From nobody Fri Sep 25 02:43:47 2026 Received: from cstnet.cn (smtp25.cstnet.cn [159.226.251.25]) (using TLSv1.2 with cipher DHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 6F9823AB274; Thu, 17 Sep 2026 10:12:25 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=159.226.251.25 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789639947; cv=none; b=k+FICeZn+oZ1zaEomcJanKhcC9ipDehY7aXTkVr3puUafyBFlhoFw2XFoWt6kDr3aa570dj+inF/BhQZWj/CiL22IPjik+aerPeA2yrgSqrzcT2v/ipkgdZhqAtnK/Lgn5rj+/deq7VP+adUCFxyljAO2aIHV28NLvFbZmh7b+g= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789639947; c=relaxed/simple; bh=14tQsQbOtIGQ+VXPEy11vLb1bRQA5rJ5Cq9xlwLatjw=; h=From:To:Cc:Subject:Date:Message-Id:MIME-Version; b=K/XB8V/vBiYSiOXlmQxmUapjJI3c2khixKZwtVT1+fRElzyffpsud2GTKjeRn6E4gkx2Yn7WZvamjyaeUXqGg4fPW1HofPJZsZU4Lhg8lVh+0C7vFL84LxnGctkkZlf+9Ljepjg7j/lQE5OuK9UkXIstJ03WIUfU8rDYN6FDahE= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=iscas.ac.cn; spf=pass smtp.mailfrom=iscas.ac.cn; arc=none smtp.client-ip=159.226.251.25 Authentication-Results: smtp.subspace.kernel.org; dmarc=none (p=none dis=none) header.from=iscas.ac.cn Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=iscas.ac.cn Received: from dfae2b116770.home.arpa (unknown [36.110.52.2]) by APP-05 (Coremail) with SMTP id zQCowAC36EIHvatqYF5+CA--.436S2; Thu, 17 Sep 2026 18:12:23 +0800 (CST) From: Wentao Liang To: hverkuil@kernel.org Cc: linux-kernel@vger.kernel.org, linux-media@vger.kernel.org, m-karicheri2@ti.com, mchehab@kernel.org, prabhakar.csengg@gmail.com, Wentao Liang , stable@vger.kernel.org Subject: [PATCH] media: vpif_capture: Fix i2c adapter reference leak in vpif_probe() Date: Thu, 17 Sep 2026 10:12:22 +0000 Message-Id: <20260917101222.2146226-1-vulab@iscas.ac.cn> X-Mailer: git-send-email 2.34.1 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable X-CM-TRANSID: zQCowAC36EIHvatqYF5+CA--.436S2 X-Coremail-Antispam: 1UD129KBjvJXoW7CrWUJF18XFW8WF1rur4Uurg_yoW8WFWkpF Wq9FWSkrW0gF109F4UJwn5uFyakw4rK3yakF92kw4xua93Xry7JFyrAF12yF4kXrWkJa47 JFn0v3yrAFW3ur7anT9S1TB71UUUUU7qnTZGkaVYY2UrUUUUjbIjqfuFe4nvWSU5nxnvy2 9KBjDU0xBIdaVrnRJUUUB2b7Iv0xC_KF4lb4IE77IF4wAFc2x0x2IEx4CE42xK8VAvwI8I cIk0rVWrJVCq3wAFIxvE14AKwVWUJVWUGwA2ocxC64kIII0Yj41l84x0c7CEw4AK67xGY2 AK021l84ACjcxK6xIIjxv20xvE14v26ryj6F1UM28EF7xvwVC0I7IYx2IY6xkF7I0E14v2 6F4j6r4UJwA2z4x0Y4vEx4A2jsIE14v26rxl6s0DM28EF7xvwVC2z280aVCY1x0267AKxV W0oVCq3wAS0I0E0xvYzxvE52x082IY62kv0487Mc02F40EFcxC0VAKzVAqx4xG6I80ewAv 7VC0I7IYx2IY67AKxVWUAVWUtwAv7VC2z280aVAFwI0_Gr1j6F4UJwAm72CE4IkC6x0Yz7 v_Jr0_Gr1lF7xvr2IYc2Ij64vIr41lF7I21c0E0s8F02x267IIx4CEVc8vx2IErcIFxwCY 1x0262kKe7AKxVWUAVWUtwCF04k20xvY0x0EwIxGrwCF04k20xvE74AGY7Cv6cx26r48Zr WUJr1UMxC20s026xCaFVCjc4AY6r1j6r4UMI8I3I0E5I8CrVAFwI0_Jr0_Jr4lx2IqxVCj r7xvwVAFwI0_JrI_JrWlx4CE17CEb7AF67AKxVWUtVW8ZwCIc40Y0x0EwIxGrwCI42IY6x IIjxv20xvE14v26r1I6r4UMIIF0xvE2Ix0cI8IcVCY1x0267AKxVWxJVW8Jr1lIxAIcVCF 04k26cxKx2IYs7xG6r1j6r1xMIIF0xvEx4A2jsIE14v26r4UJVWxJr1lIxAIcVC2z280aV CY1x0267AKxVW0oVCq3bIYCTnIWIevJa73UjIFyTuYvjxU2f-BDUUUU X-CM-SenderInfo: pyxotu46lvutnvoduhdfq/1tbiBwYNA2qrrRk5yQABsL Content-Type: text/plain; charset="utf-8" vpif_probe() takes a reference to the i2c adapter with i2c_get_adapter() and passes it to v4l2_i2c_new_subdev_board(), which does not consume it, but the reference is never released, so it is leaked both when the probe succeeds and when it fails after the adapter has been acquired. Release the reference with i2c_put_adapter() on the success path and in the probe_subdev_out cleanup, and initialise i2c_adap so that the cleanup is a no-op when the adapter was never acquired. Fixes: 6ffefff5a9e7 ("V4L/DVB (12906c): V4L : vpif capture driver for DM646= 7") Cc: stable@vger.kernel.org Signed-off-by: Wentao Liang --- drivers/media/platform/ti/davinci/vpif_capture.c | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/drivers/media/platform/ti/davinci/vpif_capture.c b/drivers/med= ia/platform/ti/davinci/vpif_capture.c index 15df3ea2f77e..572fea499b71 100644 --- a/drivers/media/platform/ti/davinci/vpif_capture.c +++ b/drivers/media/platform/ti/davinci/vpif_capture.c @@ -1602,7 +1602,7 @@ vpif_capture_get_pdata(struct platform_device *pdev, static int vpif_probe(struct platform_device *pdev) { struct vpif_subdev_info *subdevdata; - struct i2c_adapter *i2c_adap; + struct i2c_adapter *i2c_adap =3D NULL; int subdev_count; int res_idx =3D 0; int i, err; @@ -1692,9 +1692,12 @@ static int vpif_probe(struct platform_device *pdev) } } =20 + i2c_put_adapter(i2c_adap); + return 0; =20 probe_subdev_out: + i2c_put_adapter(i2c_adap); v4l2_async_nf_cleanup(&vpif_obj.notifier); /* free sub devices memory */ kfree(vpif_obj.sd); --=20 2.34.1