On Wed Jul 8 18:35:33 2026 +0530, Biren Pandya wrote:
> The ov02a10_check_hwcfg() function calls fwnode_handle_put(ep)
> immediately after allocating and parsing the endpoint. However, it
> subsequently calls fwnode_property_read_u32() using the same 'ep'
> handle, leading to a potential use-after-free.
> 
> Additionally, reading the optional 'ovti,mipi-clock-voltage' property
> used to overwrite the 'ret' variable. If the property was missing,
> 'ret' would become negative, and this failure code would be incorrectly
> returned at the end of the function, causing probe to fail entirely.
> 
> Fix the use-after-free by moving fwnode_property_read_u32() before
> the endpoint is parsed and freed. Avoid the error leak by not
> assigning the result of fwnode_property_read_u32() to 'ret'.
> 
> Fixes: 91807efbe8ec ("media: i2c: add OV02A10 image sensor driver")
> Cc: [email protected]
> Signed-off-by: Biren Pandya <[email protected]>
> Reviewed-by: Vladimir Zapolskiy <[email protected]>
> Signed-off-by: Sakari Ailus <[email protected]>

Patch committed.

Thanks,
Sakari Ailus

 drivers/media/i2c/ov02a10.c | 12 +++++-------
 1 file changed, 5 insertions(+), 7 deletions(-)

---

diff --git a/drivers/media/i2c/ov02a10.c b/drivers/media/i2c/ov02a10.c
index 143dcfe10445..0150e4d296af 100644
--- a/drivers/media/i2c/ov02a10.c
+++ b/drivers/media/i2c/ov02a10.c
@@ -820,18 +820,16 @@ static int ov02a10_check_hwcfg(struct device *dev, struct 
ov02a10 *ov02a10)
        if (!ep)
                return -ENXIO;
 
+       /* Optional indication of MIPI clock voltage unit */
+       if (!fwnode_property_read_u32(ep, "ovti,mipi-clock-voltage",
+                                     &clk_volt))
+               ov02a10->mipi_clock_voltage = clk_volt;
+
        ret = v4l2_fwnode_endpoint_alloc_parse(ep, &bus_cfg);
        fwnode_handle_put(ep);
        if (ret)
                return ret;
 
-       /* Optional indication of MIPI clock voltage unit */
-       ret = fwnode_property_read_u32(ep, "ovti,mipi-clock-voltage",
-                                      &clk_volt);
-
-       if (!ret)
-               ov02a10->mipi_clock_voltage = clk_volt;
-
        for (i = 0; i < ARRAY_SIZE(link_freq_menu_items); i++) {
                for (j = 0; j < bus_cfg.nr_of_link_frequencies; j++) {
                        if (link_freq_menu_items[i] ==
_______________________________________________
linuxtv-commits mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to