]> git.ipfire.org Git - thirdparty/kernel/stable-queue.git/blob - queue-4.4/media-au0828-fix-null-pointer-dereference-in-au0828_.patch
Linux 4.9.181
[thirdparty/kernel/stable-queue.git] / queue-4.4 / media-au0828-fix-null-pointer-dereference-in-au0828_.patch
1 From a8b76b93fe22279cc00d1496880da92685e576e3 Mon Sep 17 00:00:00 2001
2 From: Shuah Khan <shuah@kernel.org>
3 Date: Mon, 1 Apr 2019 20:43:17 -0400
4 Subject: media: au0828: Fix NULL pointer dereference in
5 au0828_analog_stream_enable()
6
7 [ Upstream commit 898bc40bfcc26abb6e06e960d6d4754c36c58b50 ]
8
9 Fix au0828_analog_stream_enable() to check if device is in the right
10 state first. When unbind happens while bind is in progress, usbdev
11 pointer could be invalid in au0828_analog_stream_enable() and a call
12 to usb_ifnum_to_if() will result in the null pointer dereference.
13
14 This problem is found with the new media_dev_allocator.sh test.
15
16 kernel: [ 590.359623] BUG: unable to handle kernel NULL pointer dereference at 00000000000004e8
17 kernel: [ 590.359627] #PF error: [normal kernel read fault]
18 kernel: [ 590.359629] PGD 0 P4D 0
19 kernel: [ 590.359632] Oops: 0000 [#1] SMP PTI
20 kernel: [ 590.359634] CPU: 3 PID: 1458 Comm: v4l_id Not tainted 5.1.0-rc2+ #30
21 kernel: [ 590.359636] Hardware name: Dell Inc. OptiPlex 7 90/0HY9JP, BIOS A18 09/24/2013
22 kernel: [ 590.359641] RIP: 0010:usb_ifnum_to_if+0x6/0x60
23 kernel: [ 590.359643] Code: 5d 41 5e 41 5f 5d c3 48 83 c4
24 10 b8 fa ff ff ff 5b 41 5c 41 5d 41 5e 41 5f 5d c3 b8 fa ff ff ff c3 0f 1f 00 6
25 6 66 66 66 90 55 <48> 8b 97 e8 04 00 00 48 89 e5 48 85 d2 74 41 0f b6 4a 04 84 c
26 9 74
27 kernel: [ 590.359645] RSP: 0018:ffffad3cc3c1fc00 EFLAGS: 00010246
28 kernel: [ 590.359646] RAX: 0000000000000000 RBX: ffff8ded b1f3c000 RCX: 1f377e4500000000
29 kernel: [ 590.359648] RDX: ffff8dedfa3a6b50 RSI: 00000000 00000000 RDI: 0000000000000000
30 kernel: [ 590.359649] RBP: ffffad3cc3c1fc28 R08: 00000000 8574acc2 R09: ffff8dedfa3a6b50
31 kernel: [ 590.359650] R10: 0000000000000001 R11: 00000000 00000000 R12: 0000000000000000
32 kernel: [ 590.359652] R13: ffff8dedb1f3f0f0 R14: ffffffff adcf7ec0 R15: 0000000000000000
33 kernel: [ 590.359654] FS: 00007f7917198540(0000) GS:ffff 8dee258c0000(0000) knlGS:0000000000000000
34 kernel: [ 590.359655] CS: 0010 DS: 0000 ES: 0000 CR0: 00 00000080050033
35 kernel: [ 590.359657] CR2: 00000000000004e8 CR3: 00000001 a388e002 CR4: 00000000000606e0
36 kernel: [ 590.359658] Call Trace:
37 kernel: [ 590.359664] ? au0828_analog_stream_enable+0x2c/0x180
38 kernel: [ 590.359666] au0828_v4l2_open+0xa4/0x110
39 kernel: [ 590.359670] v4l2_open+0x8b/0x120
40 kernel: [ 590.359674] chrdev_open+0xa6/0x1c0
41 kernel: [ 590.359676] ? cdev_put.part.3+0x20/0x20
42 kernel: [ 590.359678] do_dentry_open+0x1f6/0x360
43 kernel: [ 590.359681] vfs_open+0x2f/0x40
44 kernel: [ 590.359684] path_openat+0x299/0xc20
45 kernel: [ 590.359688] do_filp_open+0x9b/0x110
46 kernel: [ 590.359695] ? _raw_spin_unlock+0x27/0x40
47 kernel: [ 590.359697] ? __alloc_fd+0xb2/0x160
48 kernel: [ 590.359700] do_sys_open+0x1ba/0x260
49 kernel: [ 590.359702] ? do_sys_open+0x1ba/0x260
50 kernel: [ 590.359712] __x64_sys_openat+0x20/0x30
51 kernel: [ 590.359715] do_syscall_64+0x5a/0x120
52 kernel: [ 590.359718] entry_SYSCALL_64_after_hwframe+0x44/0xa9
53
54 Signed-off-by: Shuah Khan <shuah@kernel.org>
55 Signed-off-by: Hans Verkuil <hverkuil-cisco@xs4all.nl>
56 Signed-off-by: Mauro Carvalho Chehab <mchehab+samsung@kernel.org>
57 Signed-off-by: Sasha Levin <sashal@kernel.org>
58 ---
59 drivers/media/usb/au0828/au0828-video.c | 3 +++
60 1 file changed, 3 insertions(+)
61
62 diff --git a/drivers/media/usb/au0828/au0828-video.c b/drivers/media/usb/au0828/au0828-video.c
63 index 1ff66e7e26a81..1df23c01ad374 100644
64 --- a/drivers/media/usb/au0828/au0828-video.c
65 +++ b/drivers/media/usb/au0828/au0828-video.c
66 @@ -711,6 +711,9 @@ static int au0828_analog_stream_enable(struct au0828_dev *d)
67
68 dprintk(1, "au0828_analog_stream_enable called\n");
69
70 + if (test_bit(DEV_DISCONNECTED, &d->dev_state))
71 + return -ENODEV;
72 +
73 iface = usb_ifnum_to_if(d->usbdev, 0);
74 if (iface && iface->cur_altsetting->desc.bAlternateSetting != 5) {
75 dprintk(1, "Changing intf#0 to alt 5\n");
76 --
77 2.20.1
78