[PATCH 0/3] media: cancel timeout delayed work before freeing its owner

"Shengzhuo Wei" <[email protected]>
Newsgroups org.infradead.lists.linux-arm-kernel,dev.linux.lists.imx
Message-ID <[email protected]>
Three m2m codec drivers arm a per-job timeout delayed work on the
system workqueue and only cancel it on the job-completion path. If the
hardware never completes the job, the release/remove path frees the
object the timeout callback dereferences (via container_of or through
the m2m device) with the work still pending -- a use-after-free when
the timer expires.

All three are the same missed-twins class as the recent mtk-jpeg
jpeg_work release fix and the host1x timeout-worker fix. In each case
the fix is a single cancel_delayed_work_sync() placed before the object
is freed:

  - mxc-jpeg: cancel ctx->task_timer in mxc_jpeg_release() before
    kfree(ctx); the timer is otherwise only cancelled in the job IRQ.
  - hantro: cancel vpu->watchdog_work in hantro_remove() before
    v4l2_m2m_put() frees the m2m device the watchdog dereferences.
  - mtk-jpeg: cancel jpeg->job_timeout_work in mtk_jpeg_remove()
    before v4l2_m2m_release(); ctx->jpeg_work in the same driver got
    the equivalent fix earlier, the device-level work was missed.

Patches are independent of each other.

---
Shengzhuo Wei (3):
      media: nxp: imx-jpeg: cancel task_timer before freeing ctx
      media: verisilicon: hantro: cancel watchdog work before m2m release
      media: mediatek: jpeg: cancel job timeout work before m2m release

 drivers/media/platform/mediatek/jpeg/mtk_jpeg_core.c | 1 +
 drivers/media/platform/nxp/imx-jpeg/mxc-jpeg.c       | 2 ++
 drivers/media/platform/verisilicon/hantro_drv.c      | 1 +
 3 files changed, 4 insertions(+)
---
base-commit: 075b74841bd0065a3bda3440873c747938e69b68
change-id: 20260825-media-timeout-work-1cef7720c63b

Best regards,
-- 
Shengzhuo Wei <[email protected]>
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.