Received: by 2002:a25:ad19:0:0:0:0:0 with SMTP id y25csp3203197ybi; Mon, 29 Jul 2019 02:42:05 -0700 (PDT) X-Google-Smtp-Source: APXvYqzc8mZ6fBulG2VOeCJAbM90cY3BrDQpjQCcBCf0uuxZzcJlFk/Od0p4eHiHOD8kXKWNemIh X-Received: by 2002:aa7:9f1c:: with SMTP id g28mr35169090pfr.81.1564393325669; Mon, 29 Jul 2019 02:42:05 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1564393325; cv=none; d=google.com; s=arc-20160816; b=NBPw0wjhusGBfoLv7jkJU+X+l9f0n51VASCf5TgRHCK0zvfQzDBi7tgubjIYMlQ+Zm SHyR/nMWT3kl6psBr5tqqj5sYe9vP8ISRRs6xMQRmopdPD8B7kIjaQcEFFvIgIA5xooY 4iuLlk9tSq5+QlS+jcejS6IvdO/0/SsgqGJfgFYw3zTJDDS1TLgnd2FUW3WFtWsuL0hc XccDA49PPAf1SrXsVdgKkkvEMcknercbFTZEJXXbLWArNXaflXDzUrfO5Bxn0kd7gM2Y tCD1lbZ19XOscvPL7BWVlRVx8geLLKsxHLfAQ1vP4Zi3AQ/XRtxZjyRZsfUZGZA2wrBP n80Q== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:sender:content-language :content-transfer-encoding:mime-version:user-agent:date:message-id :subject:from:cc:to:dkim-signature; bh=kw/X5PHvyhK+OPglhkZH2PrJCm66ztyP4P0qwlP8Hr0=; b=AxO0kS9z7YghRi06hzH7m+1rTqOa+QgQaHBr+gNKLP5MvcmgKqG2Qu0dcZwZavqhCy kxCGdGbBcsT+1pA9tYy6RcaoOABlSp75VFz5VhjgkV/cCyywSVdufVzQobox6wn/Nozb 0gMA2L5fZcK63/c2tmAwON7+0YvIJauOJ0d3pUAC2kdEk8zGj8vuY+pw/+c6vBH/ix13 FVxPNi1sOLXJC4mz5LEhIQx2Pn6XpJbrijWDultYLbxCN3NslWdADZlC6jz9wzee2CV4 OPtbflRxxjYh7lY+KDbKoqhZKkxy09K1nJRpQg697EviyBO0xbjoce119nRjxkwd7e+a wOMg== ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@gmail.com header.s=20161025 header.b=PIRU+WPD; spf=pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=NONE sp=QUARANTINE dis=NONE) header.from=gmail.com Return-Path: Received: from vger.kernel.org (vger.kernel.org. [209.132.180.67]) by mx.google.com with ESMTP id g21si15542469pgk.293.2019.07.29.02.41.50; Mon, 29 Jul 2019 02:42:05 -0700 (PDT) Received-SPF: pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) client-ip=209.132.180.67; Authentication-Results: mx.google.com; dkim=pass header.i=@gmail.com header.s=20161025 header.b=PIRU+WPD; spf=pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org; dmarc=pass (p=NONE sp=QUARANTINE dis=NONE) header.from=gmail.com Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1726473AbfG2Jkt (ORCPT + 99 others); Mon, 29 Jul 2019 05:40:49 -0400 Received: from mail-pf1-f176.google.com ([209.85.210.176]:40192 "EHLO mail-pf1-f176.google.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1725818AbfG2Jkt (ORCPT ); Mon, 29 Jul 2019 05:40:49 -0400 Received: by mail-pf1-f176.google.com with SMTP id p184so27729116pfp.7; Mon, 29 Jul 2019 02:40:48 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=to:cc:from:subject:message-id:date:user-agent:mime-version :content-transfer-encoding:content-language; bh=kw/X5PHvyhK+OPglhkZH2PrJCm66ztyP4P0qwlP8Hr0=; b=PIRU+WPDU7Kb14O9rKBbjcvhEvWoo3Agt5kST4Gh2mzgeQzF2kueO4h60oIDShPQiO RMxaDQOYAtUYif69BWsTbTMgVhehKQFCyth2Nb0P/zVRaxTLTNqcTDA4cCsruZmE5qBs 11wWLyVSUqJFAffo/mPWABVIF1p99NlslStd8bdmLtwr6KomHnlIdsumg1YDHbwso6b4 018QtqfmefGoI02ixaOrPS6hfSt0lJhCAmFnNgGn5IuuTjRwStUExYPF/7vNOeb28iRw UrbNVZ6ILshiCUqNUzEckUKN0UWwe/GKp/dNZOK5oLujQLGO8FKdLA2pfUrJDwNVVVth VEkw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:to:cc:from:subject:message-id:date:user-agent :mime-version:content-transfer-encoding:content-language; bh=kw/X5PHvyhK+OPglhkZH2PrJCm66ztyP4P0qwlP8Hr0=; b=LBI0JzrQfZv9Juywa9862oTppr7+NKSqdZzUEeAJXFr/ZlxaMLTYFWFFC48hUm7CNi TuSi3LzXX+SdNbjH8EjTpqup/HdLiqcYwG8h7dqEbrBZMQWRzM5odAV4x1XzpXeDQS7+ Ef8fOwWyWACACJ5j1iNJHBvKkeVcznTIDYdNdvse2vVkJr9c3qyplVIUzWnjRKPaa3yx GxxWKu1GQad2TwGIJBSNeigyngdrZXfzGAf02aIq6Bo5Kra+mLO15xQECKKDZG1ayFoI A3AWN/Uc4K4DDAqKNLM21sA9z1OGpKSNe3Q5Ac1XvhtACBc9xF1bsCAt7YXS6wWHTSWw 7+Eg== X-Gm-Message-State: APjAAAUDuOa6UEx92Aqe9fJ1fQTA9q8Qu8iL6hXOxAOmElW0nGKJwgTC +I4wHH3XUbDG3rfSHI9HWo/KaBKR3hQ= X-Received: by 2002:a63:7b18:: with SMTP id w24mr102859972pgc.328.1564393248396; Mon, 29 Jul 2019 02:40:48 -0700 (PDT) Received: from ?IPv6:2402:f000:4:72:808::177e? ([2402:f000:4:72:808::177e]) by smtp.gmail.com with ESMTPSA id g2sm64960696pfi.26.2019.07.29.02.40.46 (version=TLS1_2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Mon, 29 Jul 2019 02:40:48 -0700 (PDT) To: awalls@md.metrocast.net, mchehab@kernel.org Cc: linux-media@vger.kernel.org, linux-kernel@vger.kernel.org From: Jia-Ju Bai Subject: [BUG] media: pci: cx18: a possible null-pointer dereference in cx18_vapi() Message-ID: Date: Mon, 29 Jul 2019 17:40:48 +0800 User-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; rv:60.0) Gecko/20100101 Thunderbird/60.8.0 MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8; format=flowed Content-Transfer-Encoding: 8bit Content-Language: en-US Sender: linux-kernel-owner@vger.kernel.org Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org In cx18_vapi(), when cx is NULL, it is still used on line 833:     CX18_ERR("cx == NULL (cmd=%x)\n", cmd);          v4l2_err(&cx->v4l2_dev, fmt , ## args) Thus, a possible null-pointer dereference may occur. This bug is found by a static analysis tool STCheck written by us. I do not know how to correctly fix this bug, so I only report it. Best wishes, Jia-Ju Bai