| From 29620df54c7d7362679de35a3b05d189506c577a Mon Sep 17 00:00:00 2001 |
| From: Sasha Levin <sashal@kernel.org> |
| Date: Thu, 13 Apr 2023 11:49:42 +0800 |
| Subject: media: bttv: fix use after free error due to btv->timeout timer |
| |
| From: Zheng Wang <zyytlz.wz@163.com> |
| |
| [ Upstream commit bd5b50b329e850d467e7bcc07b2b6bde3752fbda ] |
| |
| There may be some a race condition between timer function |
| bttv_irq_timeout and bttv_remove. The timer is setup in |
| probe and there is no timer_delete operation in remove |
| function. When it hit kfree btv, the function might still be |
| invoked, which will cause use after free bug. |
| |
| This bug is found by static analysis, it may be false positive. |
| |
| Fix it by adding del_timer_sync invoking to the remove function. |
| |
| cpu0 cpu1 |
| bttv_probe |
| ->timer_setup |
| ->bttv_set_dma |
| ->mod_timer; |
| bttv_remove |
| ->kfree(btv); |
| ->bttv_irq_timeout |
| ->USE btv |
| |
| Fixes: 162e6376ac58 ("media: pci: Convert timers to use timer_setup()") |
| Signed-off-by: Zheng Wang <zyytlz.wz@163.com> |
| Signed-off-by: Hans Verkuil <hverkuil-cisco@xs4all.nl> |
| Signed-off-by: Sasha Levin <sashal@kernel.org> |
| --- |
| drivers/media/pci/bt8xx/bttv-driver.c | 1 + |
| 1 file changed, 1 insertion(+) |
| |
| diff --git a/drivers/media/pci/bt8xx/bttv-driver.c b/drivers/media/pci/bt8xx/bttv-driver.c |
| index 734f02b91aa31..a50cae25b5463 100644 |
| --- a/drivers/media/pci/bt8xx/bttv-driver.c |
| +++ b/drivers/media/pci/bt8xx/bttv-driver.c |
| @@ -3830,6 +3830,7 @@ static void bttv_remove(struct pci_dev *pci_dev) |
| |
| /* free resources */ |
| free_irq(btv->c.pci->irq,btv); |
| + del_timer_sync(&btv->timeout); |
| iounmap(btv->bt848_mmio); |
| release_mem_region(pci_resource_start(btv->c.pci,0), |
| pci_resource_len(btv->c.pci,0)); |
| -- |
| 2.42.0 |
| |