On Mon Sep 7 20:18:43 2026 +0800, Wei Jie Law wrote:
> A null-ptr-deref exists in v6.12.105 and upstream. KASAN crash log:
>
> KASAN: null-ptr-deref in range [0x0000000000000080-0x0000000000000087]
> Workqueue: events uvc_ctrl_status_event_work
> RIP: 0010:uvc_ctrl_status_event+0x105/0x280
> uvc_ctrl_status_event_work+0x82/0x240
> process_one_work+0x66f/0x10b0
>
> XU controls are initialized lazily, on the first UVCIOC_CTRL_MAP or
> UVCIOC_CTRL_QUERY. Until then ctrl->info is all zeroes, so
> info.mappings is not a valid list head, list_empty() returns false, and
> uvc_ctrl_status_event() walks it from a NULL next pointer.
>
> Fixes: e5225c820c05 ("media: uvcvideo: Send a control event when a Control
> Change interrupt arrives")
> Cc: [email protected]
> Signed-off-by: Wei Jie Law <[email protected]>
> Assisted-by: LLM
> Reviewed-by: Ricardo Ribalda <[email protected]>
> Link: https://patch.msgid.link/[email protected]
> Reviewed-by: Hans de Goede <[email protected]>
> Signed-off-by: Hans de Goede <[email protected]>
> Signed-off-by: Laurent Pinchart <[email protected]>
> Signed-off-by: Hans Verkuil <[email protected]>
Patch committed.
Thanks,
Hans Verkuil
drivers/media/usb/uvc/uvc_ctrl.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
---
diff --git a/drivers/media/usb/uvc/uvc_ctrl.c b/drivers/media/usb/uvc/uvc_ctrl.c
index 3ca108b83f1d..ea28c4e819bd 100644
--- a/drivers/media/usb/uvc/uvc_ctrl.c
+++ b/drivers/media/usb/uvc/uvc_ctrl.c
@@ -2209,7 +2209,7 @@ bool uvc_ctrl_status_event_async(struct urb *urb, struct
uvc_video_chain *chain,
struct uvc_device *dev = chain->dev;
struct uvc_ctrl_work *w = &dev->async_ctrl;
- if (list_empty(&ctrl->info.mappings))
+ if (!ctrl->initialized || list_empty(&ctrl->info.mappings))
return false;
w->data = data;
_______________________________________________
linuxtv-commits mailing list -- [email protected]
To unsubscribe send an email to [email protected]