All of lore.kernel.org
 help / color / mirror / Atom feed
From: Eugen Hristev <ehristev@kernel.org>
To: Balakrishnan Sambath <balakrishnan.s@microchip.com>,
	Mauro Carvalho Chehab <mchehab@kernel.org>
Cc: Hans Verkuil <hverkuil@kernel.org>,
	Sakari Ailus <sakari.ailus@linux.intel.com>,
	linux-media@vger.kernel.org, linux-kernel@vger.kernel.org,
	stable@vger.kernel.org
Subject: Re: [PATCH v5 02/10] media: microchip-isc: take a reference on the parsed endpoints
Date: Tue, 18 Aug 2026 16:37:22 +0300	[thread overview]
Message-ID: <32509367-79c9-49f1-895a-d1ed48ab370b@kernel.org> (raw)
In-Reply-To: <20260817-balki-isc-prefix-fixes-v1-v5-2-2514df336c5e@microchip.com>

On 8/17/26 09:51, Balakrishnan Sambath wrote:
> for_each_endpoint_of_node() drops the reference on the current node as
> it advances. xisc_parse_dt() and isc_parse_dt() store the node in
> subdev_entity->epn and release it later with of_node_put(), but never
> took their own reference, so the stored pointer refers to an
> already-released node. This underflows the refcount and can
> use-after-free, reachable through the camera device tree overlay.
> 
> Take a reference with of_node_get() when storing the node, and drop it
> in microchip_isc_subdev_cleanup() so the entities the bind loop never
> reaches on an early exit do not leak it.
> 
> Fixes: c9aa973884a1 ("media: atmel: atmel-isc: add microchip-xisc driver")
> Fixes: d6701f13bd07 ("media: atmel: Use v4l2_async_notifier_add_fwnode_remote_subdev")
> Cc: stable@vger.kernel.org
> Signed-off-by: Balakrishnan Sambath <balakrishnan.s@microchip.com>
> ---


Reviewed-by: Eugen Hristev <ehristev@kernel.org>


  reply	other threads:[~2026-08-18 13:37 UTC|newest]

Thread overview: 14+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-08-17  6:51 [PATCH v5 00/10] media: microchip-isc: AWB, stream-stop and endpoint-ref fixes Balakrishnan Sambath
2026-08-17  6:51 ` [PATCH v5 01/10] media: microchip-isc: fix awb_mutex and lock lifecycle Balakrishnan Sambath
2026-08-17  6:51 ` [PATCH v5 02/10] media: microchip-isc: take a reference on the parsed endpoints Balakrishnan Sambath
2026-08-18 13:37   ` Eugen Hristev [this message]
2026-08-17  6:52 ` [PATCH v5 03/10] media: microchip-isc: synchronize the IRQ before disabling clocks on stop Balakrishnan Sambath
2026-08-17  6:52 ` [PATCH v5 04/10] media: microchip-isc: disable histogram and flush AWB work on teardown Balakrishnan Sambath
2026-08-18 15:22   ` Eugen Hristev
2026-08-17  6:52 ` [PATCH v5 05/10] media: microchip-isc: do not touch WB registers when not streaming Balakrishnan Sambath
2026-08-17  6:52 ` [PATCH v5 06/10] media: microchip-isc: store the unshifted PFE_CFG0 BPS value Balakrishnan Sambath
2026-08-17  6:52 ` [PATCH v5 07/10] media: microchip-isc: fix ISC_PFG_CFG0_BPS macro name typo Balakrishnan Sambath
2026-08-17  6:52 ` [PATCH v5 08/10] media: microchip-isc: fix PM runtime leak in AWB work handler Balakrishnan Sambath
2026-08-17  6:52 ` [PATCH v5 09/10] media: microchip-isc: fix SBGGR10 Bayer pattern Balakrishnan Sambath
2026-08-17  6:52 ` [PATCH v5 10/10] media: microchip-isc: fix WB offset and gain register field masking Balakrishnan Sambath
2026-08-18 15:24 ` [PATCH v5 00/10] media: microchip-isc: AWB, stream-stop and endpoint-ref fixes Eugen Hristev

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=32509367-79c9-49f1-895a-d1ed48ab370b@kernel.org \
    --to=ehristev@kernel.org \
    --cc=balakrishnan.s@microchip.com \
    --cc=hverkuil@kernel.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=linux-media@vger.kernel.org \
    --cc=mchehab@kernel.org \
    --cc=sakari.ailus@linux.intel.com \
    --cc=stable@vger.kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.