On Thu Jun 4 05:47:08 2026 +0000, Hungyu Lin wrote:
> Cancel sys_error_handler before tearing down the driver.
> 
> The delayed work may still be pending when iris_remove()
> runs. Since iris_core is allocated with devm_kzalloc(),
> allowing the work to execute after driver removal could
> result in accessing freed memory.
> 
> Fixes: fb583a214337 ("media: iris: introduce host firmware interface with 
> necessary hooks")
> Signed-off-by: Hungyu Lin <[email protected]>
> Reviewed-by: Vishnu Reddy <[email protected]>
> Reviewed-by: Dmitry Baryshkov <[email protected]>
> [bod: Fixed patch title]
> Signed-off-by: Bryan O'Donoghue <[email protected]>

Patch committed.

Thanks,
Bryan O'Donoghue

 drivers/media/platform/qcom/iris/iris_probe.c | 2 ++
 1 file changed, 2 insertions(+)

---

diff --git a/drivers/media/platform/qcom/iris/iris_probe.c 
b/drivers/media/platform/qcom/iris/iris_probe.c
index 6581a969fe3f..c4b8b4be339d 100644
--- a/drivers/media/platform/qcom/iris/iris_probe.c
+++ b/drivers/media/platform/qcom/iris/iris_probe.c
@@ -251,6 +251,8 @@ static void iris_remove(struct platform_device *pdev)
        if (!core)
                return;
 
+       cancel_delayed_work_sync(&core->sys_error_handler);
+
        iris_core_deinit(core);
 
        video_unregister_device(core->vdev_dec);
_______________________________________________
linuxtv-commits mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to