On Thu Sep 17 10:00:10 2026 +0000, Wentao Liang wrote:
> device_link_add() only takes a reference to the supplier when the
> link is created successfully. When it fails it returns NULL without
> taking one, so the put_device(csi_dev) before the error check can
> drop the last reference to csi_dev and dev_name(csi_dev) then
> dereferences a freed device.
>
> Move the put_device() below the error check and release the
> reference through the existing err_put label on the failure path so
> that csi_dev is no longer touched after it has been put.
>
> Fixes: 765abb76f51f ("media: ivsc: Release csi_dev reference early in
> mei_ace_setup_dev_link()")
> Signed-off-by: Wentao Liang <[email protected]>
> Signed-off-by: Sakari Ailus <[email protected]>
Patch committed.
Thanks,
Sakari Ailus
drivers/media/pci/intel/ivsc/mei_ace.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
---
diff --git a/drivers/media/pci/intel/ivsc/mei_ace.c
b/drivers/media/pci/intel/ivsc/mei_ace.c
index b306a320b70f..bb57656fc85a 100644
--- a/drivers/media/pci/intel/ivsc/mei_ace.c
+++ b/drivers/media/pci/intel/ivsc/mei_ace.c
@@ -414,13 +414,13 @@ static int mei_ace_setup_dev_link(struct mei_ace *ace)
/* setup link between mei_ace and mei_csi */
ace->csi_link = device_link_add(csi_dev, dev, DL_FLAG_PM_RUNTIME |
DL_FLAG_RPM_ACTIVE | DL_FLAG_STATELESS);
- put_device(csi_dev);
if (!ace->csi_link) {
ret = -EINVAL;
dev_err(dev, "failed to link to %s\n", dev_name(csi_dev));
- goto err;
+ goto err_put;
}
+ put_device(csi_dev);
ace->csi_dev = csi_dev;
return 0;
_______________________________________________
linuxtv-commits mailing list -- [email protected]
To unsubscribe send an email to [email protected]