• sumitg's avatar
    media: v4l2-core: fix use-after-free error · bcf628be
    sumitg authored
    [ Upstream commit 3e0f7243 ]
    
    Fixing use-after-free within __v4l2_ctrl_handler_setup().
    Memory is being freed with kfree(new_ref) for duplicate
    control reference entry but ctrl->cluster pointer is still
    referring to freed duplicate entry resulting in error on
    access. Change done to update cluster pointer only when new
    control reference is added.
    
     ==================================================================
     BUG: KASAN: use-after-free in __v4l2_ctrl_handler_setup+0x388/0x428
     Read of size 8 at addr ffffffc324e78618 by task systemd-udevd/312
    
     Allocated by task 312:
    
     Freed by task 312:
    
     The buggy address belongs to the object at ffffffc324e78600
      which belongs to the cache kmalloc-64 of size 64
     The buggy address is located 24 bytes inside of
      64-byte region [ffffffc324e78600, ffffffc324e78640)
     The buggy address belongs to the page:
     page:ffffffbf0c939e00 count:1 mapcount:0 mapping:
    					(null) index:0xffffffc324e78f80
     flags: 0x4000000000000100(slab)
     raw: 4000000000000100 0000000000000000 ffffffc324e78f80 000000018020001a
     raw: 0000000000000000 0000000100000001 ffffffc37040fb80 0000000000000000
     page dumped because: kasan: bad access detected
    
     Memory state around the buggy address:
      ffffffc324e78500: fb fb fb fb fb fb fb fb fc fc fc fc fc fc fc fc
      ffffffc324e78580: fb fb fb fb fb fb fb fb fc fc fc fc fc fc fc fc
     >ffffffc324e78600: fb fb fb fb fb fb fb fb fc fc fc fc fc fc fc fc
                                 ^
      ffffffc324e78680: 00 00 00 00 00 00 00 00 fc fc fc fc fc fc fc fc
      ffffffc324e78700: 00 00 00 00 00 fc fc fc fc fc fc fc fc fc fc fc
     ==================================================================
    Suggested-by: default avatarHans Verkuil <hverkuil-cisco@xs4all.nl>
    Signed-off-by: default avatarSumit Gupta <sumitg@nvidia.com>
    Signed-off-by: default avatarHans Verkuil <hverkuil-cisco@xs4all.nl>
    Signed-off-by: default avatarMauro Carvalho Chehab <mchehab+samsung@kernel.org>
    Signed-off-by: default avatarSasha Levin <sashal@kernel.org>
    bcf628be
v4l2-ctrls.c 120 KB