On Tue Jul 7 23:06:24 2026 +0800, Ruoyu Wang wrote:
> hfi_process_msg_packet() intentionally allows HFI_MSG_EVENT_NOTIFY
> packets without a matching session instance because HFI_EVENT_SYS_ERROR
> is a system event and has no session attached.
>
> That exception currently applies to every event-notify packet. If the
> firmware reports a late or otherwise invalid session event after
> to_instance() fails, hfi_event_notify() can dispatch it to session-only
> handlers such as event_seq_changed() or event_release_buffer_ref(), which
> dereference inst.
>
> Only system errors are valid without a session instance. Drop other
> event notifications before the session event handlers can dereference a
> NULL inst.
>
> This issue was found by a static analysis checker and confirmed by
> manual source review.
>
> Fixes: 09c2845e8fe4 ("[media] media: venus: hfi: add Host Firmware Interface
> (HFI)")
> Signed-off-by: Ruoyu Wang <[email protected]>
> Signed-off-by: Bryan O'Donoghue <[email protected]>
Patch committed.
Thanks,
Bryan O'Donoghue
drivers/media/platform/qcom/venus/hfi_msgs.c | 3 +++
1 file changed, 3 insertions(+)
---
diff --git a/drivers/media/platform/qcom/venus/hfi_msgs.c
b/drivers/media/platform/qcom/venus/hfi_msgs.c
index 5c2025c5acc7..ed6b4e5e5e92 100644
--- a/drivers/media/platform/qcom/venus/hfi_msgs.c
+++ b/drivers/media/platform/qcom/venus/hfi_msgs.c
@@ -230,6 +230,9 @@ static void hfi_event_notify(struct venus_core *core,
struct venus_inst *inst,
if (!packet)
return;
+ if (!inst && pkt->event_id != HFI_EVENT_SYS_ERROR)
+ return;
+
switch (pkt->event_id) {
case HFI_EVENT_SYS_ERROR:
event_sys_error(core, EVT_SYS_ERROR, pkt);
_______________________________________________
linuxtv-commits mailing list -- [email protected]
To unsubscribe send an email to [email protected]