On Thu Aug 27 09:52:29 2026 +0530, Jeffin Philip wrote:
> Attempting to unbind a dvbdevice that is in the process of feeding
> data causes a UAF as we free the underlying device without
> stopping the feed first. Fix this by stopping the stream first using
> vidtv_stop_streaming(). However, our codepath in the reproducer
> (mentioned in the below reply) does not decrement our users
> (dmxdev->dvr_dvbdev->users) to 1 after it has been incremented to 2
> by our read() in the reproducer, that is only possible on .release.
> This can cause a task hang as dvb_dmxdev_release() uses wait_event()
> in the wait_queue unless we use a close(fd)(in the reproducer).
> Is this a problem? Please advise.
>
> Reported-by: [email protected]
> Closes: https://syzkaller.appspot.com/bug?extid=c7fc4794e59786f5b4dc
> Fixes: f90cf6079bf6 ("media: vidtv: add a bridge driver")
> Cc: [email protected]
> Signed-off-by: Jeffin Philip <[email protected]>
> Signed-off-by: Hans Verkuil <[email protected]>
Patch committed.
Thanks,
Hans Verkuil
drivers/media/test-drivers/vidtv/vidtv_bridge.c | 2 ++
1 file changed, 2 insertions(+)
---
diff --git a/drivers/media/test-drivers/vidtv/vidtv_bridge.c
b/drivers/media/test-drivers/vidtv/vidtv_bridge.c
index 9887860b0198..f951b877ada6 100644
--- a/drivers/media/test-drivers/vidtv/vidtv_bridge.c
+++ b/drivers/media/test-drivers/vidtv/vidtv_bridge.c
@@ -551,6 +551,8 @@ static void vidtv_bridge_remove(struct platform_device
*pdev)
mutex_destroy(&dvb->feed_lock);
+ vidtv_stop_streaming(dvb);
+
for (i = 0; i < NUM_FE; ++i) {
dvb_unregister_frontend(dvb->fe[i]);
dvb_frontend_detach(dvb->fe[i]);
_______________________________________________
linuxtv-commits mailing list -- [email protected]
To unsubscribe send an email to [email protected]