UPSTREAM: media: rkvdec: fix use after free bug in rkvdec_remove
[ Upstream commit3228cec23b] In rkvdec_probe, rkvdec->watchdog_work is bound with rkvdec_watchdog_func. Then rkvdec_vp9_run may be called to start the work. If we remove the module which will call rkvdec_remove to make cleanup, there may be a unfinished work. The possible sequence is as follows, which will cause a typical UAF bug. Fix it by canceling the work before cleanup in rkvdec_remove. CPU0 CPU1 |rkvdec_watchdog_func rkvdec_remove | rkvdec_v4l2_cleanup| v4l2_m2m_release | kfree(m2m_dev); | | | v4l2_m2m_get_curr_priv | m2m_dev->curr_ctx //use Bug: 289003637 Fixes:cd33c83044("media: rkvdec: Add the rkvdec driver") Signed-off-by: Zheng Wang <zyytlz.wz@163.com> Signed-off-by: Hans Verkuil <hverkuil-cisco@xs4all.nl> Signed-off-by: Mauro Carvalho Chehab <mchehab@kernel.org> Signed-off-by: Sasha Levin <sashal@kernel.org> (cherry picked from commit6a17add9c6) Signed-off-by: Lee Jones <joneslee@google.com> Change-Id: Ibdf4667315d98ac1cd42545f61e271c291893edd
This commit is contained in:
parent
739f5722f4
commit
158d8bfffc
1 changed files with 2 additions and 0 deletions
|
|
@ -1077,6 +1077,8 @@ static int rkvdec_remove(struct platform_device *pdev)
|
|||
{
|
||||
struct rkvdec_dev *rkvdec = platform_get_drvdata(pdev);
|
||||
|
||||
cancel_delayed_work_sync(&rkvdec->watchdog_work);
|
||||
|
||||
rkvdec_v4l2_cleanup(rkvdec);
|
||||
pm_runtime_disable(&pdev->dev);
|
||||
pm_runtime_dont_use_autosuspend(&pdev->dev);
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue