Re: [PATCH 1/3] media: nxp: imx-jpeg: cancel task_timer before freeing ctx

"Ming Qian(OSS)" <[email protected]>
Newsgroups org.kernel.vger.stable,dev.linux.lists.imx,org.infradead.lists.linux-arm-kernel,org.kernel.vger.linux-media
Message-ID <[email protected]>
On Tue, Aug 25, 2026 at 03:34:30AM +0800, Shengzhuo Wei wrote:
> [You don't often get email from [email protected]. Learn why this is important at https://aka.ms/LearnAboutSenderIdentification ]
> 

Hi Shengzhuo,

Thanks for the patch.

This use-after-free has already been fixed by Fan Wu:
    https://lore.kernel.org/lkml/[email protected]/
    [PATCH] media: imx-jpeg: cancel timeout worker when streaming stops

Regards,
Ming

> mxc_jpeg_device_run() arms ctx->task_timer for each job; the only place
> it is cancelled is the job-completion IRQ handler. If the hardware
> never completes the job, mxc_jpeg_release() frees ctx with the timer
> still pending, and mxc_jpeg_device_run_timeout() then dereferences the
> freed ctx -- a use-after-free.
> 
> Cancel the timer before the ctx is torn down, before taking
> mxc_jpeg->lock so the cancel never waits on a worker that needs the
> mutex.
> 
> Fixes: cfed9632ca8e ("media: imx-jpeg: Add a timeout mechanism for each frame")
> Cc: [email protected]
> Signed-off-by: Shengzhuo Wei <[email protected]>
> Assisted-by: GLM:5.3
> ---
>  drivers/media/platform/nxp/imx-jpeg/mxc-jpeg.c | 2 ++
>  1 file changed, 2 insertions(+)
> 
> diff --git a/drivers/media/platform/nxp/imx-jpeg/mxc-jpeg.c b/drivers/media/platform/nxp/imx-jpeg/mxc-jpeg.c
> index 725e941528848e8f224fe6a96ba7f746fc45ed63..fbb64a1ecb5189d2d7b953b99dcd7bcb54e6e20e 100644
> --- a/drivers/media/platform/nxp/imx-jpeg/mxc-jpeg.c
> +++ b/drivers/media/platform/nxp/imx-jpeg/mxc-jpeg.c
> @@ -2796,6 +2796,8 @@ static int mxc_jpeg_release(struct file *file)
>         struct mxc_jpeg_ctx *ctx = mxc_jpeg_file_to_ctx(file);
>         struct device *dev = mxc_jpeg->dev;
> 
> +       cancel_delayed_work_sync(&ctx->task_timer);
> +
>         mutex_lock(&mxc_jpeg->lock);
>         if (mxc_jpeg->mode == MXC_JPEG_DECODE)
>                 dev_dbg(dev, "Release JPEG decoder instance on slot %d.",
> 
> --
> 2.47.3
>
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.