All of lore.kernel.org
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Dumitru Ceclan" <dumitru.ceclan@analog.com>
Cc: robh@kernel.org, devicetree@vger.kernel.org,
	media-ci@linuxtv.org, conor+dt@kernel.org
Subject: Re: [PATCH v15 11/22] dt-bindings: media: i2c: max96714: add support for MAX96714R
Date: Fri, 07 Aug 2026 13:26:35 +0000	[thread overview]
Message-ID: <20260807132636.CD5D11F000E9@smtp.kernel.org> (raw)
In-Reply-To: <20260807-gmsl2-3_serdes-v15-11-7212e9e5156a@analog.com>

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:

Pre-existing issues:
- [High] Unchecked `v4l2_subdev_state_get_format` dereference in `max96714_apply_patgen_timing` leading to NULL pointer dereference and kernel oops.
--

--- Patch [11]: [PATCH v15 11/22] dt-bindings: media: i2c: max96714: add support for MAX96714R ---
commit c4bf3be89835d23de9ff33f00865d0fa24fed633
Author: Cosmin Tanislav <demonsingur@gmail.com>

dt-bindings: media: i2c: max96714: add support for MAX96714R

This commit adds device tree binding support for the MAX96714R, a lower
capability variant of the MAX96714. It operates at a fixed 3Gbps rate in
the forward direction.

> diff --git a/Documentation/devicetree/bindings/media/i2c/maxim,max96714.yaml b/Documentation/devicetree/bindings/media/i2c/maxim,max96714.yaml
> index 3ace50e11921b..ec6a91c4a51c0 100644
> --- a/Documentation/devicetree/bindings/media/i2c/maxim,max96714.yaml
> +++ b/Documentation/devicetree/bindings/media/i2c/maxim,max96714.yaml
[ ... ]
> @@ -31,6 +33,7 @@ properties:
>        - items:
>            - enum:
>                - maxim,max96714
> +              - maxim,max96714r
>            - const: maxim,max96714f
>  
>    reg:

[Severity: High]
This is a pre-existing issue, but while looking at the corresponding driver
for this device, I noticed a potential NULL pointer dereference that could
be triggered by userspace:

drivers/media/i2c/max96714.c:max96714_enable_streams() {
    ...
	if (!priv->enabled_source_streams)
		max96714_enable_tx_port(priv);

	ret = max96714_apply_patgen(priv, state);
    ...
}

If userspace sets a custom routing table via VIDIOC_SUBDEV_S_ROUTING with a
source stream greater than 0 (and no stream 0), sets a test pattern via
VIDIOC_SUBDEV_S_CTRL, and enables streams for that stream,
max96714_apply_patgen() will be called unconditionally.

This in turn invokes max96714_apply_patgen_timing(), which attempts to fetch
the format for the source pad:

drivers/media/i2c/max96714.c:max96714_apply_patgen_timing() {
    ...
	struct v4l2_mbus_framefmt *fmt =
		v4l2_subdev_state_get_format(state, MAX96714_PAD_SOURCE);
	const u32 h_active = fmt->width;
    ...
}

Because v4l2_subdev_state_get_format() implicitly defaults to stream 0, could
the lookup return NULL since stream 0 doesn't exist in the user-configured
state in this scenario, resulting in a kernel oops when dereferencing
fmt->width?

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260807-gmsl2-3_serdes-v15-0-7212e9e5156a@analog.com?part=11

  reply	other threads:[~2026-08-07 13:26 UTC|newest]

Thread overview: 56+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-08-07 13:02 [PATCH v15 00/22] media: i2c: add Maxim GMSL2/3 serializer and deserializer drivers Dumitru Ceclan via B4 Relay
2026-08-07 13:02 ` Dumitru Ceclan
2026-08-07 13:02 ` [PATCH v15 01/22] media: mc: Add INTERNAL pad flag Dumitru Ceclan via B4 Relay
2026-08-07 13:02   ` Dumitru Ceclan
2026-08-07 13:02 ` [PATCH v15 02/22] dt-bindings: media: i2c: max96717: add support for I2C ATR Dumitru Ceclan via B4 Relay
2026-08-07 13:02   ` Dumitru Ceclan
2026-08-07 13:17   ` sashiko-bot
2026-08-07 13:02 ` [PATCH v15 03/22] dt-bindings: media: i2c: max96717: add support for pinctrl/pinconf Dumitru Ceclan via B4 Relay
2026-08-07 13:02   ` Dumitru Ceclan
2026-08-07 13:02 ` [PATCH v15 04/22] dt-bindings: media: i2c: max96717: add support for MAX9295A Dumitru Ceclan via B4 Relay
2026-08-07 13:02   ` Dumitru Ceclan
2026-08-07 13:02 ` [PATCH v15 05/22] dt-bindings: media: i2c: max96717: add support for MAX96793 Dumitru Ceclan via B4 Relay
2026-08-07 13:02   ` Dumitru Ceclan
2026-08-07 13:02 ` [PATCH v15 06/22] dt-bindings: media: i2c: max96712: use pattern properties for ports Dumitru Ceclan via B4 Relay
2026-08-07 13:02   ` Dumitru Ceclan
2026-08-07 13:02 ` [PATCH v15 07/22] dt-bindings: media: i2c: max96712: add support for I2C ATR Dumitru Ceclan via B4 Relay
2026-08-07 13:02   ` Dumitru Ceclan
2026-08-07 13:32   ` sashiko-bot
2026-08-07 13:02 ` [PATCH v15 08/22] dt-bindings: media: i2c: max96712: add support for POC supplies Dumitru Ceclan via B4 Relay
2026-08-07 13:02   ` Dumitru Ceclan
2026-08-07 13:02 ` [PATCH v15 09/22] dt-bindings: media: i2c: max96712: add support for MAX96724F/R Dumitru Ceclan via B4 Relay
2026-08-07 13:02   ` Dumitru Ceclan
2026-08-07 13:02 ` [PATCH v15 10/22] dt-bindings: media: i2c: max96712: add control-channel-port property Dumitru Ceclan via B4 Relay
2026-08-07 13:02   ` Dumitru Ceclan
2026-08-07 13:02 ` [PATCH v15 11/22] dt-bindings: media: i2c: max96714: add support for MAX96714R Dumitru Ceclan via B4 Relay
2026-08-07 13:02   ` Dumitru Ceclan
2026-08-07 13:26   ` sashiko-bot [this message]
2026-08-07 13:02 ` [PATCH v15 12/22] dt-bindings: media: i2c: add MAX9296A, MAX96716A, MAX96792A Dumitru Ceclan via B4 Relay
2026-08-07 13:02   ` Dumitru Ceclan
2026-08-07 13:38   ` sashiko-bot
2026-08-07 13:02 ` [PATCH v15 13/22] media: i2c: add Maxim GMSL2/3 serializer and deserializer framework Dumitru Ceclan via B4 Relay
2026-08-07 13:02   ` Dumitru Ceclan
2026-08-07 13:36   ` sashiko-bot
2026-08-07 13:02 ` [PATCH v15 14/22] media: i2c: add Maxim GMSL2/3 serializer framework Dumitru Ceclan via B4 Relay
2026-08-07 13:02   ` Dumitru Ceclan
2026-08-07 13:42   ` sashiko-bot
2026-08-07 13:02 ` [PATCH v15 15/22] media: i2c: add Maxim GMSL2/3 deserializer framework Dumitru Ceclan via B4 Relay
2026-08-07 13:02   ` Dumitru Ceclan
2026-08-07 13:42   ` sashiko-bot
2026-08-07 13:02 ` [PATCH v15 16/22] media: i2c: maxim-serdes: add MAX96717 driver Dumitru Ceclan via B4 Relay
2026-08-07 13:02   ` Dumitru Ceclan
2026-08-07 13:51   ` sashiko-bot
2026-08-07 13:02 ` [PATCH v15 17/22] media: i2c: maxim-serdes: add MAX96724 driver Dumitru Ceclan via B4 Relay
2026-08-07 13:02   ` Dumitru Ceclan
2026-08-07 13:02 ` [PATCH v15 18/22] media: i2c: maxim-serdes: add MAX9296A driver Dumitru Ceclan via B4 Relay
2026-08-07 13:02   ` Dumitru Ceclan
2026-08-07 13:55   ` sashiko-bot
2026-08-07 13:02 ` [PATCH v15 19/22] arm64: defconfig: disable deprecated MAX96712 driver Dumitru Ceclan via B4 Relay
2026-08-07 13:02   ` Dumitru Ceclan
2026-08-07 13:47   ` sashiko-bot
2026-08-07 13:02 ` [PATCH v15 20/22] staging: media: remove " Dumitru Ceclan via B4 Relay
2026-08-07 13:02   ` Dumitru Ceclan
2026-08-07 13:02 ` [PATCH v15 21/22] media: i2c: remove MAX96717 driver Dumitru Ceclan via B4 Relay
2026-08-07 13:02   ` Dumitru Ceclan
2026-08-07 13:02 ` [PATCH v15 22/22] media: i2c: remove MAX96714 driver Dumitru Ceclan via B4 Relay
2026-08-07 13:02   ` Dumitru Ceclan

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260807132636.CD5D11F000E9@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=conor+dt@kernel.org \
    --cc=devicetree@vger.kernel.org \
    --cc=dumitru.ceclan@analog.com \
    --cc=media-ci@linuxtv.org \
    --cc=robh@kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.