On Sun Mar 1 21:07:35 2026 +0000, Ruslan Valiyev wrote:
> syzbot reported a memory leak in vidtv_psi_service_desc_init [1].
> 
> When vidtv_start_streaming() fails inside vidtv_start_feed(), the
> nfeeds counter is left incremented even though no feed was actually
> started. This corrupts the driver state: subsequent start_feed calls
> see nfeeds > 1 and skip starting the mux, while stop_feed calls
> eventually try to stop a non-existent stream.
> 
> This state corruption can also lead to memory leaks, since the mux
> and channel resources may be partially allocated during a failed
> start_streaming but never cleaned up, as the stop path finds
> dvb->streaming == false and returns early.
> 
> Fix by decrementing nfeeds back when start_streaming fails, keeping
> the counter in sync with the actual number of active feeds.
> 
> [1]
> BUG: memory leak
> unreferenced object 0xffff888145b50820 (size 32):
>  comm "syz.0.17", pid 6068, jiffies 4294944486
>  backtrace (crc 90a0c7d4):
>   vidtv_psi_service_desc_init+0x74/0x1b0 
> drivers/media/test-drivers/vidtv/vidtv_psi.c:288
>   vidtv_channel_s302m_init+0xb1/0x2a0 
> drivers/media/test-drivers/vidtv/vidtv_channel.c:83
>   vidtv_channels_init+0x1b/0x40 
> drivers/media/test-drivers/vidtv/vidtv_channel.c:524
>   vidtv_mux_init+0x516/0xbe0 drivers/media/test-drivers/vidtv/vidtv_mux.c:518
>   vidtv_start_streaming drivers/media/test-drivers/vidtv/vidtv_bridge.c:194 
> [inline]
>   vidtv_start_feed+0x33e/0x4d0 
> drivers/media/test-drivers/vidtv/vidtv_bridge.c:239
> 
> Fixes: f90cf6079bf67 ("media: vidtv: add a bridge driver")
> Cc: [email protected]
> Reported-by: [email protected]
> Closes: https://syzkaller.appspot.com/bug?extid=639ebc6ec75e96674741
> Signed-off-by: Ruslan Valiyev <[email protected]>
> Signed-off-by: Hans Verkuil <[email protected]>

Patch committed.

Thanks,
Hans Verkuil

 drivers/media/test-drivers/vidtv/vidtv_bridge.c | 4 +++-
 1 file changed, 3 insertions(+), 1 deletion(-)

---

diff --git a/drivers/media/test-drivers/vidtv/vidtv_bridge.c 
b/drivers/media/test-drivers/vidtv/vidtv_bridge.c
index b6203e10e37a..a8a76434989c 100644
--- a/drivers/media/test-drivers/vidtv/vidtv_bridge.c
+++ b/drivers/media/test-drivers/vidtv/vidtv_bridge.c
@@ -237,8 +237,10 @@ static int vidtv_start_feed(struct dvb_demux_feed *feed)
 
        if (dvb->nfeeds == 1) {
                ret = vidtv_start_streaming(dvb);
-               if (ret < 0)
+               if (ret < 0) {
+                       dvb->nfeeds--;
                        rc = ret;
+               }
        }
 
        mutex_unlock(&dvb->feed_lock);
_______________________________________________
linuxtv-commits mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to