[PATCH 1/3] media: nxp: imx-jpeg: cancel task_timer before freeing ctx

"Shengzhuo Wei" <[email protected]>
Newsgroups org.kernel.vger.linux-media,org.infradead.lists.linux-arm-kernel,org.kernel.vger.stable
Message-ID <[email protected]>
mxc_jpeg_device_run() arms ctx->task_timer for each job; the only place
it is cancelled is the job-completion IRQ handler. If the hardware
never completes the job, mxc_jpeg_release() frees ctx with the timer
still pending, and mxc_jpeg_device_run_timeout() then dereferences the
freed ctx -- a use-after-free.

Cancel the timer before the ctx is torn down, before taking
mxc_jpeg->lock so the cancel never waits on a worker that needs the
mutex.

Fixes: cfed9632ca8e ("media: imx-jpeg: Add a timeout mechanism for each frame")
Cc: [email protected]
Signed-off-by: Shengzhuo Wei <[email protected]>
Assisted-by: GLM:5.3
---
 drivers/media/platform/nxp/imx-jpeg/mxc-jpeg.c | 2 ++
 1 file changed, 2 insertions(+)

diff --git a/drivers/media/platform/nxp/imx-jpeg/mxc-jpeg.c b/drivers/media/platform/nxp/imx-jpeg/mxc-jpeg.c
index 725e941528848e8f224fe6a96ba7f746fc45ed63..fbb64a1ecb5189d2d7b953b99dcd7bcb54e6e20e 100644
--- a/drivers/media/platform/nxp/imx-jpeg/mxc-jpeg.c
+++ b/drivers/media/platform/nxp/imx-jpeg/mxc-jpeg.c
@@ -2796,6 +2796,8 @@ static int mxc_jpeg_release(struct file *file)
 	struct mxc_jpeg_ctx *ctx = mxc_jpeg_file_to_ctx(file);
 	struct device *dev = mxc_jpeg->dev;
 
+	cancel_delayed_work_sync(&ctx->task_timer);
+
 	mutex_lock(&mxc_jpeg->lock);
 	if (mxc_jpeg->mode == MXC_JPEG_DECODE)
 		dev_dbg(dev, "Release JPEG decoder instance on slot %d.",

-- 
2.47.3
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.