Linux Media Controller development
 help / color / mirror / Atom feed
* [PATCH] media: ipu6: Fix bus device use-after-free
@ 2026-09-24 12:06 Antti Laakso
  2026-09-24 12:18 ` Sakari Ailus
  0 siblings, 1 reply; 2+ messages in thread
From: Antti Laakso @ 2026-09-24 12:06 UTC (permalink / raw)
  To: linux-media, sakari.ailus, sarang.sapre, error27

The ipu6_bus_del_devices() will uninitialize and free bus devices and
dereferencing isp->psys and isp->isys will lead to use-after-free.

While at it, remove unnecessary checks for isp->isys/psys.

Reported-by: Dan Carpenter <error27@gmail.com>
Fixes: 69ebb1bfc865 ("media: ipu6: Move isys fw mapping to pci_probe")
Signed-off-by: Antti Laakso <antti.laakso@linux.intel.com>
---
 drivers/media/pci/intel/ipu6/ipu6.c | 16 +++++++---------
 1 file changed, 7 insertions(+), 9 deletions(-)

diff --git a/drivers/media/pci/intel/ipu6/ipu6.c b/drivers/media/pci/intel/ipu6/ipu6.c
index 43d951735f72..b9a79181d736 100644
--- a/drivers/media/pci/intel/ipu6/ipu6.c
+++ b/drivers/media/pci/intel/ipu6/ipu6.c
@@ -836,6 +836,8 @@ static int ipu6_pci_probe(struct pci_dev *pdev, const struct pci_device_id *id)
 static void ipu6_pci_remove(struct pci_dev *pdev)
 {
 	struct ipu6_device *isp = pci_get_drvdata(pdev);
+	struct ipu6_mmu *isys_mmu = isp->isys->mmu;
+	struct ipu6_mmu *psys_mmu = isp->psys->mmu;
 	unsigned long dir;
 
 	devm_free_irq(&pdev->dev, pdev->irq, isp);
@@ -844,11 +846,9 @@ static void ipu6_pci_remove(struct pci_dev *pdev)
 	ipu6_cpd_free_pkg_dir(isp->psys);
 	ipu6_unmap_fw_region(isp->psys, dir);
 
-	if (isp->isys) {
-		ipu6_cpd_free_pkg_dir(isp->isys);
-		if (isp->isys->fw_sgt.nents)
-			ipu6_unmap_fw_region(isp->isys, dir);
-	}
+	ipu6_cpd_free_pkg_dir(isp->isys);
+	if (isp->isys->fw_sgt.nents)
+		ipu6_unmap_fw_region(isp->isys, dir);
 
 	vfree(isp->fw_code_region);
 	isp->fw_code_region = NULL;
@@ -862,10 +862,8 @@ static void ipu6_pci_remove(struct pci_dev *pdev)
 
 	release_firmware(isp->cpd_fw);
 
-	if (isp->psys)
-		ipu6_mmu_cleanup(isp->psys->mmu);
-	if (isp->isys)
-		ipu6_mmu_cleanup(isp->isys->mmu);
+	ipu6_mmu_cleanup(psys_mmu);
+	ipu6_mmu_cleanup(isys_mmu);
 }
 
 static void ipu6_pci_reset_prepare(struct pci_dev *pdev)
-- 
2.55.0


^ permalink raw reply related	[flat|nested] 2+ messages in thread

end of thread, other threads:[~2026-09-24 12:18 UTC | newest]

Thread overview: 2+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-24 12:06 [PATCH] media: ipu6: Fix bus device use-after-free Antti Laakso
2026-09-24 12:18 ` Sakari Ailus

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox