Skip to content
Snippets Groups Projects
Commit 0f1d3387 authored by Dongliang Mu's avatar Dongliang Mu Committed by Yongqiang Liu
Browse files

media: em28xx: initialize refcount before kref_get

stable inclusion
from stable-v4.19.238
commit 0113fa98a49a8e46a19b0ad80f29c904c6feec23
category: bugfix
bugzilla: https://gitee.com/src-openeuler/kernel/issues/I5RX5X


CVE: CVE-2022-3239

---------------------------

[ Upstream commit c08eadca1bdfa099e20a32f8fa4b52b2f672236d ]

The commit 47677e51("[media] em28xx: Only deallocate struct
em28xx after finishing all extensions") adds kref_get to many init
functions (e.g., em28xx_audio_init). However, kref_init is called too
late in em28xx_usb_probe, since em28xx_init_dev before will invoke
those init functions and call kref_get function. Then refcount bug
occurs in my local syzkaller instance.

Fix it by moving kref_init before em28xx_init_dev. This issue occurs
not only in dev but also dev->dev_next.

Fixes: 47677e51 ("[media] em28xx: Only deallocate struct em28xx after finishing all extensions")
Reported-by: default avatarsyzkaller <syzkaller@googlegroups.com>
Signed-off-by: default avatarDongliang Mu <mudongliangabcd@gmail.com>
Signed-off-by: default avatarHans Verkuil <hverkuil-cisco@xs4all.nl>
Signed-off-by: default avatarSasha Levin <sashal@kernel.org>
Signed-off-by: default avatarGuo Mengqi <guomengqi3@huawei.com>
Reviewed-by: default avatarXiu Jianfeng <xiujianfeng@huawei.com>
Reviewed-by: default avatarWeilong Chen <chenweilong@huawei.com>
Signed-off-by: default avatarYongqiang Liu <liuyongqiang13@huawei.com>
parent b2297d93
No related branches found
No related tags found
No related merge requests found
...@@ -3816,6 +3816,8 @@ static int em28xx_usb_probe(struct usb_interface *intf, ...@@ -3816,6 +3816,8 @@ static int em28xx_usb_probe(struct usb_interface *intf,
goto err_free; goto err_free;
} }
kref_init(&dev->ref);
dev->devno = nr; dev->devno = nr;
dev->model = id->driver_info; dev->model = id->driver_info;
dev->alt = -1; dev->alt = -1;
...@@ -3916,6 +3918,8 @@ static int em28xx_usb_probe(struct usb_interface *intf, ...@@ -3916,6 +3918,8 @@ static int em28xx_usb_probe(struct usb_interface *intf,
} }
if (dev->board.has_dual_ts && em28xx_duplicate_dev(dev) == 0) { if (dev->board.has_dual_ts && em28xx_duplicate_dev(dev) == 0) {
kref_init(&dev->dev_next->ref);
dev->dev_next->ts = SECONDARY_TS; dev->dev_next->ts = SECONDARY_TS;
dev->dev_next->alt = -1; dev->dev_next->alt = -1;
dev->dev_next->is_audio_only = has_vendor_audio && dev->dev_next->is_audio_only = has_vendor_audio &&
...@@ -3970,12 +3974,8 @@ static int em28xx_usb_probe(struct usb_interface *intf, ...@@ -3970,12 +3974,8 @@ static int em28xx_usb_probe(struct usb_interface *intf,
em28xx_write_reg(dev, 0x0b, 0x82); em28xx_write_reg(dev, 0x0b, 0x82);
mdelay(100); mdelay(100);
} }
kref_init(&dev->dev_next->ref);
} }
kref_init(&dev->ref);
request_modules(dev); request_modules(dev);
/* /*
......
0% or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment