On Tue Mar 3 11:27:54 2026 +0000, Ruslan Valiyev wrote:
> syzbot reported a general protection fault in vidtv_psi_desc_assign [1].
> 
> vidtv_psi_pmt_stream_init() can return NULL on memory allocation
> failure, but vidtv_channel_pmt_match_sections() does not check for
> this. When tail is NULL, the subsequent call to
> vidtv_psi_desc_assign(&tail->descriptor, desc) dereferences a NULL
> pointer offset, causing a general protection fault.
> 
> Add a NULL check after vidtv_psi_pmt_stream_init(). On failure, clean
> up the already-allocated stream chain and return.
> 
> [1]
> Oops: general protection fault, probably for non-canonical address 
> 0xdffffc0000000000: 0000 [#1] SMP KASAN PTI
> KASAN: null-ptr-deref in range [0x0000000000000000-0x0000000000000007]
> RIP: 0010:vidtv_psi_desc_assign+0x24/0x90 
> drivers/media/test-drivers/vidtv/vidtv_psi.c:629
> Call Trace:
>  <TASK>
>  vidtv_channel_pmt_match_sections 
> drivers/media/test-drivers/vidtv/vidtv_channel.c:349 [inline]
>  vidtv_channel_si_init+0x1445/0x1a50 
> drivers/media/test-drivers/vidtv/vidtv_channel.c:479
>  vidtv_mux_init+0x526/0xbe0 drivers/media/test-drivers/vidtv/vidtv_mux.c:519
>  vidtv_start_streaming drivers/media/test-drivers/vidtv/vidtv_bridge.c:194 
> [inline]
>  vidtv_start_feed+0x33e/0x4d0 
> drivers/media/test-drivers/vidtv/vidtv_bridge.c:239
> 
> Fixes: f90cf6079bf67 ("media: vidtv: add a bridge driver")
> Cc: [email protected]
> Reported-by: [email protected]
> Closes: https://syzkaller.appspot.com/bug?extid=1f5bcc7c919ec578777a
> Signed-off-by: Ruslan Valiyev <[email protected]>
> Signed-off-by: Hans Verkuil <[email protected]>

Patch committed.

Thanks,
Hans Verkuil

 drivers/media/test-drivers/vidtv/vidtv_channel.c | 4 ++++
 1 file changed, 4 insertions(+)

---

diff --git a/drivers/media/test-drivers/vidtv/vidtv_channel.c 
b/drivers/media/test-drivers/vidtv/vidtv_channel.c
index da20657adc74..5f8c3af87171 100644
--- a/drivers/media/test-drivers/vidtv/vidtv_channel.c
+++ b/drivers/media/test-drivers/vidtv/vidtv_channel.c
@@ -341,6 +341,10 @@ vidtv_channel_pmt_match_sections(struct vidtv_channel 
*channels,
                                        tail = vidtv_psi_pmt_stream_init(tail,
                                                                         
s->type,
                                                                         e_pid);
+                                       if (!tail) {
+                                               
vidtv_psi_pmt_stream_destroy(head);
+                                               return;
+                                       }
 
                                        if (!head)
                                                head = tail;
_______________________________________________
linuxtv-commits mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to