From nobody Wed Sep 30 13:02:56 2026 Received: from mail-pj1-f52.google.com (mail-pj1-f52.google.com [209.85.216.52]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 2E6C13C3C0C for ; Sat, 8 Aug 2026 11:06:25 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.216.52 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786187187; cv=none; b=CSJjBNxWD/XdkmKpPr1VFhPU2aLo937BD2ofTNPIWz8NJusl+4EaJsI/O6nhMrHJuu+B/WWG0rLSwxmxEzctjkVhcR17e3CdwAzWsWK/GUcxr6ljII7kNx34Tbj043dKBK+VSDHjKVosPEP/CiK9UYZhVyuOVN1bqeAlPBJ/cUo= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786187187; c=relaxed/simple; bh=tDsFj4Lh9ROCK1QL6OxCscLJBiWTpO7vMwF1199NUaA=; h=From:To:Cc:Subject:Date:Message-Id:In-Reply-To:References: MIME-Version; b=SHTM2zxDqy5/zdbRrP9eOQeZypntvmuAMeMu+RyGzfQmvlHjdxT4Z7F86c8nJ1BnDVchYgnCEyozij86FDbd0Ha7dMSNkxN+qvqjhkIi5fnlryFadfw7ey8iC0dvHWIvPIq4gHCxPi7w8Q2bFp+lNhp1aXRu589HNpUpW3cjdlc= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=aqtvqisa; arc=none smtp.client-ip=209.85.216.52 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="aqtvqisa" Received: by mail-pj1-f52.google.com with SMTP id 98e67ed59e1d1-384930ca5e2so395999a91.3 for ; Sat, 08 Aug 2026 04:06:25 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1786187185; x=1786791985; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=hTWsfLJS/81iyczYbFu23mRRJqJRdNk8TSWy7ODIao4=; b=aqtvqisaSfmRgbgmXiZItxO6cdp6CJCvU2xi8KQyHTOEgXvX+p5mbLocVg2WkigFff Rj6zJwIMmnP3rezFT2a7ZCgLa+1j9cP8G0qbQOjJG31q7EBhNrM+tcHCwKPC4pWKs9KU h216ZnIHQtQCtBKvVfCDXhZ9QTsW06f9104xFGdlSeZbW+O7XRVXmqx0xCv66DKuMv9c fyvO9KeecpQtqLA6URSRQwOsq5toOIDyPyh199sWFtxR9WPpuFodkHYT2DSqqpgG37eA EcEBoFX+ttTj0p5SSacPQxQXLzM3hcp9wfW9KvCLe1ju04OUfZ88/OrhsnDW9vDSoinY Tgbg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1786187185; x=1786791985; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=hTWsfLJS/81iyczYbFu23mRRJqJRdNk8TSWy7ODIao4=; b=NfJtqfjBL8AGshDyDj97X8OOc2KBu8FeS4Jwjmvy0et0cymHCmZFIPghhUxt5Fk6+M GHBUg+eaeLBYOpEbPafzCO6ejQTLzAVD3GIBbwOXC5WRMhYw18TjdUHEKfL0JS5PRafG 5eGL4hxTtyS02xntZ8FbTknl9KNZiiIw+1BENzISOcppcR3CoXLdK1bUAobowHGmpECc f0GDAH5D+6isk4ypKoNhh7Y2TqyObT2vDD0dtvHS5I7RQXrcwrhhD7XQ1lksgvN9Y1Z6 0rsS7ZeZU3O3fNOrGDC1PyY99OEnF3//6SgaBYMDZ823qkTMIo4aSJHMrWWblb9xELoQ 201g== X-Forwarded-Encrypted: i=1; AHgh+RrmT51S6AIr8t1OmOSDXi0HFuRFSt5FrSTemSq14IVuHqOYWrILsKD/NxNTKyUfwepN4kR75p3uH3YUGcw=@vger.kernel.org X-Gm-Message-State: AOJu0Ywj6AsC0HR/sgDWht9A1upTpJi5PwMS6awo+b7AoXJVrevr0D/t u+prYX09gM/Qdghnev31GJCuNiC/GzyM6WdnLu7KdChVgiLJJ3ic1iTu X-Gm-Gg: AR+sD12YBx+BsiX0yDSbrVb7XVMgXQGKM0FK16MYc0/VGp4Z5++4jZaK8zATwjhYPo2 R7cRnLQgKJs6lJWc99QJESEpN1RFvIiohWxlHsnf08LYgSiMYNQAZ0dAeEGDwGhRgiLXUeafRbf pHEAnwhU4rADTRmkdd9ofqooy67/wrziDLs+vQv8M7p00ua64eQauWvBsTxRKPwI71ZdlcPGKP0 y2rCYtJz2jIdCcl+iLHPuCSA9eOBiyWGyGdG5HS1iO6feuSLu/YwIzLhTwBHr61RLQ8sCyl69VF DSg149S3A3qoyXumqkQ2JFv2wIkefaRQeI1kjThH4spgiNFYbgT/Tm5D+FPtoQyI2ZrYTzZ9F9C qjcXheb+OrQ8qJJLXmb4ZoONptOWo0kUtfLGHLvJUVQ2a3U2KrE3Y2CgT+yCDyL5l4wmGKOpogV 79lAiNp+6VaL0Y9CIQpCJw8oaD1XhSErQJAW3g7hpv6HZCrrIA2m4PS7ffAWTa6aaxVtpX2u6LC at9dQ== X-Received: by 2002:a17:90b:2dc1:b0:38f:de97:b06 with SMTP id 98e67ed59e1d1-3903c535d79mr33954628a91.5.1786187185202; Sat, 08 Aug 2026 04:06:25 -0700 (PDT) Received: from SGN-LDSENG.tasernet.com ([2405:4800:5cc3:11a:1ac0:4dff:fe8b:4a69]) by smtp.gmail.com with ESMTPSA id a92af1059eb24-141019b4eabsm15243343c88.6.2026.08.08.04.06.21 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sat, 08 Aug 2026 04:06:24 -0700 (PDT) From: Cong Nguyen To: Maxime Ripard , Mauro Carvalho Chehab , linux-media@vger.kernel.org Cc: Chen-Yu Tsai , Jernej Skrabec , Samuel Holland , Sakari Ailus , linux-arm-kernel@lists.infradead.org, linux-sunxi@lists.linux.dev, linux-kernel@vger.kernel.org, Cong Nguyen , stable@vger.kernel.org Subject: [PATCH v1 1/3] media: sun4i-csi: fix video device and subdev leak in notify_complete() Date: Sat, 8 Aug 2026 18:06:15 +0700 Message-Id: <7804a3c87beefde14e0358fa2a11e63005525890.1786184456.git.congnt264@gmail.com> X-Mailer: git-send-email 2.25.1 In-Reply-To: References: Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" sun4i_csi_notify_complete() registers the bridge subdev with v4l2_device_register_subdev() and the video device with sun4i_csi_v4l2_register() (which calls video_register_device()) before it creates the media pad links and registers the subdev nodes. If any of the later steps fail, the error path only unregistered the media device: err_clean_media: media_device_unregister(&csi->mdev); return ret; The already registered video device and bridge subdev were left behind. Because this failure propagates back through v4l2_async_nf_register() and aborts probe, the driver's devm-managed struct sun4i_csi (which embeds the video_device) is freed while /dev/videoX is still registered, so a subsequent open() from userspace dereferences freed memory. Unwind the registrations in reverse order on error, mirroring the teardown in sun4i_csi_remove(): unregister the video device with vb2_video_unregister_device() and the bridge subdev with v4l2_device_unregister_subdev(). Also unwind the intermediate v4l2/media registration steps so every early return leaves no half-registered state. Fixes: 577bbf23b758 ("media: sunxi: Add A10 CSI driver") Cc: stable@vger.kernel.org Assisted-by: Claude:claude-opus-4 Signed-off-by: Cong Nguyen --- drivers/media/platform/sunxi/sun4i-csi/sun4i_csi.c | 8 ++++++-- 1 file changed, 6 insertions(+), 2 deletions(-) diff --git a/drivers/media/platform/sunxi/sun4i-csi/sun4i_csi.c b/drivers/m= edia/platform/sunxi/sun4i-csi/sun4i_csi.c index e53a07b770b7..a8711336a754 100644 --- a/drivers/media/platform/sunxi/sun4i-csi/sun4i_csi.c +++ b/drivers/media/platform/sunxi/sun4i-csi/sun4i_csi.c @@ -85,11 +85,11 @@ static int sun4i_csi_notify_complete(struct v4l2_async_= notifier *notifier) =20 ret =3D sun4i_csi_v4l2_register(csi); if (ret < 0) - return ret; + goto err_unregister_subdev; =20 ret =3D media_device_register(&csi->mdev); if (ret) - return ret; + goto err_unregister_video; =20 /* Create link from subdev to main device */ ret =3D media_create_pad_link(&subdev->entity, CSI_SUBDEV_SOURCE, @@ -114,6 +114,10 @@ static int sun4i_csi_notify_complete(struct v4l2_async= _notifier *notifier) =20 err_clean_media: media_device_unregister(&csi->mdev); +err_unregister_video: + vb2_video_unregister_device(&csi->vdev); +err_unregister_subdev: + v4l2_device_unregister_subdev(subdev); =20 return ret; } --=20 2.25.1 From nobody Wed Sep 30 13:02:56 2026 Received: from mail-pg1-f172.google.com (mail-pg1-f172.google.com [209.85.215.172]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 0BBA73D16E2 for ; Sat, 8 Aug 2026 11:17:20 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.215.172 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786187845; cv=none; b=kdo2mPCiljLrdFOjcNwzvGLOrqZdqAfNEDrCZ7WbjV+M169Hl76npmFdtaFRiHFZlUSBDQgMDCaPtig0Bd10U/8dG2HjpPyZNZHSARyjjpjHnSvUzmoN/FLbE/I72kJ3PQxBGM15NYKk8igrfV19pRSCFNW3rmkJUvlIJszBiz0= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786187845; c=relaxed/simple; bh=/o1udNNLV+FNe1R9p8BzEoEJfIqD9mThtLK2mmEohxQ=; h=From:To:Cc:Subject:Date:Message-Id:In-Reply-To:References: MIME-Version; b=Ud8SwCFFLhPeO0fKnG0mXYIsb0aU5/THbHiq71J4iII0Jn8yO8aD0rXoJL5AxeM+yRnFBtnAa6ea1iNO05cHwqU731/FX2SnTNzOBOgQh9pl4MJIFLjCOBsOHdZ02WxQTxs7aiGrB4GIgI4LUa7gZC2/J+/fUvYWTy5RLfz9TY8= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=M0ReT1tr; arc=none smtp.client-ip=209.85.215.172 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="M0ReT1tr" Received: by mail-pg1-f172.google.com with SMTP id 41be03b00d2f7-ca80d708489so218538a12.1 for ; Sat, 08 Aug 2026 04:17:20 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1786187840; x=1786792640; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=VegdV0CGVtEAsdoGYq2fWs6TLBlXPmk2Egy9/veY9KE=; b=M0ReT1trpbHUGbvE6ipiIDdU4zdS3ysLx4hoMj5chMA28BJnjH5UFJcKzTUIIXkruZ /CJqS0VEOP5bh0SectkjAbRacELSDSQ8U+SJC0sLbiRgZk9PRxAbtA5V0BwBLguh9XUV Lct2voctfZD/31GGGfm87iXK5wKg7/RdsnCbyfh4EkTNAu8xpfayoS0qAPeKiR2U4ffX CWhcLdwm0UH7LrbFUMsHBn8ntP3qWzbTXKLO2Unv4MmRFxVR0JM3o2kgdeZZ464yKbX2 2qXVNnYqz36WX0qCN0L/mm5EK3aABVBj8s4aPSAwXYIz4bCiDZ/CMUaLlcxer29uYBxH YNyw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1786187840; x=1786792640; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=VegdV0CGVtEAsdoGYq2fWs6TLBlXPmk2Egy9/veY9KE=; b=k0j2mqpRA60yzYEnxjZdqukRHB1q5WWyD+iT2TuMbzu2muH24Lt3fJbHY+AxM8YvOn q78DSF3krS0yT0jplZgmcFRw7pjKJZG7vmsEmDN8D3Hlryn/FowyNULmR3rux/Jex444 3pYthvjMCtQ+B3/5r2TyIXcG0PStfzovoGrbuzhHER7JGkdfhGhN9KKXbsGAcDnDuoRh icIONn1qAL3XUBssce1aJ6DqPbxzpLyT5iJOR+tyHPe5h4f767EHodPI/TcKCe1/mvMA b6V8+LbZc6CjlXX11h7zqK4I09N2TlUkE91/puaO8B6NjjlQjKt16a5BMCTrFwQcZB6g 9vwA== X-Forwarded-Encrypted: i=1; AHgh+RpZryVCF5NRi/WISS0LcXlTcXqAgFUBb5G6G21zdJktoJRVbdF7DGLMRoyG5YO0N+5KcydvNRKBaoOGCdw=@vger.kernel.org X-Gm-Message-State: AOJu0YwyBnaBJU2kZzP9pmCmjAlhB3m0iONbEsI+i6wMSMgDuby/wzGw hOkKeNoMbM1Sj4NKMOg6La4IYQPfIT0BlSKjyJInWy97onsAhX73lRwK X-Gm-Gg: AR+sD13gfbqVfzqrvGpJ5mAncp+gRr6T6/2nwUzruVV0UBeN7XVtqDrlKN8EZRyMziR hOvL/xESsnhV8n40Mtl1dcOtqdVVhvXPC1jFOL4WMJcNAssg1LYU/qpW0nIw3LmiAvdZGS/t9/0 /UYjUD0leNP9bLBkiV3z/JIF9m6ayKgpYetzTVAeSJrEvRRQkJpCA9+vMOaFY5AKPKjatOhkcfM pncVhuhD7h3AUAlLeQq05F4DA9GfGAQeVNASXzNkMztHgkCNGeHynu/bQabKib6052wpgIualqR jofHDi7BKHlBPtFjbzdUh8ABzqQpApfD6uLBwJjvOmJj3SNTf0Q3zKOmUJuutcNgMHoOAKiEqKZ o1BpLwFfiD1z4bTx7mwxFWKbdTgnpuaQhU4+OmzBTa+ir3E7vBWMRDwXGpn/oOWrsfrxGnHnYli Gxpo2EiWt8W9Khd5QNc2gc0HJAlWYk2hKsj6KGmXvwOjewO01FPW0ceXWyc16XVpkgj/7WwOTrX h2QZA== X-Received: by 2002:a05:6300:141:b0:3c3:750f:3cf9 with SMTP id adf61e73a8af0-3cbd3ac3fbemr6024104637.11.1786187840297; Sat, 08 Aug 2026 04:17:20 -0700 (PDT) Received: from SGN-LDSENG.tasernet.com ([2405:4800:5cc3:11a:1ac0:4dff:fe8b:4a69]) by smtp.gmail.com with ESMTPSA id 5a478bee46e88-315bebdf796sm17179976eec.22.2026.08.08.04.17.15 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sat, 08 Aug 2026 04:17:19 -0700 (PDT) From: Cong Nguyen To: Maxime Ripard , Mauro Carvalho Chehab , linux-media@vger.kernel.org Cc: Chen-Yu Tsai , Jernej Skrabec , Samuel Holland , Sakari Ailus , linux-arm-kernel@lists.infradead.org, linux-sunxi@lists.linux.dev, linux-kernel@vger.kernel.org, Cong Nguyen , stable@vger.kernel.org Subject: [PATCH v1 2/3] media: sun4i-csi: disable interrupts when stopping streaming Date: Sat, 8 Aug 2026 18:17:09 +0700 Message-Id: X-Mailer: git-send-email 2.25.1 In-Reply-To: References: Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" sun4i_csi_start_streaming() enables the frame-done interrupt in CSI_INT_EN_REG, but sun4i_csi_stop_streaming() only stops the capture engine (CSI_CPT_CTRL_REG) via sun4i_csi_capture_stop(). It never disables the interrupt source nor synchronizes with the handler. Capture stops at the end of the current frame, so a frame-done interrupt can still fire shortly after stop_streaming() returns. If userspace then closes the device, sun4i_csi_release() calls pm_runtime_put() and the CSI block is powered down (clocks gated, reset asserted). A delayed interrupt handler would then read/write CSI registers on the gated block, which can hang or crash the system. Clear CSI_INT_EN_REG and call synchronize_irq() in stop_streaming(), before returning the active buffers and freeing the scratch buffer, so no handler can run past this point. Store the IRQ number in struct sun4i_csi so it is available here. Fixes: 577bbf23b758 ("media: sunxi: Add A10 CSI driver") Cc: stable@vger.kernel.org Assisted-by: Claude:claude-opus-4 Signed-off-by: Cong Nguyen --- drivers/media/platform/sunxi/sun4i-csi/sun4i_csi.h | 1 + drivers/media/platform/sunxi/sun4i-csi/sun4i_dma.c | 11 +++++++++++ 2 files changed, 12 insertions(+) diff --git a/drivers/media/platform/sunxi/sun4i-csi/sun4i_csi.h b/drivers/m= edia/platform/sunxi/sun4i-csi/sun4i_csi.h index 4e0c2df45d4d..51173faea871 100644 --- a/drivers/media/platform/sunxi/sun4i-csi/sun4i_csi.h +++ b/drivers/media/platform/sunxi/sun4i-csi/sun4i_csi.h @@ -112,6 +112,7 @@ struct sun4i_csi { const struct sun4i_csi_traits *traits; =20 void __iomem *regs; + int irq; struct clk *bus_clk; struct clk *isp_clk; struct clk *ram_clk; diff --git a/drivers/media/platform/sunxi/sun4i-csi/sun4i_dma.c b/drivers/m= edia/platform/sunxi/sun4i-csi/sun4i_dma.c index e911c7f7acc5..da697f39f2bc 100644 --- a/drivers/media/platform/sunxi/sun4i-csi/sun4i_dma.c +++ b/drivers/media/platform/sunxi/sun4i-csi/sun4i_dma.c @@ -354,6 +354,16 @@ static void sun4i_csi_stop_streaming(struct vb2_queue = *vq) v4l2_subdev_call(csi->src_subdev, video, s_stream, 0); sun4i_csi_capture_stop(csi); =20 + /* + * Disable the frame done interrupt and wait for the handler to + * finish. A frame may complete right as capture is stopped, so an + * interrupt can still be pending here; without this the handler could + * run after the device is powered down (pm_runtime_put() on release) + * and access registers on a gated block. + */ + writel(0, csi->regs + CSI_INT_EN_REG); + synchronize_irq(csi->irq); + /* Release all active buffers */ spin_lock_irqsave(&csi->qlock, flags); return_all_buffers(csi, VB2_BUF_STATE_ERROR); @@ -438,6 +448,7 @@ int sun4i_csi_dma_register(struct sun4i_csi *csi, int i= rq) dev_err(csi->dev, "Couldn't register our interrupt\n"); goto err_unregister_device; } + csi->irq =3D irq; =20 return 0; =20 --=20 2.25.1 From nobody Wed Sep 30 13:02:56 2026 Received: from mail-pj1-f53.google.com (mail-pj1-f53.google.com [209.85.216.53]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 24CA8369D5D for ; Sat, 8 Aug 2026 11:17:38 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.216.53 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786187859; cv=none; b=V5zmz91sz6e8DAlt+e7z3uoloaJRYE1q6CdVtBBtiS09DGtD7izO3QD9nJNg5e1He6SEwoLpnPfRPWxnkqqk9sii703upeB1cgqa17Xw6DoNsl2ZerD8LIdESFvUADeetiKkjs641gAjPiawrKIGl2jBmeF3tbzLzP5r2vms3p8= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786187859; c=relaxed/simple; bh=ON1kS1no0SPn9XlGXhFU53i+x3fCGvAcs6uB4rd1MZ8=; h=From:To:Cc:Subject:Date:Message-Id:In-Reply-To:References: MIME-Version; b=U8b2/1ls/50ala7y1k1Uc1KBwTFHFh3F8787zd5tVTFcFj+p2Ou43tmD9Ef+zIWz/vb7Yfh6X9I/VKEI8nnu7g9jEelzBKMR1pW0r/uc9CrYzGD5z9LeK/+Jz0CNkSEgG5d3m3sCh6x5Ee5ZjPMhub0a2oKzPUg0umdNtdlf+5U= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=pUzWV/cE; arc=none smtp.client-ip=209.85.216.53 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="pUzWV/cE" Received: by mail-pj1-f53.google.com with SMTP id 98e67ed59e1d1-38ea87caafeso236212a91.3 for ; Sat, 08 Aug 2026 04:17:38 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1786187857; x=1786792657; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=3Vav1/IZDRyi5TmIe+ztFcmW7gzOkBU4RfYMZP3HSBU=; b=pUzWV/cEKxVtYw6+fECFaQXltF9VwTzQXLEtd/vTMo6iBvLinHEm6zUtwoC5W6Mdjs tPPs+gEmfGmWhRx0jCMao1v/QmMt3dDXBIHTpVUl5UFrtRdaM4Kpr2DUgu5sbF0ZRL1m mj2XaK16tfsGb6WndGRmDljrxRrdc2j3EmxWA1GyI6Kgqmfl78ZI22aepz9ULtqpJs0c qRwCMQb9QJkUyEZDnSMHifwzK40mXCXcXsXUWmVbQ929/KgAkWMgbNNxvd2+OZ2/Rldn UORvJbjOPwbrH9EgxfYHbDhiSPx3baybXdfACmR6PMjbR5BrB0m9UYstQOY3L4qr5Buj bVJw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1786187857; x=1786792657; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=3Vav1/IZDRyi5TmIe+ztFcmW7gzOkBU4RfYMZP3HSBU=; b=Izh528ICZtSV6h0cl7ZsNmqF8W182XQ7+THsOn5lDUHM5jOxFbTewgABht4vgTkJbH n5kQEe8yhiik0rydMjiSUC3Y0EmbHSsL5kyal7+FSRnzNMNEaAtv8rT5FTrZAZcAjPs+ KHyzYpE+KzMi6LAAHgstB1iC1XsM8/DVHpckudW4xCw1F4wWppcECOVWtAfvE5G8H2/9 Fu3BC8NEzeX7HBYf0g3S2qVLRd4BenQCxMY5LZCoPGlVxDa7GLAyxE2eQp3aWM5WmZ+3 tmzP4tapbZwPzXBHKREKzn9Vk/K6FkZ9pTKEd2hB42PJSdVnedk4YSJbN1ZVs1/NS7QQ AKJA== X-Forwarded-Encrypted: i=1; AHgh+RoUubdF3DxY2CFqPH73U8TrbVc3zTUJWWoCxwdaf+XG8g8W7IfeF2o5bZoWEdgQZ1KL/HEUmRXyaIELj3c=@vger.kernel.org X-Gm-Message-State: AOJu0YywBl//5mWgRwwhgaMaMLXa8KTjKvgLE3W/W10bNBNFOfpC0Ynl 0QVmpwEuP+Xo0+aa9oXHeXCL4oYu6I3xP702iDe/YLysf2cTVETiKrW7 X-Gm-Gg: AR+sD13Kwv5ZLIoxizF3xE6wjSO4qcdQKhY13V76X2jZWhX6LHNTtcbv7yk/tKbvSmb zeU6uD0k6l4u8FEUYRzray3DeU+PBthhlUmiSz8M9zDMRT2j4iCObULqwy5DcjExIDGVsGaRLhy 0STgMZ5ueb029/yMTsdVXukyb5PQ3NccLQptvBSSTnaEeg70R07cWvI2PVtAF+/x3xXpkcADpOX vfIgb7ZU4kCeYQQ0c1kSdi71RYqn6WHrYL9AO0l8trZVIjEMT66PoL1Djn4uB1HvEGXbM3IAVKO ClwSd9TMZ9k+xdn+vkKSac3KhzPSD1wrqDPvjMwb0+Vez/EJ5dQx2rHAsPjP6RT1PEYKJGbQ368 NggMqZ07zzBOnsiWYr9ALdEkHXWm4Ni7OZ1ygeYd7y8aPdY0nkaXR0AnT20s+R4KraLL724JnsD bNIVUmYulX7eTtjSjjI55jHsM4G1XUo66VTqmoH7qrCr/2Plw3TYdxGryf14gYrmO+pHMItRehz ulZtQ== X-Received: by 2002:a17:90b:448b:b0:38e:524:8797 with SMTP id 98e67ed59e1d1-3909d8c3b9cmr13238521a91.13.1786187857487; Sat, 08 Aug 2026 04:17:37 -0700 (PDT) Received: from SGN-LDSENG.tasernet.com ([2405:4800:5cc3:11a:1ac0:4dff:fe8b:4a69]) by smtp.gmail.com with ESMTPSA id 5a478bee46e88-315bebde308sm18356313eec.20.2026.08.08.04.17.33 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Sat, 08 Aug 2026 04:17:37 -0700 (PDT) From: Cong Nguyen To: Maxime Ripard , Mauro Carvalho Chehab , linux-media@vger.kernel.org Cc: Chen-Yu Tsai , Jernej Skrabec , Samuel Holland , Sakari Ailus , linux-arm-kernel@lists.infradead.org, linux-sunxi@lists.linux.dev, linux-kernel@vger.kernel.org, Cong Nguyen , stable@vger.kernel.org Subject: [PATCH v1 3/3] media: sun4i-csi: add notifier unbind callback to drop the source subdev Date: Sat, 8 Aug 2026 18:17:28 +0700 Message-Id: <61d4901af20a4d2d0f9484328c173bbdfc52ec05.1786184456.git.congnt264@gmail.com> X-Mailer: git-send-email 2.25.1 In-Reply-To: References: Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" sun4i_csi_notify_ops only implements .bound and .complete. When the remote sensor's subdevice goes away (e.g. its module is unloaded), the V4L2 async core unbinds and frees it, but the driver keeps the stale pointer in csi->src_subdev and leaves the video node registered. A subsequent VIDIOC_STREAMON reaches sun4i_csi_start_streaming(), which calls v4l2_subdev_call(csi->src_subdev, video, s_stream, 1) on the freed subdev, resulting in a use-after-free. Add an .unbind callback that unregisters the video device so userspace can no longer start streaming, and clears csi->src_subdev. Unregistering the already-unregistered video device again in sun4i_csi_remove() is harmless (vb2_video_unregister_device() is a no-op when it is not registered). Fixes: 577bbf23b758 ("media: sunxi: Add A10 CSI driver") Cc: stable@vger.kernel.org Assisted-by: Claude:claude-opus-4 Signed-off-by: Cong Nguyen --- .../media/platform/sunxi/sun4i-csi/sun4i_csi.c | 17 +++++++++++++++++ 1 file changed, 17 insertions(+) diff --git a/drivers/media/platform/sunxi/sun4i-csi/sun4i_csi.c b/drivers/m= edia/platform/sunxi/sun4i-csi/sun4i_csi.c index a8711336a754..6610ada1c06d 100644 --- a/drivers/media/platform/sunxi/sun4i-csi/sun4i_csi.c +++ b/drivers/media/platform/sunxi/sun4i-csi/sun4i_csi.c @@ -122,8 +122,25 @@ static int sun4i_csi_notify_complete(struct v4l2_async= _notifier *notifier) return ret; } =20 +static void sun4i_csi_notify_unbind(struct v4l2_async_notifier *notifier, + struct v4l2_subdev *subdev, + struct v4l2_async_connection *asd) +{ + struct sun4i_csi *csi =3D container_of(notifier, struct sun4i_csi, + notifier); + + /* + * The remote subdev is being freed. Tear down the video node so + * userspace can no longer reach sun4i_csi_start_streaming() and + * dereference the now dangling source subdev, and drop the pointer. + */ + vb2_video_unregister_device(&csi->vdev); + csi->src_subdev =3D NULL; +} + static const struct v4l2_async_notifier_operations sun4i_csi_notify_ops = =3D { .bound =3D sun4i_csi_notify_bound, + .unbind =3D sun4i_csi_notify_unbind, .complete =3D sun4i_csi_notify_complete, }; =20 --=20 2.25.1