From: sashiko-bot@kernel.org
To: "Karl Mehltretter" <kmehltretter@gmail.com>
Cc: dmitry.torokhov@gmail.com, linux-input@vger.kernel.org,
media-ci@linuxtv.org, dri-devel@lists.freedesktop.org,
linux-usb@vger.kernel.org
Subject: Re: [RFT PATCH] Input: sur40 - fix DMA handling in video capture
Date: Wed, 07 Oct 2026 05:58:41 +0000 [thread overview]
Message-ID: <sashiko-outbox-162655@kernel.org> (raw)
In-Reply-To: <20261007054430.40155-1-kmehltretter@gmail.com>
Thank you for your contribution! Sashiko AI review found 2 potential issue(s) to consider:
- [High] media: use-after-free of sur40 state on disconnect when V4L2 fd is open
- [Medium] usb: invalid GFP flags (0) passed to usb_sg_init in sleepable context
--
commit f65bffa4ada0f7963abf3d4813cdc5924218586d
Author: Karl Mehltretter <kmehltretter@gmail.com>
Input: sur40 - fix DMA handling in video capture
This commit fixes video capture failures by transitioning from vb2_dma_sg to
vb2_vmalloc. It receives each frame into a driver-owned, page-backed
scatterlist and copies it through the vb2 mapping, while synchronizing
CPU writes to imported dma-bufs.
> diff --git a/drivers/input/touchscreen/sur40.c b/drivers/input/touchscreen/sur40.c
> index 09d8c5f8d09fc..72e3f0fa1f4cb 100644
> --- a/drivers/input/touchscreen/sur40.c
> +++ b/drivers/input/touchscreen/sur40.c
[ ... ]
> @@ -579,11 +584,17 @@ static void sur40_process_video(struct sur40_state *sur40)
>
> dev_dbg(sur40->dev, "header acquired\n");
>
> - sgt = vb2_dma_sg_plane_desc(&new_buf->vb.vb2_buf, 0);
> + vaddr = vb2_plane_vaddr(&new_buf->vb.vb2_buf, 0);
> + if (!vaddr)
> + goto err_poll;
>
> + /*
> + * vb2_plane_vaddr() may return a vmalloc or vmap address. Receive
> + * into page-backed memory so the USB core can map it for DMA.
> + */
> result = usb_sg_init(&sgr, sur40->usbdev,
> usb_rcvbulkpipe(sur40->usbdev, VIDEO_ENDPOINT), 0,
> - sgt->sgl, sgt->nents, sur40->pix_fmt.sizeimage, 0);
> + sur40->video_sgl, sur40->video_nents, size, 0);
[Severity: Medium]
Is it correct to pass 0 as the mem_flags argument to usb_sg_init() here?
Passing 0 implies no reclaim and no wait (equivalent to GFP_NOWAIT), which
restricts usb_alloc_urb() and internal kmalloc operations. This can increase
the probability of spurious -ENOMEM failures under memory pressure.
Since sur40_process_video() executes inside the input poller worker thread
(sur40_poll) which runs in process context and is allowed to sleep (it already
calls usb_bulk_msg() and usb_sg_wait()), shouldn't this use GFP_KERNEL instead?
[ ... ]
> @@ -831,6 +883,7 @@ static void sur40_disconnect(struct usb_interface *interface)
> video_unregister_device(&sur40->vdev);
> v4l2_device_unregister(&sur40->v4l2);
>
> + sgl_free(sur40->video_sgl);
> kfree(sur40->bulk_in_buffer);
> kfree(sur40);
[Severity: High]
Could freeing the sur40 structure unconditionally here lead to a use-after-free
if userspace holds the V4L2 file descriptor open during device unplug?
When the application later closes the file, the V4L2 core invokes
vb2_fop_release(), which dereferences vdev->queue and attempts to acquire
vdev->queue->lock. Because vdev is embedded in the freed sur40 structure,
this results in a direct use-after-free.
While the commit message acknowledges this bug and defers to a pending patch
series for the disconnect fixes, the current patch adds new cleanup to this
vulnerable path. The referenced series is absent from the provided tree,
leaving the vulnerability exposed.
--
Sashiko AI review · https://sashiko.dev/#/patchset/20261007054430.40155-1-kmehltretter@gmail.com?part=1
next prev parent reply other threads:[~2026-10-07 5:58 UTC|newest]
Thread overview: 4+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-10-07 5:44 [RFT PATCH] Input: sur40 - fix DMA handling in video capture Karl Mehltretter
2026-10-07 5:58 ` sashiko-bot [this message]
2026-10-08 4:16 ` kernel test robot
2026-10-09 10:35 ` kernel test robot
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=sashiko-outbox-162655@kernel.org \
--to=sashiko-bot@kernel.org \
--cc=dmitry.torokhov@gmail.com \
--cc=dri-devel@lists.freedesktop.org \
--cc=kmehltretter@gmail.com \
--cc=linux-input@vger.kernel.org \
--cc=linux-usb@vger.kernel.org \
--cc=media-ci@linuxtv.org \
--cc=sashiko-reviews@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).