]> git.ipfire.org Git - thirdparty/kernel/stable.git/commitdiff
media: cpia2: fix memory leak in cpia2_usb_probe
authorPavel Skripkin <paskripkin@gmail.com>
Wed, 21 Apr 2021 19:43:45 +0000 (21:43 +0200)
committerGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Tue, 20 Jul 2021 14:15:43 +0000 (16:15 +0200)
[ Upstream commit be8656e62e9e791837b606a027802b504a945c97 ]

syzbot reported leak in cpia2 usb driver. The problem was
in invalid error handling.

v4l2_device_register() is called in cpia2_init_camera_struct(), but
all error cases after cpia2_init_camera_struct() did not call the
v4l2_device_unregister()

Reported-by: syzbot+d1e69c888f0d3866ead4@syzkaller.appspotmail.com
Signed-off-by: Pavel Skripkin <paskripkin@gmail.com>
Signed-off-by: Hans Verkuil <hverkuil-cisco@xs4all.nl>
Signed-off-by: Mauro Carvalho Chehab <mchehab+huawei@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
drivers/media/usb/cpia2/cpia2.h
drivers/media/usb/cpia2/cpia2_core.c
drivers/media/usb/cpia2/cpia2_usb.c

index ab238ac8bfc06ea2b1d5d5f559b38ec1dd150b1c..50c952250dc9b30cb2bc0e7ca32823e3d95fd0d9 100644 (file)
@@ -438,6 +438,7 @@ int cpia2_send_command(struct camera_data *cam, struct cpia2_command *cmd);
 int cpia2_do_command(struct camera_data *cam,
                     unsigned int command,
                     unsigned char direction, unsigned char param);
+void cpia2_deinit_camera_struct(struct camera_data *cam, struct usb_interface *intf);
 struct camera_data *cpia2_init_camera_struct(struct usb_interface *intf);
 int cpia2_init_camera(struct camera_data *cam);
 int cpia2_allocate_buffers(struct camera_data *cam);
index 3dfbb545c0e3859e9481575d235868f51fcd48f0..42cce7e94101beca766d6fc88e91e6efe4e925fc 100644 (file)
@@ -2172,6 +2172,18 @@ static void reset_camera_struct(struct camera_data *cam)
        cam->height = cam->params.roi.height;
 }
 
+/******************************************************************************
+ *
+ *  cpia2_init_camera_struct
+ *
+ *  Deinitialize camera struct
+ *****************************************************************************/
+void cpia2_deinit_camera_struct(struct camera_data *cam, struct usb_interface *intf)
+{
+       v4l2_device_unregister(&cam->v4l2_dev);
+       kfree(cam);
+}
+
 /******************************************************************************
  *
  *  cpia2_init_camera_struct
index 4c191fcd3a7f55be1c7306bdfbb8b87d97e1ca36..8392175740695f75d64afc6d72f9072aa5131aa9 100644 (file)
@@ -853,15 +853,13 @@ static int cpia2_usb_probe(struct usb_interface *intf,
        ret = set_alternate(cam, USBIF_CMDONLY);
        if (ret < 0) {
                ERR("%s: usb_set_interface error (ret = %d)\n", __func__, ret);
-               kfree(cam);
-               return ret;
+               goto alt_err;
        }
 
 
        if((ret = cpia2_init_camera(cam)) < 0) {
                ERR("%s: failed to initialize cpia2 camera (ret = %d)\n", __func__, ret);
-               kfree(cam);
-               return ret;
+               goto alt_err;
        }
        LOG("  CPiA Version: %d.%02d (%d.%d)\n",
               cam->params.version.firmware_revision_hi,
@@ -881,11 +879,14 @@ static int cpia2_usb_probe(struct usb_interface *intf,
        ret = cpia2_register_camera(cam);
        if (ret < 0) {
                ERR("%s: Failed to register cpia2 camera (ret = %d)\n", __func__, ret);
-               kfree(cam);
-               return ret;
+               goto alt_err;
        }
 
        return 0;
+
+alt_err:
+       cpia2_deinit_camera_struct(cam, intf);
+       return ret;
 }
 
 /******************************************************************************