On Tue Jul 7 23:06:24 2026 +0800, Ruoyu Wang wrote:
> hfi_process_msg_packet() intentionally allows HFI_MSG_EVENT_NOTIFY
> packets without a matching session instance because HFI_EVENT_SYS_ERROR
> is a system event and has no session attached.
> 
> That exception currently applies to every event-notify packet. If the
> firmware reports a late or otherwise invalid session event after
> to_instance() fails, hfi_event_notify() can dispatch it to session-only
> handlers such as event_seq_changed() or event_release_buffer_ref(), which
> dereference inst.
> 
> Only system errors are valid without a session instance. Drop other
> event notifications before the session event handlers can dereference a
> NULL inst.
> 
> This issue was found by a static analysis checker and confirmed by
> manual source review.
> 
> Fixes: 09c2845e8fe4 ("[media] media: venus: hfi: add Host Firmware Interface 
> (HFI)")
> Signed-off-by: Ruoyu Wang <[email protected]>
> Signed-off-by: Bryan O'Donoghue <[email protected]>

Patch committed.

Thanks,
Bryan O'Donoghue

 drivers/media/platform/qcom/venus/hfi_msgs.c | 3 +++
 1 file changed, 3 insertions(+)

---

diff --git a/drivers/media/platform/qcom/venus/hfi_msgs.c 
b/drivers/media/platform/qcom/venus/hfi_msgs.c
index 5c2025c5acc7..ed6b4e5e5e92 100644
--- a/drivers/media/platform/qcom/venus/hfi_msgs.c
+++ b/drivers/media/platform/qcom/venus/hfi_msgs.c
@@ -230,6 +230,9 @@ static void hfi_event_notify(struct venus_core *core, 
struct venus_inst *inst,
        if (!packet)
                return;
 
+       if (!inst && pkt->event_id != HFI_EVENT_SYS_ERROR)
+               return;
+
        switch (pkt->event_id) {
        case HFI_EVENT_SYS_ERROR:
                event_sys_error(core, EVT_SYS_ERROR, pkt);
_______________________________________________
linuxtv-commits mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to