.180.131 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1772511128; cv=none; b=WVenvbgm0nMuuAph7A6eCmxo6tzUGOwwdxty2AAH2f0K78moRVLVWo2m6kkYGcd5xG/wTklJRgaM3JAy8JzN+JiDwfIp2qTkNqujruECFPNlc3YNBsRYrDQWOA66pUogDUxcPbnc4AearO25DT5mYLsv16LaYWeS6pQpq6mt4cM= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1772511128; c=relaxed/simple; bh=jv0Ppc9b/nRH4DuyNAk1Qw5DVsy1zDiysYv6TXbYVNM=; h=Message-ID:Date:MIME-Version:Subject:To:Cc:References:From: In-Reply-To:Content-Type; b=YYygcI6fYqr4J8aWJDBmaBx0X2MvZCrlXeJfVM9cicF1Kej8u/j2zQwptN8IdlzeA4WcvtKV1zyLZOvsIhEty26/59BsL/TRQc2Fbik7WwjskkxtXzmMUR2smmo6OT58Hsn5M/c4m+/y3aKZE3MDeo0IT0EErV32U9uEAZWug90= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=oss.qualcomm.com; spf=pass smtp.mailfrom=oss.qualcomm.com; dkim=pass (2048-bit key) header.d=qualcomm.com header.i=@qualcomm.com header.b=Eq3Bxdgj; dkim=pass (2048-bit key) header.d=oss.qualcomm.com header.i=@oss.qualcomm.com header.b=Jbb8a0YW; arc=none smtp.client-ip=205.220.180.131 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=oss.qualcomm.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=oss.qualcomm.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=qualcomm.com header.i=@qualcomm.com header.b="Eq3Bxdgj"; dkim=pass (2048-bit key) header.d=oss.qualcomm.com header.i=@oss.qualcomm.com header.b="Jbb8a0YW" Received: from pps.filterd (m0279869.ppops.net [127.0.0.1]) by mx0a-0031df01.pphosted.com (8.18.1.11/8.18.1.11) with ESMTP id 622NAvne2048888 for ; Tue, 3 Mar 2026 04:11:58 GMT DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=qualcomm.com; h= cc:content-transfer-encoding:content-type:date:from:in-reply-to :message-id:mime-version:references:subject:to; s=qcppdkim1; bh= aAXuw4WiHJ4I5hsmz1YeLDT4X8hqfp4XZsCr46xei6E=; b=Eq3Bxdgjm/2AVxW4 6yjXslPCJfagL15iGxk5eU6CCDkj4/USrhxGSC4flZLcwIlutiEPMzxWUvVyHdeA Pp7nfE+GdtpbfE/kj6bHZr4e4JFUl5gsQSKAs0yjbqGOiXgE19UA7p2PRfjMvocv Mmau26Uhi/SNt2UJzlgdtAumsc/CMIBM4y2uh5L6o6b41173WrLXutdPzfOyp02s nbucA5QDe6tBpMyWvMOJ1ViEbpA9rHDZDuFWwauw4UDWYU/gJaWujwi3lCT3GKwy Wc5hwyMOxFc0RGjPmQVwcqWmmD8b3EZfT2JwfkbZNCK6R2tpLqFfVx+Yv9F/te1T tydTow== Received: from mail-pl1-f197.google.com (mail-pl1-f197.google.com [209.85.214.197]) by mx0a-0031df01.pphosted.com (PPS) with ESMTPS id 4cncmftf7y-1 (version=TLSv1.3 cipher=TLS_AES_128_GCM_SHA256 bits=128 verify=NOT) for ; Tue, 03 Mar 2026 04:11:58 +0000 (GMT) Received: by mail-pl1-f197.google.com with SMTP id d9443c01a7336-2ae48a21d12so14810695ad.1 for ; Mon, 02 Mar 2026 20:11:58 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=oss.qualcomm.com; s=google; t=1772511118; x=1773115918; darn=vger.kernel.org; h=content-transfer-encoding:in-reply-to:from:content-language :references:cc:to:subject:user-agent:mime-version:date:message-id :from:to:cc:subject:date:message-id:reply-to; bh=aAXuw4WiHJ4I5hsmz1YeLDT4X8hqfp4XZsCr46xei6E=; b=Jbb8a0YWLsERyvGwl9QG7Bv6yvhUUyQeog+U+zNLh8ejMdbqdINxtHKSKdoLpETR4F F3awFVt+T2MqOZM3lO+qJyVQizxxjsbPz5lNvQNTTySPnVtWo5PLmtNy72Q1VjqHVFKt vLW/oKKVmmiW8u7fLhPF7qZGQ1N6of10jbtqOReR+MB+Jl4AKD4qZeuFMTjdStjhlxeC B/UbRNGfqPAat0qcUsf3aCecPYYfy9uQ8UgdgBmjXMua4QTTR3GGSH+Q0jQX55m/F2wy CWeo0ixiKRLAw/w4CCPvD2TXzeNVhVkJYkzj8wOer2J0Cu1l1H0RjfYxYoOCddS6Ms+Z EaaQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20230601; t=1772511118; x=1773115918; h=content-transfer-encoding:in-reply-to:from:content-language :references:cc:to:subject:user-agent:mime-version:date:message-id :x-gm-gg:x-gm-message-state:from:to:cc:subject:date:message-id :reply-to; bh=aAXuw4WiHJ4I5hsmz1YeLDT4X8hqfp4XZsCr46xei6E=; b=KWDFZH0B/6NX90ifjlGs5CFXlbLKG18p5/u0bGrFNNnd0b00GWdjIKd7e9WopXJuhg n6j2RV3vT19/ZM0zxrTfXx+7t/77FMiIGop7xmei3H5EudJjfbozlNVDCe230bdDFImD XfIUQ+XdDkxv9rwJBtf8fWtTwSUt3YKYAUwmeqUGaWk37qrFRhMyJIOua++EJKe94ThJ pg+dOt68e/N7ArGUeFLSjKsCMewD9hkMxghpP80/Cl347lzC0tj+x8hR48fecotGZElG kixnYTjp54+rhk1OBermLs0oABpNBq9pO4h2+APP0RZichLb8pKfg4dorvUoUA0Zmxr3 +0aA== X-Forwarded-Encrypted: i=1; AJvYcCUKMv1EJDxs7ofpOgsPEfVeu+bPLyuy3/Ja1cYYxvnBM3DmqDaQWnjxYJn5GU/IhWf27A79MlhYADhwFrU=@vger.kernel.org X-Gm-Message-State: AOJu0YzB1FGxeFAFhbcPpaoqX20IPXrTAU1jlXiL5jX1IlhR0w0s5oUr LbGOdLsKTO77JZ7hr5SEgW3MohOwhlWLLMmyJ7BlN+VQYsEQwdhlCbQfs0GIERPrGe/3ICG7NIz f3I+jzZBFl/mgvIHonLqsvnqpchxtBnSDBJgf8flfkcXNqNdU157wdtZ3/C+B9kPYa2o= X-Gm-Gg: ATEYQzwUUCSkpdppb80XHTb2PyOmFFlwwTRAJJ/iSyiCaW/QhRUI+Z0YjnMnWvahjFW kVLjIW0+h0m0DVFYyXM6IHbmek8rF21BLoXGa2AAEiIzxb1KHZo1qyvEsBSs2qygjgG63hsq/Az 955/U075LF4nV1Jes8zLhfWQiDyTIEqGfzMcmg7k17wwcJFsxco3H2P/Zzfh7X5DQzW6GYgfewd zsNjCBiG63c8cNUq3uRyAM0tlR2U9fla2vjm1VynCxDVHJ//mV9P6YRcdgdu83xLILFLT54kJe7 E2KKyijwfrV+3WCaHNHFc99Ii3dW++Pjui/jKkDqxDPmGrjZRfkjOQ028SycrECVtDsobVZoZjK STsioW9sz7nW8NiTdwR3NQmUzsSTroZ0jgAUYEglSC8/OnwH/s6sUFA== X-Received: by 2002:a17:902:da8f:b0:2ab:2633:d981 with SMTP id d9443c01a7336-2ae2e4b0832mr169443795ad.32.1772511117499; Mon, 02 Mar 2026 20:11:57 -0800 (PST) X-Received: by 2002:a17:902:da8f:b0:2ab:2633:d981 with SMTP id d9443c01a7336-2ae2e4b0832mr169443305ad.32.1772511116847; Mon, 02 Mar 2026 20:11:56 -0800 (PST) Received: from [10.206.105.120] ([202.46.23.25]) by smtp.gmail.com with ESMTPSA id d9443c01a7336-2ae5e1699c9sm11570305ad.10.2026.03.02.20.11.53 (version=TLS1_3 cipher=TLS_AES_128_GCM_SHA256 bits=128/128); Mon, 02 Mar 2026 20:11:56 -0800 (PST) Message-ID: Date: Tue, 3 Mar 2026 09:41:51 +0530 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:102.0) Gecko/20100101 Thunderbird/102.8.0 Subject: Re: [PATCH] media: iris: fix use-after-free of fmt_src during MBPF check To: Bryan O'Donoghue , Vikash Garodia , Dikshita Agarwal , Abhinav Kumar , Mauro Carvalho Chehab Cc: linux-media@vger.kernel.org, linux-arm-msm@vger.kernel.org, linux-kernel@vger.kernel.org References: <20260227-fix-use-after-free-of-fmt_src-during-mbpf-v1-1-307cdafffa2a@oss.qualcomm.com> <75a8b887-cbdd-4780-8262-1cc24a55bc90@kernel.org> Content-Language: en-US From: Vishnu Reddy In-Reply-To: <75a8b887-cbdd-4780-8262-1cc24a55bc90@kernel.org> Content-Type: text/plain; charset=UTF-8; format=flowed Content-Transfer-Encoding: 8bit X-Authority-Analysis: v=2.4 cv=Br+QAIX5 c=1 sm=1 tr=0 ts=69a65f8e cx=c_pps a=cmESyDAEBpBGqyK7t0alAg==:117 a=ZePRamnt/+rB5gQjfz0u9A==:17 a=IkcTkHD0fZMA:10 a=Yq5XynenixoA:10 a=s4-Qcg_JpJYA:10 a=VkNPw1HP01LnGYTKEx00:22 a=u7WPNUs3qKkmUXheDGA7:22 a=_glEPmIy2e8OvE2BGh3C:22 a=EUspDBNiAAAA:8 a=xiCWW2qfg3M94FGKY5wA:9 a=3ZKOabzyN94A:10 a=QEXdDO2ut3YA:10 a=1OuFwYUASf3TG4hYMiVC:22 X-Proofpoint-ORIG-GUID: 7O5KquWM44AcgJ9KIloP-qMywahjzEqv X-Proofpoint-Spam-Details-Enc: AW1haW4tMjYwMzAzMDAyNCBTYWx0ZWRfX8/Ma3aQWMO7T T2GdxMcDX9kJHS5D8Lz+PTcu+zsCTu4RaMaFeOR6AvZeFHHsy5n9Z7j6zFU6yxIg9mgEmHhnwlr ScD2oaRI/YOLl7y6CZzTKm60k3pRkR2prRJceXB8PnJIP1H3NiJx7xzpaiY5WZC//Pw0AFxhapy zCBIBPByuZOW16l3KJr0KDPt9Ql676wuRid+covz0mHbj3zF/D+mw+1WMvOjtx30bDUBz9inIy/ zmHGd2mSkgpfGteY5flf/fZ2P6exsLU63OiiXMDTYWmeqAdpwv4BFnLVZiCIbkneEXTYpY/UQDG LyhRPTlRw+cUtAEP9TYg6fXuKbdzLqQUO12JJQYf/Q5pVN63G9OMq7RPImd6/sztlbU0FpVdnco tgRJmla4rPZ7vh34M1Q9RkSK7mXyj2U+WTrEQQlgtZ0t9nUrEobOsHArfqA+ckXR39zBvYUdKVY chc4z3gR912aD8M7u4w== X-Proofpoint-GUID: 7O5KquWM44AcgJ9KIloP-qMywahjzEqv X-Proofpoint-Virus-Version: vendor=baseguard engine=ICAP:2.0.293,Aquarius:18.0.1121,Hydra:6.1.51,FMLib:17.12.100.49 definitions=2026-03-02_05,2026-03-03_01,2025-10-01_01 X-Proofpoint-Spam-Details: rule=outbound_notspam policy=outbound score=0 phishscore=0 malwarescore=0 clxscore=1011 bulkscore=0 spamscore=0 priorityscore=1501 adultscore=0 lowpriorityscore=0 suspectscore=0 impostorscore=0 classifier=typeunknown authscore=0 authtc= authcc= route=outbound adjust=0 reason=mlx scancount=1 engine=8.22.0-2602130000 definitions=main-2603030024 On 2/28/2026 3:15 AM, Bryan O'Donoghue wrote: > On 27/02/2026 17:33, Vishnu Reddy wrote: >> A race condition was observed during concurrency testing. the core MBPF >> check walks the list of active instances and reads fields such as >> fmt_src >> height and width. > > Where does that happen - you highlight iris_close() below - that's > good, what's the method or methods that can run concurrently with > iris_close() - you should state those in the commit log so that > reviewers like myself and people reading the commit in the future know > where to look. > > At the same time, iris_close() could free these format >> structures before the instance was removed from core list. this >> creates a >> use-after-free window where the MBPF checker access the freed memory and >> read invalid values. > > Without looking at the code this description seems suspect. > > &inst->lock ought to protect inst && inst->thing if it doesn't, then > the lock isn't being used correctly. > During concurrency testing, multiple instances can be created in parallel. Each instance has its own inst->lock, while the core list is protected by the global core->lock. The race occurs because these two locks protect different scopes: inst->lock protects fields within a single instance core->lock protects the list of active instances The MBPF checker walks the core instance list under the core->lock. While doing so, it reads fields such as fmt_src->width and fmt_src->height from each instance. Now consider what happens concurrently: Instance A (MBPF check): Acquires core->lock Iterates over the instance list Reads inst->fmt_src->width, inst->fmt_src->height, etc. Instance B (iris_close() for a different instance): Acquires inst->lock Frees inst->fmt_src and inst->fmt_dst (At this moment, the instance is still in the core list.) Releases inst->lock. Later acquires core->lock and removes that instance from the core list The problem is that fmt_src is freed before the instance is removed from the core list. This creates a use‑after‑free window: MBPF check (Instance A) is still walking the core list It reaches the instance whose fmt_src has already been freed by Instance B It dereferences a dangling pointer → use-after-free This situation occurs because: inst->lock only protects the instance internals MBPF checker does not take inst->lock when reading fmt_src It only relies on the core->lock, the instance is valid as long as it is in the core list Therefore, ordering of freeing inst->fmt_src and inst->fmt_dest in iris_close() is incorrect. The fix is to postpone freeing fmt_src and fmt_dst until after: The instance has been removed from the core list, and All teardown under the core lock is complete. Will update commit description in v2. >> >> To fix this, the freeing of fmt_src and fmt_dst is moved to the end >> of iris_close(), after the instance has been removed from the core >> list and teardown is complete. This avoids accessing dangling pointers >> during the MBPF check. >> >> Signed-off-by: Vishnu Reddy > > Needs > > - Fixes: > - Cc: stable ACK > >> --- >>   drivers/media/platform/qcom/iris/iris_vdec.c | 6 ------ >>   drivers/media/platform/qcom/iris/iris_vdec.h | 1 - >>   drivers/media/platform/qcom/iris/iris_venc.c | 6 ------ >>   drivers/media/platform/qcom/iris/iris_venc.h | 1 - >>   drivers/media/platform/qcom/iris/iris_vidc.c | 6 ++---- >>   5 files changed, 2 insertions(+), 18 deletions(-) >> >> diff --git a/drivers/media/platform/qcom/iris/iris_vdec.c >> b/drivers/media/platform/qcom/iris/iris_vdec.c >> index 719217399a30..99d544e2af4f 100644 >> --- a/drivers/media/platform/qcom/iris/iris_vdec.c >> +++ b/drivers/media/platform/qcom/iris/iris_vdec.c >> @@ -61,12 +61,6 @@ int iris_vdec_inst_init(struct iris_inst *inst) >>       return iris_ctrls_init(inst); >>   } >> >> -void iris_vdec_inst_deinit(struct iris_inst *inst) >> -{ >> -    kfree(inst->fmt_dst); >> -    kfree(inst->fmt_src); >> -} >> - >>   static const struct iris_fmt iris_vdec_formats_cap[] = { >>       [IRIS_FMT_NV12] = { >>           .pixfmt = V4L2_PIX_FMT_NV12, >> diff --git a/drivers/media/platform/qcom/iris/iris_vdec.h >> b/drivers/media/platform/qcom/iris/iris_vdec.h >> index ec1ce55d1375..5123d2a340e1 100644 >> --- a/drivers/media/platform/qcom/iris/iris_vdec.h >> +++ b/drivers/media/platform/qcom/iris/iris_vdec.h >> @@ -9,7 +9,6 @@ >>   struct iris_inst; >> >>   int iris_vdec_inst_init(struct iris_inst *inst); >> -void iris_vdec_inst_deinit(struct iris_inst *inst); >>   int iris_vdec_enum_fmt(struct iris_inst *inst, struct v4l2_fmtdesc >> *f); >>   int iris_vdec_try_fmt(struct iris_inst *inst, struct v4l2_format *f); >>   int iris_vdec_s_fmt(struct iris_inst *inst, struct v4l2_format *f); >> diff --git a/drivers/media/platform/qcom/iris/iris_venc.c >> b/drivers/media/platform/qcom/iris/iris_venc.c >> index aa27b22704eb..4d886769d958 100644 >> --- a/drivers/media/platform/qcom/iris/iris_venc.c >> +++ b/drivers/media/platform/qcom/iris/iris_venc.c >> @@ -79,12 +79,6 @@ int iris_venc_inst_init(struct iris_inst *inst) >>       return iris_ctrls_init(inst); >>   } >> >> -void iris_venc_inst_deinit(struct iris_inst *inst) >> -{ >> -    kfree(inst->fmt_dst); >> -    kfree(inst->fmt_src); >> -} >> - >>   static const struct iris_fmt iris_venc_formats_cap[] = { >>       [IRIS_FMT_H264] = { >>           .pixfmt = V4L2_PIX_FMT_H264, >> diff --git a/drivers/media/platform/qcom/iris/iris_venc.h >> b/drivers/media/platform/qcom/iris/iris_venc.h >> index c4db7433da53..00c1716b2747 100644 >> --- a/drivers/media/platform/qcom/iris/iris_venc.h >> +++ b/drivers/media/platform/qcom/iris/iris_venc.h >> @@ -9,7 +9,6 @@ >>   struct iris_inst; >> >>   int iris_venc_inst_init(struct iris_inst *inst); >> -void iris_venc_inst_deinit(struct iris_inst *inst); >>   int iris_venc_enum_fmt(struct iris_inst *inst, struct v4l2_fmtdesc >> *f); >>   int iris_venc_try_fmt(struct iris_inst *inst, struct v4l2_format *f); >>   int iris_venc_s_fmt(struct iris_inst *inst, struct v4l2_format *f); >> diff --git a/drivers/media/platform/qcom/iris/iris_vidc.c >> b/drivers/media/platform/qcom/iris/iris_vidc.c >> index bd38d84c9cc7..5eb1786b0737 100644 >> --- a/drivers/media/platform/qcom/iris/iris_vidc.c >> +++ b/drivers/media/platform/qcom/iris/iris_vidc.c >> @@ -289,10 +289,6 @@ int iris_close(struct file *filp) >>       v4l2_m2m_ctx_release(inst->m2m_ctx); >>       v4l2_m2m_release(inst->m2m_dev); >>       mutex_lock(&inst->lock); >> -    if (inst->domain == DECODER) >> -        iris_vdec_inst_deinit(inst); >> -    else if (inst->domain == ENCODER) >> -        iris_venc_inst_deinit(inst); >>       iris_session_close(inst); >>       iris_inst_change_state(inst, IRIS_INST_DEINIT); >>       iris_v4l2_fh_deinit(inst, filp); >> @@ -304,6 +300,8 @@ int iris_close(struct file *filp) >>       mutex_unlock(&inst->lock); >>       mutex_destroy(&inst->ctx_q_lock); >>       mutex_destroy(&inst->lock); >> +    kfree(inst->fmt_src); >> +    kfree(inst->fmt_dst); >>       kfree(inst); > > On the face of it I like the logic of moving the kfree() after > destruction of the various other bits - however the description in the > log makes me question of the two locks we have are being used > correctly .. > > Please provide more detail. Given details above and will update commit description in v2. >> >>       return 0; >> >> --- >> base-commit: 6de23f81a5e08be8fbf5e8d7e9febc72a5b5f27f >> change-id: >> 20260226-fix-use-after-free-of-fmt_src-during-mbpf-abc27f573400 >> >> Best regards, >> -- >> Vishnu Reddy >> > Regards, Vishnu Reddy