Re: [PATCH 1/3] media: nxp: imx-jpeg: cancel task_timer before freeing ctx
"Ming Qian(OSS)" <[email protected]>
| Newsgroups | org.kernel.vger.stable,dev.linux.lists.imx,org.infradead.lists.linux-arm-kernel,org.kernel.vger.linux-media |
|---|---|
| Message-ID | <[email protected]> |
On Tue, Aug 25, 2026 at 03:34:30AM +0800, Shengzhuo Wei wrote: > [You don't often get email from [email protected]. Learn why this is important at https://aka.ms/LearnAboutSenderIdentification ] > Hi Shengzhuo, Thanks for the patch. This use-after-free has already been fixed by Fan Wu: https://lore.kernel.org/lkml/[email protected]/ [PATCH] media: imx-jpeg: cancel timeout worker when streaming stops Regards, Ming > mxc_jpeg_device_run() arms ctx->task_timer for each job; the only place > it is cancelled is the job-completion IRQ handler. If the hardware > never completes the job, mxc_jpeg_release() frees ctx with the timer > still pending, and mxc_jpeg_device_run_timeout() then dereferences the > freed ctx -- a use-after-free. > > Cancel the timer before the ctx is torn down, before taking > mxc_jpeg->lock so the cancel never waits on a worker that needs the > mutex. > > Fixes: cfed9632ca8e ("media: imx-jpeg: Add a timeout mechanism for each frame") > Cc: [email protected] > Signed-off-by: Shengzhuo Wei <[email protected]> > Assisted-by: GLM:5.3 > --- > drivers/media/platform/nxp/imx-jpeg/mxc-jpeg.c | 2 ++ > 1 file changed, 2 insertions(+) > > diff --git a/drivers/media/platform/nxp/imx-jpeg/mxc-jpeg.c b/drivers/media/platform/nxp/imx-jpeg/mxc-jpeg.c > index 725e941528848e8f224fe6a96ba7f746fc45ed63..fbb64a1ecb5189d2d7b953b99dcd7bcb54e6e20e 100644 > --- a/drivers/media/platform/nxp/imx-jpeg/mxc-jpeg.c > +++ b/drivers/media/platform/nxp/imx-jpeg/mxc-jpeg.c > @@ -2796,6 +2796,8 @@ static int mxc_jpeg_release(struct file *file) > struct mxc_jpeg_ctx *ctx = mxc_jpeg_file_to_ctx(file); > struct device *dev = mxc_jpeg->dev; > > + cancel_delayed_work_sync(&ctx->task_timer); > + > mutex_lock(&mxc_jpeg->lock); > if (mxc_jpeg->mode == MXC_JPEG_DECODE) > dev_dbg(dev, "Release JPEG decoder instance on slot %d.", > > -- > 2.47.3 >