On Mon Aug 10 17:50:12 2026 +0800, Xu Rao wrote:
> v4l2_async_match_notify() creates ancillary media links before adding
> asc->asc_subdev_entry to sd->asc_list.
> 
> If ancillary link creation fails, the function jumps to
> err_call_unbind while asc_subdev_entry has not been linked yet. Async
> connections are zero-allocated, so the list entry still has NULL next
> and prev pointers on this path. Calling list_del() on it can therefore
> dereference NULL instead of returning the original link creation error.
> 
> Do not delete asc_subdev_entry from err_call_unbind. There is no list
> insertion to undo on this path; the bound callback and sub-device
> registration are the operations that need to be rolled back.
> 
> Fixes: 28a1295795d8 ("media: v4l: async: Allow multiple connections between 
> entities")
> Cc: [email protected]
> Signed-off-by: Xu Rao <[email protected]>
> Signed-off-by: Sakari Ailus <[email protected]>

Patch committed.

Thanks,
Sakari Ailus

 drivers/media/v4l2-core/v4l2-async.c | 1 -
 1 file changed, 1 deletion(-)

---

diff --git a/drivers/media/v4l2-core/v4l2-async.c 
b/drivers/media/v4l2-core/v4l2-async.c
index f36d60e6ff41..460bf3dbbb88 100644
--- a/drivers/media/v4l2-core/v4l2-async.c
+++ b/drivers/media/v4l2-core/v4l2-async.c
@@ -392,7 +392,6 @@ static int v4l2_async_match_notify(struct 
v4l2_async_notifier *notifier,
 
 err_call_unbind:
        v4l2_async_nf_call_unbind(notifier, sd, asc);
-       list_del(&asc->asc_subdev_entry);
 
 err_unregister_subdev:
        if (registered)
_______________________________________________
linuxtv-commits mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to