summaryrefslogtreecommitdiff
path: root/Documentation/admin-guide
diff options
context:
space:
mode:
authorMyeonghun Pak <mhun512@gmail.com>2026-09-12 22:05:54 -0400
committerHans Verkuil <hverkuil+cisco@kernel.org>2026-09-23 14:54:49 +0200
commit22f552ff726a82a086be4ef02ce5099a0e8624b6 (patch)
tree76691024faefad6078120fd4c200b10d4851e218 /Documentation/admin-guide
parent9887716132d6c3c58cc67841dfb441c5a4a0d209 (diff)
downloadlinux-next-22f552ff726a82a086be4ef02ce5099a0e8624b6.tar.gz
linux-next-22f552ff726a82a086be4ef02ce5099a0e8624b6.zip
media: cx23885: unregister DVB bus when SP2 CI setup fails
The DVBSKY S950C, DVBSKY T980C and TechnoTrend CT2-4500 CI paths register the DVB bus before attaching their SP2 CI client. If that client cannot be created, bound, or pinned, the current error path removes the I2C frontend components and only deallocates the frontend list, leaving the registered DVB adapter behind. Removing an I2C demod before unregistering the DVB bus can also expose the use-after-free ordering fixed for the normal remove path. Unregister the DVB bus immediately when SP2 CI setup fails, before the existing I2C client cleanup. The bus helper empties the frontend list, so the later frontend deallocation has nothing left to release. Keep failures from vb2_dvb_register_bus() on the existing cleanup path. Also release an unbound SP2 client and propagate the actual I2C creation or CI registration error. This issue was identified during our ongoing static-analysis research while reviewing kernel code. Fixes: 2b0aac3011bc ("[media] cx23885: move CI/MAC registration to a separate function") Cc: stable@vger.kernel.org Assisted-by: OpenAI:GPT-5.6 Co-developed-by: Ijae Kim <ae878000@gmail.com> Signed-off-by: Ijae Kim <ae878000@gmail.com> Signed-off-by: Myeonghun Pak <mhun512@gmail.com> Signed-off-by: Hans Verkuil <hverkuil+cisco@kernel.org>
Diffstat (limited to 'Documentation/admin-guide')
0 files changed, 0 insertions, 0 deletions