On Mon Sep 7 20:18:43 2026 +0800, Wei Jie Law wrote:
> A null-ptr-deref exists in v6.12.105 and upstream. KASAN crash log:
> 
>   KASAN: null-ptr-deref in range [0x0000000000000080-0x0000000000000087]
>   Workqueue: events uvc_ctrl_status_event_work
>   RIP: 0010:uvc_ctrl_status_event+0x105/0x280
>    uvc_ctrl_status_event_work+0x82/0x240
>    process_one_work+0x66f/0x10b0
> 
> XU controls are initialized lazily, on the first UVCIOC_CTRL_MAP or
> UVCIOC_CTRL_QUERY.  Until then ctrl->info is all zeroes, so
> info.mappings is not a valid list head, list_empty() returns false, and
> uvc_ctrl_status_event() walks it from a NULL next pointer.
> 
> Fixes: e5225c820c05 ("media: uvcvideo: Send a control event when a Control 
> Change interrupt arrives")
> Cc: [email protected]
> Signed-off-by: Wei Jie Law <[email protected]>
> Assisted-by: LLM
> Reviewed-by: Ricardo Ribalda <[email protected]>
> Link: https://patch.msgid.link/[email protected]
> Reviewed-by: Hans de Goede <[email protected]>
> Signed-off-by: Hans de Goede <[email protected]>
> Signed-off-by: Laurent Pinchart <[email protected]>
> Signed-off-by: Hans Verkuil <[email protected]>

Patch committed.

Thanks,
Hans Verkuil

 drivers/media/usb/uvc/uvc_ctrl.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

---

diff --git a/drivers/media/usb/uvc/uvc_ctrl.c b/drivers/media/usb/uvc/uvc_ctrl.c
index 3ca108b83f1d..ea28c4e819bd 100644
--- a/drivers/media/usb/uvc/uvc_ctrl.c
+++ b/drivers/media/usb/uvc/uvc_ctrl.c
@@ -2209,7 +2209,7 @@ bool uvc_ctrl_status_event_async(struct urb *urb, struct 
uvc_video_chain *chain,
        struct uvc_device *dev = chain->dev;
        struct uvc_ctrl_work *w = &dev->async_ctrl;
 
-       if (list_empty(&ctrl->info.mappings))
+       if (!ctrl->initialized || list_empty(&ctrl->info.mappings))
                return false;
 
        w->data = data;
_______________________________________________
linuxtv-commits mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to