* [syzbot] [media?] memory leak in dvb_register_frontend
@ 2026-08-24 3:35 syzbot
2026-08-24 6:59 ` Forwarded: [PATCH] media: vidtv: fix frontend reference leak on unbind syzbot
0 siblings, 1 reply; 3+ messages in thread
From: syzbot @ 2026-08-24 3:35 UTC (permalink / raw)
To: linux-kernel, linux-media, mchehab, syzkaller-bugs
Hello,
syzbot found the following issue on:
HEAD commit: 26260251022f Merge tag 'livepatching-for-7.3' of git://git..
git tree: upstream
console output: https://syzkaller.appspot.com/x/log.txt?x=179ac415580000
kernel config: https://syzkaller.appspot.com/x/.config?x=6c1b5958b2d1207f
dashboard link: https://syzkaller.appspot.com/bug?extid=32f018fd65e799f79ae0
compiler: gcc (Debian 14.2.0-19) 14.2.0, GNU ld (GNU Binutils for Debian) 2.44
syz repro: https://syzkaller.appspot.com/x/repro.syz?x=15f99549580000
Downloadable assets:
disk image: https://storage.googleapis.com/syzbot-assets/0f75e7622b1f/disk-26260251.raw.xz
vmlinux: https://storage.googleapis.com/syzbot-assets/2bbff9fd7b60/vmlinux-26260251.xz
kernel image: https://storage.googleapis.com/syzbot-assets/95d733004907/bzImage-26260251.xz
IMPORTANT: if you fix the issue, please add the following tag to the commit:
Reported-by: syzbot+32f018fd65e799f79ae0@syzkaller.appspotmail.com
BUG: memory leak
unreferenced object 0xffff888104d8ec00 (size 1024):
comm "swapper/0", pid 1, jiffies 4294937925
hex dump (first 32 bytes):
00 cf b9 05 81 88 ff ff 00 00 00 00 00 00 00 00 ................
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
backtrace (crc 284558ee):
kmemleak_alloc_recursive include/linux/kmemleak.h:44 [inline]
slab_post_alloc_hook mm/slub.c:4599 [inline]
slab_alloc_node mm/slub.c:4919 [inline]
__kmalloc_cache_noprof+0x359/0x440 mm/slub.c:5480
_kmalloc_noprof include/linux/slab.h:988 [inline]
_kzalloc_noprof include/linux/slab.h:1309 [inline]
dvb_register_frontend+0xad/0x2b0 drivers/media/dvb-core/dvb_frontend.c:3047
vidtv_bridge_dvb_init drivers/media/test-drivers/vidtv/vidtv_bridge.c:438 [inline]
vidtv_bridge_probe+0x1f6/0x420 drivers/media/test-drivers/vidtv/vidtv_bridge.c:510
platform_probe+0x86/0xf0 drivers/base/platform.c:1507
call_driver_probe drivers/base/dd.c:628 [inline]
really_probe+0x12f/0x3a0 drivers/base/dd.c:706
__driver_probe_device+0xe9/0x1a0 drivers/base/dd.c:868
driver_probe_device+0x28/0xf0 drivers/base/dd.c:898
__driver_attach drivers/base/dd.c:1292 [inline]
__driver_attach+0x10a/0x200 drivers/base/dd.c:1232
bus_for_each_dev+0xb8/0x120 drivers/base/bus.c:383
bus_add_driver+0x122/0x280 drivers/base/bus.c:763
driver_register+0xb1/0x140 drivers/base/driver.c:174
vidtv_bridge_init+0x52/0x80 drivers/media/test-drivers/vidtv/vidtv_bridge.c:602
do_one_initcall+0x74/0x430 init/main.c:1353
do_initcall_level init/main.c:1415 [inline]
do_initcalls init/main.c:1431 [inline]
do_basic_setup init/main.c:1451 [inline]
kernel_init_freeable+0x2a9/0x340 init/main.c:1666
kernel_init+0x20/0x1d0 init/main.c:1556
ret_from_fork+0x219/0x490 arch/x86/kernel/process.c:158
BUG: memory leak
unreferenced object 0xffff888105b9cf00 (size 192):
comm "swapper/0", pid 1, jiffies 4294937926
hex dump (first 32 bytes):
00 01 00 00 00 00 ad de 22 01 00 00 00 00 ad de ........".......
01 00 00 00 00 00 00 00 00 3a 95 03 81 88 ff ff .........:......
backtrace (crc 9bd60cfd):
kmemleak_alloc_recursive include/linux/kmemleak.h:44 [inline]
slab_post_alloc_hook mm/slub.c:4599 [inline]
slab_alloc_node mm/slub.c:4919 [inline]
__kmalloc_cache_noprof+0x359/0x440 mm/slub.c:5480
_kmalloc_noprof include/linux/slab.h:988 [inline]
_kzalloc_noprof include/linux/slab.h:1309 [inline]
dvb_register_device+0x117/0xac0 drivers/media/dvb-core/dvbdev.c:472
dvb_register_frontend+0x1d0/0x2b0 drivers/media/dvb-core/dvb_frontend.c:3074
vidtv_bridge_dvb_init drivers/media/test-drivers/vidtv/vidtv_bridge.c:438 [inline]
vidtv_bridge_probe+0x1f6/0x420 drivers/media/test-drivers/vidtv/vidtv_bridge.c:510
platform_probe+0x86/0xf0 drivers/base/platform.c:1507
call_driver_probe drivers/base/dd.c:628 [inline]
really_probe+0x12f/0x3a0 drivers/base/dd.c:706
__driver_probe_device+0xe9/0x1a0 drivers/base/dd.c:868
driver_probe_device+0x28/0xf0 drivers/base/dd.c:898
__driver_attach drivers/base/dd.c:1292 [inline]
__driver_attach+0x10a/0x200 drivers/base/dd.c:1232
bus_for_each_dev+0xb8/0x120 drivers/base/bus.c:383
bus_add_driver+0x122/0x280 drivers/base/bus.c:763
driver_register+0xb1/0x140 drivers/base/driver.c:174
vidtv_bridge_init+0x52/0x80 drivers/media/test-drivers/vidtv/vidtv_bridge.c:602
do_one_initcall+0x74/0x430 init/main.c:1353
do_initcall_level init/main.c:1415 [inline]
do_initcalls init/main.c:1431 [inline]
do_basic_setup init/main.c:1451 [inline]
kernel_init_freeable+0x2a9/0x340 init/main.c:1666
kernel_init+0x20/0x1d0 init/main.c:1556
connection error: failed to recv *flatrpc.ExecutorMessageRawT: read tcp 127.0.0.1:35893->127.0.0.1:38908: read: connection reset by peer
---
This report is generated by a bot. It may contain errors.
See https://goo.gl/tpsmEJ for more information about syzbot.
syzbot engineers can be reached at syzkaller@googlegroups.com.
syzbot will keep track of this issue. See:
https://goo.gl/tpsmEJ#status for how to communicate with syzbot.
If the report is already addressed, let syzbot know by replying with:
#syz fix: exact-commit-title
If you want syzbot to run the reproducer, reply with:
#syz test: git://repo/address.git branch-or-commit-hash
If you attach or paste a git patch, syzbot will apply it before testing.
If you want to overwrite report's subsystems, reply with:
#syz set subsystems: new-subsystem
(See the list of subsystem names on the web dashboard)
If the report is a duplicate of another one, reply with:
#syz dup: exact-subject-of-another-report
If you want to undo deduplication, reply with:
#syz undup
^ permalink raw reply [flat|nested] 3+ messages in thread
* Forwarded: [PATCH] media: vidtv: fix frontend reference leak on unbind
2026-08-24 3:35 [syzbot] [media?] memory leak in dvb_register_frontend syzbot
@ 2026-08-24 6:59 ` syzbot
0 siblings, 0 replies; 3+ messages in thread
From: syzbot @ 2026-08-24 6:59 UTC (permalink / raw)
To: linux-kernel, syzkaller-bugs
For archival purposes, forwarding an incoming command email to
linux-kernel@vger.kernel.org, syzkaller-bugs@googlegroups.com.
***
Subject: [PATCH] media: vidtv: fix frontend reference leak on unbind
Author: piyushpatle228@gmail.com
dvb_register_frontend() keeps two references to the frontend. One is
released by dvb_unregister_frontend(), and the other by
dvb_frontend_detach(). vidtv only called dvb_unregister_frontend(), so
the second reference was never released. As a result,
__dvb_frontend_free() was never called, leaking the frontend private
data and its struct dvb_device.
The detach call was removed by commit 63101b756893 ("media: vidtv: fix
driver unbind/remove") because it caused an OOPS. The demod .release
callback freed vidtv_demod_state, and the I2C remove callbacks then
accessed the freed state.
That commit also removed those accesses from the I2C remove callbacks.
Restore the detach call, but remove the demod .release callback.
vidtv_demod_state is owned by the I2C client and is already freed by
vidtv_demod_i2c_remove(), so the frontend detach path should not free
it.
Tested with kmemleak and KASAN over 10 bind/unbind cycles. The reported
frontend and dvb_device leaks were present before the fix and were gone
after it, with no KASAN reports.
Reported-by: syzbot+32f018fd65e799f79ae0@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=32f018fd65e799f79ae0
Fixes: 63101b756893 ("media: vidtv: fix driver unbind/remove")
Signed-off-by: Piyush Patle <piyushpatle228@gmail.com>
---
#syz test: git://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git master
drivers/media/test-drivers/vidtv/vidtv_bridge.c | 2 ++
drivers/media/test-drivers/vidtv/vidtv_demod.c | 9 ---------
2 files changed, 2 insertions(+), 9 deletions(-)
diff --git a/drivers/media/test-drivers/vidtv/vidtv_bridge.c b/drivers/media/test-drivers/vidtv/vidtv_bridge.c
index fd69b4ee16f4..9887860b0198 100644
--- a/drivers/media/test-drivers/vidtv/vidtv_bridge.c
+++ b/drivers/media/test-drivers/vidtv/vidtv_bridge.c
@@ -474,6 +474,7 @@ static int vidtv_bridge_dvb_init(struct vidtv_dvb *dvb)
fail_demod_probe:
for (i = i - 1; i >= 0; --i) {
dvb_unregister_frontend(dvb->fe[i]);
+ dvb_frontend_detach(dvb->fe[i]);
fail_fe:
dvb_module_release(dvb->i2c_client_tuner[i]);
fail_tuner_probe:
@@ -552,6 +553,7 @@ static void vidtv_bridge_remove(struct platform_device *pdev)
for (i = 0; i < NUM_FE; ++i) {
dvb_unregister_frontend(dvb->fe[i]);
+ dvb_frontend_detach(dvb->fe[i]);
dvb_module_release(dvb->i2c_client_tuner[i]);
dvb_module_release(dvb->i2c_client_demod[i]);
}
diff --git a/drivers/media/test-drivers/vidtv/vidtv_demod.c b/drivers/media/test-drivers/vidtv/vidtv_demod.c
index 6e5fe402976b..3aa586004638 100644
--- a/drivers/media/test-drivers/vidtv/vidtv_demod.c
+++ b/drivers/media/test-drivers/vidtv/vidtv_demod.c
@@ -343,13 +343,6 @@ static int vidtv_diseqc_send_burst(struct dvb_frontend *fe,
return 0;
}
-static void vidtv_demod_release(struct dvb_frontend *fe)
-{
- struct vidtv_demod_state *state = fe->demodulator_priv;
-
- kfree(state);
-}
-
static const struct dvb_frontend_ops vidtv_demod_ops = {
.delsys = {
SYS_DVBT,
@@ -390,8 +383,6 @@ static const struct dvb_frontend_ops vidtv_demod_ops = {
FE_CAN_HIERARCHY_AUTO,
},
- .release = vidtv_demod_release,
-
.set_frontend = vidtv_demod_set_frontend,
.get_frontend = vidtv_demod_get_frontend,
--
2.43.0
^ permalink raw reply related [flat|nested] 3+ messages in thread
* Re: [syzbot] [media?] memory leak in dvb_register_frontend
[not found] <20260824065907.429639-1-piyushpatle228@gmail.com>
@ 2026-08-24 8:14 ` syzbot
0 siblings, 0 replies; 3+ messages in thread
From: syzbot @ 2026-08-24 8:14 UTC (permalink / raw)
To: linux-kernel, piyushpatle228, syzkaller-bugs
Hello,
syzbot has tested the proposed patch and the reproducer did not trigger any issue:
Reported-by: syzbot+32f018fd65e799f79ae0@syzkaller.appspotmail.com
Tested-by: syzbot+32f018fd65e799f79ae0@syzkaller.appspotmail.com
Tested on:
commit: 0a0d1d55 Merge tag 'scftorture.2026.08.18a' of git://g..
git tree: upstream
console output: https://syzkaller.appspot.com/x/log.txt?x=13b84979580000
kernel config: https://syzkaller.appspot.com/x/.config?x=e9cd457924935cdf
dashboard link: https://syzkaller.appspot.com/bug?extid=32f018fd65e799f79ae0
compiler: gcc (Debian 14.2.0-19) 14.2.0, GNU ld (GNU Binutils for Debian) 2.44
patch: https://syzkaller.appspot.com/x/patch.diff?x=11be2625580000
Note: testing is done by a robot and is best-effort only.
^ permalink raw reply [flat|nested] 3+ messages in thread
end of thread, other threads:[~2026-08-24 8:14 UTC | newest]
Thread overview: 3+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-08-24 3:35 [syzbot] [media?] memory leak in dvb_register_frontend syzbot
2026-08-24 6:59 ` Forwarded: [PATCH] media: vidtv: fix frontend reference leak on unbind syzbot
[not found] <20260824065907.429639-1-piyushpatle228@gmail.com>
2026-08-24 8:14 ` [syzbot] [media?] memory leak in dvb_register_frontend syzbot
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox