• Alan Stern's avatar
    media: usbvision: Fix races among open, close, and disconnect · 9e08117c
    Alan Stern authored
    Visual inspection of the usbvision driver shows that it suffers from
    three races between its open, close, and disconnect handlers.  In
    particular, the driver is careful to update its usbvision->user and
    usbvision->remove_pending flags while holding the private mutex, but:
    
    	usbvision_v4l2_close() and usbvision_radio_close() don't hold
    	the mutex while they check the value of
    	usbvision->remove_pending;
    
    	usbvision_disconnect() doesn't hold the mutex while checking
    	the value of usbvision->user; and
    
    	also, usbvision_v4l2_open() and usbvision_radio_open() don't
    	check whether the device has been unplugged before allowing
    	the user to open the device files.
    
    Each of these can potentially lead to usbvision_release() being called
    twice and use-after-free errors.
    
    This patch fixes the races by reading the flags while the mutex is
    still held and checking for pending removes before allowing an open to
    succeed.
    Signed-off-by: default avatarAlan Stern <stern@rowland.harvard.edu>
    CC: <stable@vger.kernel.org>
    Signed-off-by: default avatarHans Verkuil <hverkuil-cisco@xs4all.nl>
    Signed-off-by: default avatarMauro Carvalho Chehab <mchehab+samsung@kernel.org>
    9e08117c
usbvision-video.c 45.3 KB