On Thu Sep 17 10:00:10 2026 +0000, Wentao Liang wrote:
> device_link_add() only takes a reference to the supplier when the
> link is created successfully.  When it fails it returns NULL without
> taking one, so the put_device(csi_dev) before the error check can
> drop the last reference to csi_dev and dev_name(csi_dev) then
> dereferences a freed device.
> 
> Move the put_device() below the error check and release the
> reference through the existing err_put label on the failure path so
> that csi_dev is no longer touched after it has been put.
> 
> Fixes: 765abb76f51f ("media: ivsc: Release csi_dev reference early in 
> mei_ace_setup_dev_link()")
> Signed-off-by: Wentao Liang <[email protected]>
> Signed-off-by: Sakari Ailus <[email protected]>

Patch committed.

Thanks,
Sakari Ailus

 drivers/media/pci/intel/ivsc/mei_ace.c | 4 ++--
 1 file changed, 2 insertions(+), 2 deletions(-)

---

diff --git a/drivers/media/pci/intel/ivsc/mei_ace.c 
b/drivers/media/pci/intel/ivsc/mei_ace.c
index b306a320b70f..bb57656fc85a 100644
--- a/drivers/media/pci/intel/ivsc/mei_ace.c
+++ b/drivers/media/pci/intel/ivsc/mei_ace.c
@@ -414,13 +414,13 @@ static int mei_ace_setup_dev_link(struct mei_ace *ace)
        /* setup link between mei_ace and mei_csi */
        ace->csi_link = device_link_add(csi_dev, dev, DL_FLAG_PM_RUNTIME |
                                        DL_FLAG_RPM_ACTIVE | DL_FLAG_STATELESS);
-       put_device(csi_dev);
        if (!ace->csi_link) {
                ret = -EINVAL;
                dev_err(dev, "failed to link to %s\n", dev_name(csi_dev));
-               goto err;
+               goto err_put;
        }
 
+       put_device(csi_dev);
        ace->csi_dev = csi_dev;
 
        return 0;
_______________________________________________
linuxtv-commits mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to