From: "Shengzhuo Wei" <me@cherr.cc>
To: "Mirela Rabulea" <mirela.rabulea@nxp.com>,
"Mauro Carvalho Chehab" <mchehab@kernel.org>,
"Frank Li" <Frank.Li@nxp.com>,
"Sascha Hauer" <s.hauer@pengutronix.de>,
"Pengutronix Kernel Team" <kernel@pengutronix.de>,
"Fabio Estevam" <festevam@gmail.com>,
"Hans Verkuil" <hverkuil@kernel.org>,
"Ming Qian" <ming.qian@nxp.com>,
"Nicolas Dufresne" <nicolas.dufresne@collabora.com>,
"Benjamin Gaignard" <benjamin.gaignard@collabora.com>,
"Philipp Zabel" <p.zabel@pengutronix.de>,
"Ezequiel Garcia" <ezequiel@vanguardiasur.com.ar>,
"Bin Liu" <bin.liu@mediatek.com>,
"Matthias Brugger" <matthias.bgg@gmail.com>,
"AngeloGioacchino Del Regno"
<angelogioacchino.delregno@collabora.com>,
"irui wang" <irui.wang@mediatek.com>,
"kyrie wu" <kyrie.wu@mediatek.com>
Cc: <imx@lists.linux.dev>, <linux-media@vger.kernel.org>,
<linux-arm-kernel@lists.infradead.org>, <stable@vger.kernel.org>,
"Shengzhuo Wei" <me@cherr.cc>
Subject: [PATCH 0/3] media: cancel timeout delayed work before freeing its owner
Date: Tue, 25 Aug 2026 03:34:29 +0800 [thread overview]
Message-ID: <20260825-media-timeout-work-v1-0-ebfebbeb6c31@cherr.cc> (raw)
Three m2m codec drivers arm a per-job timeout delayed work on the
system workqueue and only cancel it on the job-completion path. If the
hardware never completes the job, the release/remove path frees the
object the timeout callback dereferences (via container_of or through
the m2m device) with the work still pending -- a use-after-free when
the timer expires.
All three are the same missed-twins class as the recent mtk-jpeg
jpeg_work release fix and the host1x timeout-worker fix. In each case
the fix is a single cancel_delayed_work_sync() placed before the object
is freed:
- mxc-jpeg: cancel ctx->task_timer in mxc_jpeg_release() before
kfree(ctx); the timer is otherwise only cancelled in the job IRQ.
- hantro: cancel vpu->watchdog_work in hantro_remove() before
v4l2_m2m_put() frees the m2m device the watchdog dereferences.
- mtk-jpeg: cancel jpeg->job_timeout_work in mtk_jpeg_remove()
before v4l2_m2m_release(); ctx->jpeg_work in the same driver got
the equivalent fix earlier, the device-level work was missed.
Patches are independent of each other.
---
Shengzhuo Wei (3):
media: nxp: imx-jpeg: cancel task_timer before freeing ctx
media: verisilicon: hantro: cancel watchdog work before m2m release
media: mediatek: jpeg: cancel job timeout work before m2m release
drivers/media/platform/mediatek/jpeg/mtk_jpeg_core.c | 1 +
drivers/media/platform/nxp/imx-jpeg/mxc-jpeg.c | 2 ++
drivers/media/platform/verisilicon/hantro_drv.c | 1 +
3 files changed, 4 insertions(+)
---
base-commit: 075b74841bd0065a3bda3440873c747938e69b68
change-id: 20260825-media-timeout-work-1cef7720c63b
Best regards,
--
Shengzhuo Wei <me@cherr.cc>
next reply other threads:[~2026-08-24 19:34 UTC|newest]
Thread overview: 10+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-24 19:34 Shengzhuo Wei [this message]
2026-08-24 19:34 ` [PATCH 1/3] media: nxp: imx-jpeg: cancel task_timer before freeing ctx Shengzhuo Wei
2026-08-24 19:48 ` sashiko-bot
2026-08-25 1:56 ` Ming Qian(OSS)
2026-08-25 3:39 ` Shengzhuo Wei
2026-08-24 19:34 ` [PATCH 2/3] media: verisilicon: hantro: cancel watchdog work before m2m release Shengzhuo Wei
2026-08-24 19:49 ` sashiko-bot
2026-09-14 19:35 ` Frank Li
2026-08-24 19:34 ` [PATCH 3/3] media: mediatek: jpeg: cancel job timeout " Shengzhuo Wei
2026-08-24 19:49 ` sashiko-bot
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260825-media-timeout-work-v1-0-ebfebbeb6c31@cherr.cc \
--to=me@cherr.cc \
--cc=Frank.Li@nxp.com \
--cc=angelogioacchino.delregno@collabora.com \
--cc=benjamin.gaignard@collabora.com \
--cc=bin.liu@mediatek.com \
--cc=ezequiel@vanguardiasur.com.ar \
--cc=festevam@gmail.com \
--cc=hverkuil@kernel.org \
--cc=imx@lists.linux.dev \
--cc=irui.wang@mediatek.com \
--cc=kernel@pengutronix.de \
--cc=kyrie.wu@mediatek.com \
--cc=linux-arm-kernel@lists.infradead.org \
--cc=linux-media@vger.kernel.org \
--cc=matthias.bgg@gmail.com \
--cc=mchehab@kernel.org \
--cc=ming.qian@nxp.com \
--cc=mirela.rabulea@nxp.com \
--cc=nicolas.dufresne@collabora.com \
--cc=p.zabel@pengutronix.de \
--cc=s.hauer@pengutronix.de \
--cc=stable@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.