drivers/media/v4l2-core/v4l2-async.c | 1 - 1 file changed, 1 deletion(-)
From: Xu Rao <raoxu@uniontech.com>
v4l2_async_match_notify() creates ancillary media links before adding
asc->asc_subdev_entry to sd->asc_list.
If ancillary link creation fails, the function jumps to
err_call_unbind while asc_subdev_entry has not been linked yet. Async
connections are zero-allocated, so the list entry still has NULL next
and prev pointers on this path. Calling list_del() on it can therefore
dereference NULL instead of returning the original link creation error.
Do not delete asc_subdev_entry from err_call_unbind. There is no list
insertion to undo on this path; the bound callback and sub-device
registration are the operations that need to be rolled back.
Fixes: 28a1295795d8 ("media: v4l: async: Allow multiple connections between entities")
Cc: stable@vger.kernel.org
Signed-off-by: Xu Rao <raoxu@uniontech.com>
---
drivers/media/v4l2-core/v4l2-async.c | 1 -
1 file changed, 1 deletion(-)
diff --git a/drivers/media/v4l2-core/v4l2-async.c b/drivers/media/v4l2-core/v4l2-async.c
index 888a2e213b08..0aa4265a6782 100644
--- a/drivers/media/v4l2-core/v4l2-async.c
+++ b/drivers/media/v4l2-core/v4l2-async.c
@@ -392,7 +392,6 @@ static int v4l2_async_match_notify(struct v4l2_async_notifier *notifier,
err_call_unbind:
v4l2_async_nf_call_unbind(notifier, sd, asc);
- list_del(&asc->asc_subdev_entry);
err_unregister_subdev:
if (registered)
--
2.50.1
Hi Rao,
On Mon, Aug 10, 2026 at 05:50:12PM +0800, raoxu wrote:
> From: Xu Rao <raoxu@uniontech.com>
>
> v4l2_async_match_notify() creates ancillary media links before adding
> asc->asc_subdev_entry to sd->asc_list.
>
> If ancillary link creation fails, the function jumps to
> err_call_unbind while asc_subdev_entry has not been linked yet. Async
> connections are zero-allocated, so the list entry still has NULL next
> and prev pointers on this path. Calling list_del() on it can therefore
> dereference NULL instead of returning the original link creation error.
>
> Do not delete asc_subdev_entry from err_call_unbind. There is no list
> insertion to undo on this path; the bound callback and sub-device
> registration are the operations that need to be rolled back.
>
> Fixes: 28a1295795d8 ("media: v4l: async: Allow multiple connections between entities")
> Cc: stable@vger.kernel.org
> Signed-off-by: Xu Rao <raoxu@uniontech.com>
Can you resend this, please? Somehow Patchwork didn't pick it up.
--
Regards,
Sakari Ailus
On Tue, Aug 11, 2026 at 09:21:07AM +0300, Sakari Ailus wrote: > Can you resend this, please? Somehow Patchwork didn't pick it up. Please ignore. There was an issue with Message-Id coding I suppose. -- Sakari Ailus
© 2016 - 2026 Red Hat, Inc.