From nobody Tue Jun 16 18:02:15 2026 Received: from mail-pf1-f176.google.com (mail-pf1-f176.google.com [209.85.210.176]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 6B6CB136672 for ; Thu, 30 Apr 2026 05:40:55 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.210.176 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1777527657; cv=none; b=LKarn54K84z2lxLvlUR0OA/otDKjlPP0xIUuDx6MG3GgekOa8HZMHUWTsTG6OZ5nYiqo3U6sbH0Ja4Z1HGDpCmiGEIyGLMDb+LVUic0xgofeYN1sd3wa3mzCLC/tmykVr52h5zvH9osH/UtloqYigVnYbWnteQjbyygnaGD7Ljk= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1777527657; c=relaxed/simple; bh=sZvheAZoRjvdKOT6LW/gjyVxmpfa0CA+ZSeMbibVNSg=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=HP+2cXVUg/n3g3kP01tIeSnvxrSA4y4pL2ezu90OzGNKMqIbeKN4Sc3NWjsfeSMCvsCuBWBkooS+n4yxIyAMVbJJwcD8/3jh+8t9Ib01wJfYiCSOcdZbJwof1nPMGPdajxDu39a8M2sB5nRLOWhPlMXVHvqRGb4Fo+MjhSFfBJk= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=ixphaErN; arc=none smtp.client-ip=209.85.210.176 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="ixphaErN" Received: by mail-pf1-f176.google.com with SMTP id d2e1a72fcca58-82f8892d4d6so241444b3a.0 for ; Wed, 29 Apr 2026 22:40:55 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1777527655; x=1778132455; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to; bh=1+zXDwYkscXkwwf38XELFgWIvVjVJaXVdUr9CcmySjw=; b=ixphaErNs1+/2ILmQCYRgWaxvCWSimn26T8rN2NXAFpG81WzPmP301pp41584+7nyE LIxLmg7ZKtFrM4TTCuzJNLm2690OjnDaET0z/LByFF7v6qPc5XgXYl2kXGLw61OVvNn2 CABnfil3PrtKadAnPUUu4jIyekW+Q8SgDkAiCwOOcPNlxHIFskKEsPGgSUF6awnX1wxJ Uu4lzt2nYNiGMSk2VrMZolmKAa2yjwxdO4LkxY2Zc6fQIT6aZFvksW/AxgXzXSvYr//H 6jgRIkHRGZAbJpb/GUWx93mvogS0NTMjmO/abJhreTaP0ny/c9wca3UdEOkhpn+qUWZa QacA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1777527655; x=1778132455; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to; bh=1+zXDwYkscXkwwf38XELFgWIvVjVJaXVdUr9CcmySjw=; b=GFcCgxx1Sf03NO8Q52kcypfzXVVY/ZCLLrNBR0HRkva31E6OMdp8WjCNm6nF2Ih/kn kBwGv5TALPF8x59MPVbOuN4FgkEH7YOVa6FKrxIi1FXn4UrGj+UMFvwtf2gMBx9extfP Fr/2dmgjwdWKx7Sp7vACl/bk6nEpAoVs5rKE2P9ILT63hqKOJx+N9j3H1ttBj0WdJGZ/ ph//PmmNB3f4Rga6gox/qoVNKW/vdx8IFKXBh0iFiunlPVR7oKepKcH+TYmPEVqr++4z ATDzB6x+UCaNQZSxSIlnwLVv6673W6TyjUUflilKnGdzDmCB8EZOmH/wY6Ffnu3JMnsG FEgg== X-Forwarded-Encrypted: i=1; AFNElJ869QKcl5BgYl5H65i/+PnEc0glQvoGxmtNEWE3zueBUuSbLk4NNdU3TK3KKtph/f4D0KlWHjKVBU9QPyE=@vger.kernel.org X-Gm-Message-State: AOJu0YzH5PT5EyPszxLTGTZuF/hMOgZEjmPBVxpn0s7kkeJsPQno8dlt Znd6vcGf71H/8i5L3zjnU+RL2EpUnxfDOQM2u8+zOiCpZ0gSiK7GtQhH X-Gm-Gg: AeBDiesY81iQ5UpTwKMzHyU1Ugo7E9ysoa0CBArchKTBZHpsGO0yARO8/SrHuNJtbcC wU9FQ7r39RAUg56MUJ/r20f6O0Q8d/QcqtxNvI/R9dbF2ZRvFLSsiFx96euv4+Z8ldmqU6q7ahJ w10bgbV2kJ3DROJe4mSrKDUn2+Ipv5m/6fuiD8xlPsB3HBWK2WwC1TrO5FJdvAuLMZlRoSj14mD nGE6V4NfRgtfsyt14HC/zBLj7dsI8BQ+udNpmYoNUSRGGq8a6mQ65KCZEJ0MEz4y8ctPlSpKHWi aiLi+b3yrE1JEcc4W+nS0QomQJ6L2HP+zBquAp0iWCLLxbwuuZ73iyPMOMgt9Eoj6L0R9djf87i 2RWD2juRJFZwGYyQAGEldSXanSKnmIG1wmYBGZaK7uM5ZIQhjuYFGDhf99ElBdAbBCvBxcK8NNS h0AQdYuM6lHyZIHlEa X-Received: by 2002:a05:6a00:302a:b0:82f:4386:7989 with SMTP id d2e1a72fcca58-834fdc0daabmr1792231b3a.24.1777527654799; Wed, 29 Apr 2026 22:40:54 -0700 (PDT) Received: from lgs.. ([2001:250:5800:1000::5a26]) by smtp.gmail.com with ESMTPSA id d2e1a72fcca58-834ed7eb090sm3858242b3a.43.2026.04.29.22.40.50 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Wed, 29 Apr 2026 22:40:54 -0700 (PDT) From: Guangshuo Li To: Sakari Ailus , Bingbu Cao , Mauro Carvalho Chehab , Greg Kroah-Hartman , Hans Verkuil , linux-media@vger.kernel.org, linux-staging@lists.linux.dev, linux-kernel@vger.kernel.org Cc: Guangshuo Li Subject: [PATCH] media: staging/ipu7: Fix pdata double free in init error paths Date: Thu, 30 Apr 2026 13:38:20 +0800 Message-ID: <20260430053820.446080-1-lgs201920130244@gmail.com> X-Mailer: git-send-email 2.43.0 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" ipu7_bus_initialize_device() stores the caller allocated pdata pointer in adev->pdata and installs ipu7_bus_release() as the device release callback. After auxiliary_device_init() succeeds, pdata is released by ipu7_bus_release(). The isys and psys init error paths still call kfree(pdata) after put_device() or after ipu7_bus_add_device() fails. In both cases the auxiliary device release callback has already been invoked, so pdata has already been freed through adev->pdata. Remove the duplicate kfree(pdata) calls. Also cache the MMU init error before calling put_device(), since put_device() may release the auxiliary device container. This issue was found by a static analysis tool I am developing. Fixes: b7fe4c0019b1 ("media: staging/ipu7: add Intel IPU7 PCI device driver= ") Signed-off-by: Guangshuo Li --- drivers/staging/media/ipu7/ipu7.c | 20 ++++++++------------ 1 file changed, 8 insertions(+), 12 deletions(-) diff --git a/drivers/staging/media/ipu7/ipu7.c b/drivers/staging/media/ipu7= /ipu7.c index c771e763f8c5..069f0238c8cf 100644 --- a/drivers/staging/media/ipu7/ipu7.c +++ b/drivers/staging/media/ipu7/ipu7.c @@ -2169,21 +2169,19 @@ ipu7_isys_init(struct pci_dev *pdev, struct device = *parent, isys_adev->mmu =3D ipu7_mmu_init(dev, base, ISYS_MMID, &ipdata->hw_variant); if (IS_ERR(isys_adev->mmu)) { - dev_err_probe(dev, PTR_ERR(isys_adev->mmu), + ret =3D PTR_ERR(isys_adev->mmu); + dev_err_probe(dev, ret, "ipu7_mmu_init(isys_adev->mmu) failed\n"); put_device(&isys_adev->auxdev.dev); - kfree(pdata); - return ERR_CAST(isys_adev->mmu); + return ERR_CAST(ret); } =20 isys_adev->mmu->dev =3D &isys_adev->auxdev.dev; isys_adev->subsys =3D IPU_IS; =20 ret =3D ipu7_bus_add_device(isys_adev); - if (ret) { - kfree(pdata); + if (ret) return ERR_PTR(ret); - } =20 return isys_adev; } @@ -2216,21 +2214,19 @@ ipu7_psys_init(struct pci_dev *pdev, struct device = *parent, psys_adev->mmu =3D ipu7_mmu_init(&pdev->dev, base, PSYS_MMID, &ipdata->hw_variant); if (IS_ERR(psys_adev->mmu)) { - dev_err_probe(&pdev->dev, PTR_ERR(psys_adev->mmu), + ret =3D PTR_ERR(psys_adev->mmu); + dev_err_probe(&pdev->dev, ret, "ipu7_mmu_init(psys_adev->mmu) failed\n"); put_device(&psys_adev->auxdev.dev); - kfree(pdata); - return ERR_CAST(psys_adev->mmu); + return ERR_CAST(ret); } =20 psys_adev->mmu->dev =3D &psys_adev->auxdev.dev; psys_adev->subsys =3D IPU_PS; =20 ret =3D ipu7_bus_add_device(psys_adev); - if (ret) { - kfree(pdata); + if (ret) return ERR_PTR(ret); - } =20 return psys_adev; } --=20 2.43.0