On Tue Mar 3 11:27:54 2026 +0000, Ruslan Valiyev wrote:
> syzbot reported a general protection fault in vidtv_psi_desc_assign [1].
>
> vidtv_psi_pmt_stream_init() can return NULL on memory allocation
> failure, but vidtv_channel_pmt_match_sections() does not check for
> this. When tail is NULL, the subsequent call to
> vidtv_psi_desc_assign(&tail->descriptor, desc) dereferences a NULL
> pointer offset, causing a general protection fault.
>
> Add a NULL check after vidtv_psi_pmt_stream_init(). On failure, clean
> up the already-allocated stream chain and return.
>
> [1]
> Oops: general protection fault, probably for non-canonical address
> 0xdffffc0000000000: 0000 [#1] SMP KASAN PTI
> KASAN: null-ptr-deref in range [0x0000000000000000-0x0000000000000007]
> RIP: 0010:vidtv_psi_desc_assign+0x24/0x90
> drivers/media/test-drivers/vidtv/vidtv_psi.c:629
> Call Trace:
> <TASK>
> vidtv_channel_pmt_match_sections
> drivers/media/test-drivers/vidtv/vidtv_channel.c:349 [inline]
> vidtv_channel_si_init+0x1445/0x1a50
> drivers/media/test-drivers/vidtv/vidtv_channel.c:479
> vidtv_mux_init+0x526/0xbe0 drivers/media/test-drivers/vidtv/vidtv_mux.c:519
> vidtv_start_streaming drivers/media/test-drivers/vidtv/vidtv_bridge.c:194
> [inline]
> vidtv_start_feed+0x33e/0x4d0
> drivers/media/test-drivers/vidtv/vidtv_bridge.c:239
>
> Fixes: f90cf6079bf67 ("media: vidtv: add a bridge driver")
> Cc: [email protected]
> Reported-by: [email protected]
> Closes: https://syzkaller.appspot.com/bug?extid=1f5bcc7c919ec578777a
> Signed-off-by: Ruslan Valiyev <[email protected]>
> Signed-off-by: Hans Verkuil <[email protected]>
Patch committed.
Thanks,
Hans Verkuil
drivers/media/test-drivers/vidtv/vidtv_channel.c | 4 ++++
1 file changed, 4 insertions(+)
---
diff --git a/drivers/media/test-drivers/vidtv/vidtv_channel.c
b/drivers/media/test-drivers/vidtv/vidtv_channel.c
index da20657adc74..5f8c3af87171 100644
--- a/drivers/media/test-drivers/vidtv/vidtv_channel.c
+++ b/drivers/media/test-drivers/vidtv/vidtv_channel.c
@@ -341,6 +341,10 @@ vidtv_channel_pmt_match_sections(struct vidtv_channel
*channels,
tail = vidtv_psi_pmt_stream_init(tail,
s->type,
e_pid);
+ if (!tail) {
+
vidtv_psi_pmt_stream_destroy(head);
+ return;
+ }
if (!head)
head = tail;
_______________________________________________
linuxtv-commits mailing list -- [email protected]
To unsubscribe send an email to [email protected]