On Thu Jul 23 12:22:42 2026 -0600, Diego Fernando Mancera Gomez wrote:
> The audio-only path registers extensions while probing the primary device.
> For a dual-TS board, this happens before dev_next is created. The duplicate
> device inherits is_audio_only and is then independently inserted into
> em28xx_devlist.
> 
> The list is intended to contain only primary devices: extension operations
> reach the secondary device through dev_next. The independently linked
> secondary can be freed during disconnect while its list node remains
> reachable, resulting in a use-after-free.
> 
> Defer audio-only extension registration to the module-request work item. It
> runs only after probing has completed construction of the optional
> secondary device, so only the primary is registered and extension callbacks
> reach the secondary through dev_next.
> 
> Fixes: 4a089668ef22 ("media: em28xx-cards: rework the em28xx probing code")
> Cc: [email protected]
> Reported-by: [email protected]
> Closes: 
> https://lore.kernel.org/all/[email protected]/T/
> Suggested-by: Fedor Pchelkin <[email protected]>
> Signed-off-by: Diego Fernando Mancera Gomez <[email protected]>
> Signed-off-by: Hans Verkuil <[email protected]>

Patch committed.

Thanks,
Hans Verkuil

 drivers/media/usb/em28xx/em28xx-cards.c | 3 +--
 1 file changed, 1 insertion(+), 2 deletions(-)

---

diff --git a/drivers/media/usb/em28xx/em28xx-cards.c 
b/drivers/media/usb/em28xx/em28xx-cards.c
index b94b00456bcd..b7c534fc8a21 100644
--- a/drivers/media/usb/em28xx/em28xx-cards.c
+++ b/drivers/media/usb/em28xx/em28xx-cards.c
@@ -3675,6 +3675,7 @@ static void request_module_async(struct work_struct *work)
         * intf. Don't register extensions twice on those devices.
         */
        if (dev->is_audio_only) {
+               em28xx_init_extension(dev);
 #if defined(CONFIG_MODULES) && defined(MODULE)
                request_module("em28xx-alsa");
 #endif
@@ -3913,8 +3914,6 @@ static int em28xx_init_dev(struct em28xx *dev, struct 
usb_device *udev,
                        retval = -ENODEV;
                        goto err_deinit_media;
                }
-               em28xx_init_extension(dev);
-
                return 0;
        }
 
_______________________________________________
linuxtv-commits mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to