On Wed Aug 12 13:00:23 2026 +0100, Sean Young wrote:
> During or after rc_unregister_device(), IR may still be reported which
> results in a input event being reported. This could result in a null
> pointer deref in rc_keydown() or a use-after-free of the input device if
> the pointer was read before it is set to NULL.
> 
> Fixes: dccc0c3ddf8f ("media: rc: fix race between unregister and urb/irq 
> callbacks")
> Signed-off-by: Sean Young <[email protected]>
> Cc: [email protected]
> Acked-by: Hans Verkuil <[email protected]>

Patch committed.

Thanks,
Sean Young

 drivers/media/rc/rc-main.c | 8 ++++----
 1 file changed, 4 insertions(+), 4 deletions(-)

---

diff --git a/drivers/media/rc/rc-main.c b/drivers/media/rc/rc-main.c
index 930d45517229..d4baaae3a834 100644
--- a/drivers/media/rc/rc-main.c
+++ b/drivers/media/rc/rc-main.c
@@ -1753,7 +1753,7 @@ void rc_free_device(struct rc_dev *dev)
        if (!dev)
                return;
 
-       input_free_device(dev->input_dev);
+       input_put_device(dev->input_dev);
 
        put_device(&dev->dev);
 
@@ -1865,6 +1865,8 @@ static int rc_setup_rx_device(struct rc_dev *dev)
        if (rc)
                return rc;
 
+       input_get_device(dev->input_dev);
+
        /*
         * Default delay of 250ms is too short for some protocols, especially
         * since the timeout is currently set to 250ms. Increase it to 500ms,
@@ -1891,10 +1893,8 @@ static void rc_free_rx_device(struct rc_dev *dev)
        if (!dev)
                return;
 
-       if (dev->input_dev) {
+       if (dev->input_dev)
                input_unregister_device(dev->input_dev);
-               dev->input_dev = NULL;
-       }
 
        ir_free_table(&dev->rc_map);
 }
_______________________________________________
linuxtv-commits mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to